Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 30.07.2015, 13:14   #1
Gooaly
 
Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab - Standard

Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab



Hallo zusammen, habe mir wohl was eingefangen...


Wenn ich mit den Chrome Browser surfe und ich einen Link auf z.B Spiegel.de klicke - öffnet sich nach klick ein WerbeTab.

Passiert in unregelmäßigen Abständen.

Hier mal die Logs...

Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-30 14:03:36
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Samsung_ rev.EXT0 232,89GB
Running: Gmer-19357.exe; Driver: C:\Users\Andree\AppData\Local\Temp\uwdiqpob.sys


---- User code sections - GMER 2.1 ----

.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17      0000000076e91401 2 bytes JMP 000000010779a47c
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17        0000000076e91419 2 bytes JMP 000000010779a494
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17      0000000076e91431 2 bytes JMP 000000010779a4ac
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42      0000000076e9144a 2 bytes JMP 0000000076f5fcc5
.text   ...                                                                                                                               * 9
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17         0000000076e914dd 2 bytes JMP 000000010779a558
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17  0000000076e914f5 2 bytes JMP 000000010779a570
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17         0000000076e9150d 2 bytes JMP 000000010779a588
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17  0000000076e91525 2 bytes JMP 000000010779a5a0
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17        0000000076e9153d 2 bytes JMP 000000010779a5b8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17             0000000076e91555 2 bytes JMP 000000010779a5d0
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17      0000000076e9156d 2 bytes JMP 000000010779a5e8
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17        0000000076e91585 2 bytes JMP 000000010779a600
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17           0000000076e9159d 2 bytes JMP 000000010779a618
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17        0000000076e915b5 2 bytes JMP 000000010779a630
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17      0000000076e915cd 2 bytes JMP 000000015d37ce48
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20  0000000076e916b2 2 bytes JMP 000000010779a72d
.text   C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2836] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31  0000000076e916bd 2 bytes JMP 000000010779a738
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                  000007fefcdb2db0 5 bytes JMP 000007fffcda0180
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                             000007fefcdb37d0 7 bytes JMP 000007fffcda00d8
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                           000007fefcdba410 2 bytes JMP 000007fffcda0110
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3                                       000007fefcdba413 2 bytes [FE, FF]
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                               000007fefcdbaec0 6 bytes JMP 000007fffcda0148
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                            000007fefd9689d0 8 bytes JMP 000007fffcda01f0
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                          000007fefd96be40 8 bytes JMP 000007fffcda01b8
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\dxgi.dll!CreateDXGIFactory                                                  000007fef5b6dc88 5 bytes JMP 000007fff5b400d8
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1                                                 000007fef5b6de10 5 bytes JMP 000007fff5b40110
.text   C:\Windows\system32\Dwm.exe[3496] C:\Windows\system32\d3d11.dll!D3D11CreateDeviceAndSwapChain                                     000007fef41500f8 9 bytes {MOV RAX, 0x62044600; JMP RAX}
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                          0000000075c81efe 7 bytes JMP 000000016ccd4b10
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                            0000000075c85b9d 7 bytes JMP 000000016ccd54b0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                            0000000075c913f9 7 bytes JMP 000000016ccd4e50
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                           0000000075c9ea45 7 bytes JMP 000000016ccd4b00
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                   0000000075d28ea4 7 bytes JMP 000000016ccd45c0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                   0000000075d28f29 5 bytes JMP 000000016ccd4670
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                     0000000075d29281 5 bytes JMP 000000016ccd45d0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                        0000000076751d29 5 bytes JMP 000000016ccd4580
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                      0000000076751dd7 5 bytes JMP 000000016ccd4540
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                          0000000076752ab1 5 bytes JMP 000000016ccd4680
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                             0000000076752d1d 5 bytes JMP 000000016ccd4360
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\USER32.dll!CreateWindowExW                             0000000074dd8a29 5 bytes JMP 000000016ccd3a40
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                         0000000074de4572 5 bytes JMP 000000016ccd42e0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                         0000000074dfe567 5 bytes JMP 000000016ccd4350
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                    0000000074e207d7 5 bytes JMP 000000016ccd3850
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                  0000000074e37a5c 5 bytes JMP 000000016ccd42d0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                     00000000768ad2b4 5 bytes JMP 000000016ccd3b60
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                       00000000768ad4ee 5 bytes JMP 000000016ccd3b80
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                    0000000076e91401 2 bytes JMP 000000010779a47c
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                      0000000076e91419 2 bytes JMP 000000010779a494
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                    0000000076e91431 2 bytes JMP 000000010779a4ac
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                    0000000076e9144a 2 bytes JMP 0000000076f5fcc5
.text   ...                                                                                                                               * 9
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                       0000000076e914dd 2 bytes JMP 000000010779a558
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                0000000076e914f5 2 bytes JMP 000000010779a570
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                       0000000076e9150d 2 bytes JMP 000000010779a588
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                0000000076e91525 2 bytes JMP 000000010779a5a0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                      0000000076e9153d 2 bytes JMP 000000010779a5b8
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                           0000000076e91555 2 bytes JMP 000000010779a5d0
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                    0000000076e9156d 2 bytes JMP 000000010779a5e8
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                      0000000076e91585 2 bytes JMP 000000010779a600
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                         0000000076e9159d 2 bytes JMP 000000010779a618
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                      0000000076e915b5 2 bytes JMP 000000010779a630
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                    0000000076e915cd 2 bytes JMP 000000015d37ce48
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                0000000076e916b2 2 bytes JMP 000000010779a72d
.text   C:\Program Files (x86)\TeamViewer\TeamViewer.exe[3640] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                0000000076e916bd 2 bytes JMP 000000010779a738
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                              0000000075c81efe 7 bytes JMP 000000016ccd4b10
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                0000000075c85b9d 7 bytes JMP 000000016ccd54b0
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                0000000075c913f9 7 bytes JMP 000000016ccd4e50
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                               0000000075c9ea45 7 bytes JMP 000000016ccd4b00
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                       0000000075d28ea4 7 bytes JMP 000000016ccd45c0
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                       0000000075d28f29 5 bytes JMP 000000016ccd4670
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                         0000000075d29281 5 bytes JMP 000000016ccd45d0
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                            0000000076751d29 5 bytes JMP 000000016ccd4580
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                          0000000076751dd7 5 bytes JMP 000000016ccd4540
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                              0000000076752ab1 5 bytes JMP 000000016ccd4680
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                 0000000076752d1d 5 bytes JMP 000000016ccd4360
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                         00000000768ad2b4 5 bytes JMP 000000016ccd3b60
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                           00000000768ad4ee 5 bytes JMP 000000016ccd3b80
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                 0000000074dd8a29 5 bytes JMP 000000016ccd3a40
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                             0000000074de4572 5 bytes JMP 000000016ccd42e0
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                             0000000074dfe567 5 bytes JMP 000000016ccd4350
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                        0000000074e207d7 5 bytes JMP 000000016ccd3850
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                      0000000074e37a5c 5 bytes JMP 000000016ccd42d0
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                0000000074c35ea5 5 bytes JMP 000000016ccd3a00
.text   C:\Program Files (x86)\TeamViewer\tv_w32.exe[1936] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                 0000000074c69d0b 5 bytes JMP 000000016ccd3990
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!RegSetValueExW                                0000000076aca3e0 7 bytes JMP 000000016fff0228
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!RegQueryValueExW                              0000000076ad3f00 5 bytes JMP 000000016fff0180
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!RegDeleteValueW                               0000000076aeffd0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                         0000000076aff350 5 bytes JMP 000000016fff0110
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                       0000000076b29aa0 7 bytes JMP 000000016fff00d8
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                       0000000076b39530 5 bytes JMP 000000016fff0148
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\kernel32.dll!RegSetValueExA                                0000000076b58850 7 bytes JMP 000000016fff01f0
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                 000007fefcdb2db0 5 bytes JMP 000007fffcda0180
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                            000007fefcdb37d0 7 bytes JMP 000007fffcda00d8
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                          000007fefcdba410 2 bytes JMP 000007fffcda0110
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3                      000007fefcdba413 2 bytes [FE, FF]
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                              000007fefcdbaec0 6 bytes JMP 000007fffcda0148
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                           000007fefd9689d0 8 bytes JMP 000007fffcda01f0
.text   C:\Program Files (x86)\TeamViewer\tv_x64.exe[4532] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                         000007fefd96be40 8 bytes JMP 000007fffcda01b8
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                              0000000075c81efe 7 bytes JMP 000000016ccd4b10
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                0000000075c85b9d 7 bytes JMP 000000016ccd54b0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                0000000075c913f9 7 bytes JMP 000000016ccd4e50
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                               0000000075c9ea45 7 bytes JMP 000000016ccd4b00
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                       0000000075d28ea4 7 bytes JMP 000000016ccd45c0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                       0000000075d28f29 5 bytes JMP 000000016ccd4670
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                         0000000075d29281 5 bytes JMP 000000016ccd45d0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                            0000000076751d29 5 bytes JMP 000000016ccd4580
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                          0000000076751dd7 5 bytes JMP 000000016ccd4540
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                              0000000076752ab1 5 bytes JMP 000000016ccd4680
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                 0000000076752d1d 5 bytes JMP 000000016ccd4360
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                         00000000768ad2b4 5 bytes JMP 000000016ccd3b60
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                           00000000768ad4ee 5 bytes JMP 000000016ccd3b80
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                 0000000074dd8a29 5 bytes JMP 000000016ccd3a40
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                             0000000074de4572 5 bytes JMP 000000016ccd42e0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                             0000000074dfe567 5 bytes JMP 000000016ccd4350
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                        0000000074e207d7 5 bytes JMP 000000016ccd3850
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                      0000000074e37a5c 5 bytes JMP 000000016ccd42d0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                        0000000076e91401 2 bytes JMP 000000010779a47c
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                          0000000076e91419 2 bytes JMP 000000010779a494
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                        0000000076e91431 2 bytes JMP 000000010779a4ac
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                        0000000076e9144a 2 bytes JMP 0000000076f5fcc5
.text   ...                                                                                                                               * 9
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                           0000000076e914dd 2 bytes JMP 000000010779a558
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                    0000000076e914f5 2 bytes JMP 000000010779a570
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                           0000000076e9150d 2 bytes JMP 000000010779a588
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                    0000000076e91525 2 bytes JMP 000000010779a5a0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                          0000000076e9153d 2 bytes JMP 000000010779a5b8
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                               0000000076e91555 2 bytes JMP 000000010779a5d0
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                        0000000076e9156d 2 bytes JMP 000000010779a5e8
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                          0000000076e91585 2 bytes JMP 000000010779a600
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                             0000000076e9159d 2 bytes JMP 000000010779a618
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                          0000000076e915b5 2 bytes JMP 000000010779a630
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                        0000000076e915cd 2 bytes JMP 000000015d37ce48
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                    0000000076e916b2 2 bytes JMP 000000010779a72d
.text   C:\Program Files (x86)\Skype\Phone\Skype.exe[5920] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                    0000000076e916bd 2 bytes JMP 000000010779a738
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                              000007fefcdb2db0 5 bytes JMP 000007fffcda0180
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                         000007fefcdb37d0 7 bytes JMP 000007fffcda00d8
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                       000007fefcdba410 2 bytes JMP 000007fffcda0110
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3                                   000007fefcdba413 2 bytes [FE, FF]
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                           000007fefcdbaec0 6 bytes JMP 000007fffcda0148
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\ole32.dll!CoCreateInstance                                              000007fefdb274a0 11 bytes JMP 000007fffcda0228
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                             000007fefdb3bf10 7 bytes JMP 000007fffcda0260
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                        000007fefd9689d0 8 bytes JMP 000007fffcda01f0
.text   C:\Windows\system32\DllHost.exe[3112] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                      000007fefd96be40 8 bytes JMP 000007fffcda01b8
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                 0000000075c81efe 7 bytes JMP 000000016ccd4b10
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                   0000000075c85b9d 7 bytes JMP 000000016ccd54b0
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                   0000000075c913f9 7 bytes JMP 000000016ccd4e50
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                  0000000075c9ea45 7 bytes JMP 000000016ccd4b00
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx          0000000075d28ea4 7 bytes JMP 000000016ccd45c0
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation          0000000075d28f29 5 bytes JMP 000000016ccd4670
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW            0000000075d29281 5 bytes JMP 000000016ccd45d0
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW               0000000076751d29 5 bytes JMP 000000016ccd4580
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW             0000000076751dd7 5 bytes JMP 000000016ccd4540
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                 0000000076752ab1 5 bytes JMP 000000016ccd4680
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                    0000000076752d1d 5 bytes JMP 000000016ccd4360
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\USER32.dll!CreateWindowExW                    0000000074dd8a29 5 bytes JMP 000000016ccd3a40
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                0000000074de4572 5 bytes JMP 000000016ccd42e0
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                0000000074dfe567 5 bytes JMP 000000016ccd4350
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW           0000000074e207d7 5 bytes JMP 000000016ccd3850
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo         0000000074e37a5c 5 bytes JMP 000000016ccd42d0
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList            00000000768ad2b4 5 bytes JMP 000000016ccd3b60
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo              00000000768ad4ee 5 bytes JMP 000000016ccd3b80
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                   0000000074c35ea5 5 bytes JMP 000000016ccd3a00
.text   C:\Program Files (x86)\Schichtplaner 5\Schichtplaner5.exe[4376] C:\Windows\syswow64\ole32.dll!CoCreateInstance                    0000000074c69d0b 5 bytes JMP 000000016ccd3990
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                              000007fefcdb2db0 5 bytes JMP 000007fffcda0180
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                         000007fefcdb37d0 7 bytes JMP 000007fffcda00d8
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                       000007fefcdba410 2 bytes JMP 000007fffcda0110
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3                                   000007fefcdba413 2 bytes [FE, FF]
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                           000007fefcdbaec0 6 bytes JMP 000007fffcda0148
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                        000007fefd9689d0 8 bytes JMP 000007fffcda01f0
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                      000007fefd96be40 8 bytes JMP 000007fffcda01b8
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\ole32.dll!CoCreateInstance                                              000007fefdb274a0 11 bytes JMP 000007fffcda0228
.text   C:\Windows\system32\taskeng.exe[5740] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                             000007fefdb3bf10 7 bytes JMP 000007fffcda0260
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                    0000000075c81efe 7 bytes JMP 000000016ccd4b10
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                      0000000075c85b9d 7 bytes JMP 000000016ccd54b0
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                      0000000075c913f9 7 bytes JMP 000000016ccd4e50
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                     0000000075c9ea45 7 bytes JMP 000000016ccd4b00
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                             0000000075d28ea4 7 bytes JMP 000000016ccd45c0
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                             0000000075d28f29 5 bytes JMP 000000016ccd4670
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                               0000000075d29281 5 bytes JMP 000000016ccd45d0
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                  0000000076751d29 5 bytes JMP 000000016ccd4580
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                0000000076751dd7 5 bytes JMP 000000016ccd4540
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                    0000000076752ab1 5 bytes JMP 000000016ccd4680
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                       0000000076752d1d 5 bytes JMP 000000016ccd4360
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                               00000000768ad2b4 5 bytes JMP 000000016ccd3b60
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                 00000000768ad4ee 5 bytes JMP 000000016ccd3b80
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                       0000000074dd8a29 5 bytes JMP 000000016ccd3a40
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                   0000000074de4572 5 bytes JMP 000000016ccd42e0
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                   0000000074dfe567 5 bytes JMP 000000016ccd4350
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                              0000000074e207d7 5 bytes JMP 000000016ccd3850
.text   C:\Users\Andree\Desktop\Gmer-19357.exe[3424] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                            0000000074e37a5c 5 bytes JMP 000000016ccd42d0

---- Devices - GMER 2.1 ----

Device  \Driver\alj4lhiq \Device\Scsi\alj4lhiq1                                                                                           fffffa800d00d2c0
Device  \Driver\axj1oc45 \Device\Scsi\axj1oc451                                                                                           fffffa800d0192c0
Device  \Driver\alj4lhiq \Device\Scsi\alj4lhiq1Port1Path0Target0Lun0                                                                      fffffa800d00d2c0
Device  \FileSystem\Ntfs \Ntfs                                                                                                            fffffa8009a062c0
Device  \FileSystem\fastfat \Fat                                                                                                          fffffa800f8772c0
Device  \Driver\usbehci \Device\USBPDO-1                                                                                                  fffffa800cf652c0
Device  \Driver\cdrom \Device\CdRom0                                                                                                      fffffa800a6942c0
Device  \Driver\cdrom \Device\CdRom1                                                                                                      fffffa800a6942c0
Device  \Driver\cdrom \Device\CdRom2                                                                                                      fffffa800a6942c0
Device  \Driver\dtsoftbus01 \Device\0000008b                                                                                              fffffa800a63c2c0
Device  \Driver\usbehci \Device\USBFDO-0                                                                                                  fffffa800cf652c0
Device  \Driver\dtsoftbus01 \Device\DTSoftBusCtl                                                                                          fffffa800a63c2c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{47466E2B-DCBA-4C55-B778-3CA49DF77B69}                                                          fffffa800a6962c0
Device  \Driver\usbehci \Device\USBFDO-1                                                                                                  fffffa800cf652c0
Device  \Driver\NetBT \Device\NetBt_Wins_Export                                                                                           fffffa800a6962c0
Device  \Driver\alj4lhiq \Device\ScsiPort1                                                                                                fffffa800d00d2c0
Device  \Driver\usbehci \Device\USBPDO-0                                                                                                  fffffa800cf652c0
Device  \Driver\axj1oc45 \Device\ScsiPort2                                                                                                fffffa800d0192c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{386D820A-842F-4E32-9D4E-9D06CF6258A5}                                                          fffffa800a6962c0

---- Modules - GMER 2.1 ----

Module  \SystemRoot\System32\Drivers\alj4lhiq.SYS                                                                                         fffff8800890a000-fffff88008955000 (307200 bytes)
Module  \SystemRoot\System32\Drivers\axj1oc45.SYS                                                                                         fffff88008984000-fffff880089d5000 (331776 bytes)

---- Threads - GMER 2.1 ----

Thread  C:\Windows\SysWOW64\ntdll.dll [5200:8796]                                                                                         00000000000dee7e
Thread  C:\Windows\SysWOW64\ntdll.dll [5200:2436]                                                                                         00000000717032fb

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0cd292440e5c                                                       
Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0cd292440e5c@041552eec404                                          0x77 0x2A 0x23 0xD6 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                  
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                               0
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                            0x41 0x82 0xBB 0x5A ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                               C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                         
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                   0x25 0xB4 0x76 0xE3 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                      0xA0 0x02 0x00 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                                  
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                            0xC9 0x22 0xB6 0x2B ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC                                                  
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                               C:\Program Files (x86)\DAEMON Tools Lite\
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                               0x00 0x00 0x00 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                               1
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                            0x10 0xA0 0xC7 0x5D ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001                                         
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                                      0xA0 0x02 0x00 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                                   0x96 0x70 0x2A 0xC7 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0                                    
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                              0x3B 0xA9 0xCF 0xF6 ...
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0cd292440e5c (not active ControlSet)                                   
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0cd292440e5c@041552eec404                                              0x77 0x2A 0x23 0xD6 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                              
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                   0
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                0x41 0x82 0xBB 0x5A ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                   C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)                     
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                       0x25 0xB4 0x76 0xE3 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                          0xA0 0x02 0x00 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)              
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                0xC9 0x22 0xB6 0x2B ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)                              
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0                                                   C:\Program Files (x86)\DAEMON Tools Lite\
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0                                                   0x00 0x00 0x00 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0                                                   1
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12                                                0x10 0xA0 0xC7 0x5D ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)                     
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0                                          0xA0 0x02 0x00 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12                                       0x96 0x70 0x2A 0xC7 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)                
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12                                  0x3B 0xA9 0xCF 0xF6 ...

---- EOF - GMER 2.1 ----
         
Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.4 (07.27.2015:1)
OS: Windows 7 Home Premium x64
Ran by Andree on 30.07.2015 at 13:41:10,46
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\Users\Andree\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\ytd video downloader.lnk



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader
Successfully deleted: [Folder] C:\ProgramData\ytd video downloader



~~~ Chrome


[C:\Users\Andree\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Andree\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Andree\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Andree\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.07.2015 at 13:44:22,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

FRST Logfile:
Code:
ATTFilter
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:28-07-2015
durchgeführt von Andree (Administrator) auf ANDREE-PC (30-07-2015 13:46:59)
Gestartet von C:\Users\Andree\Desktop
Geladene Profile: Andree (Verfügbare Profile: Andree)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 11 (Standard-Browser: Chrome)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Prozesse (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)

(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Beepa P/L) C:\Program Files (x86)\Fraps\fraps64.dat
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Nicht auf der Ausnahmeliste) ==================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-10] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2465088 2014-11-17] (NVIDIA Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [782008 2015-07-23] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [134368 2015-07-02] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1426058691-527678139-852453726-1000\...\Run: [AdobeBridge] => [X]
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176048 2014-11-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [157024 2014-11-21] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt64.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2012-08-23] (Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2012-08-23] (Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2012-08-23] (Acronis)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Andree\AppData\Roaming\Dropbox\bin\DropboxExt.26.dll [2015-07-07] (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicyScripts: Gruppenrichtline erkannt <======= ATTENTION

==================== Internet (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt..)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-1426058691-527678139-852453726-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-05-06] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-06] (Oracle Corporation)
Toolbar: HKLM - Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll Keine Datei
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{3E4AE2DA-E6CF-4797-A8F9-62AA205A971E}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{47466E2B-DCBA-4C55-B778-3CA49DF77B69}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{64482786-A620-4EC3-97BB-96DED8825299}: [DhcpNameServer] 172.20.10.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2013-03-21] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-24] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-06-03] (DivX, LLC)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2014-04-15] (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-06] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems)
FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff

Chrome: 
=======
CHR Profile: C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-09]
CHR Extension: (Adblock Plus) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-09-26]
CHR Extension: (Google Search) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-09]
CHR Extension: (Easy Video Downloader Express) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbcpmdpjjlhppmhfkcgbeanaanipdjbk [2013-12-26]
CHR Extension: (Bitdefender Wallet) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabcmochhfpldjekobfaaggijgohadih [2014-08-07]
CHR Extension: (ZenMate) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-07-16]
CHR Extension: (AdBlock) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-09-26]
CHR Extension: (Google Wallet) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (NotScripts) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn [2013-09-26]
CHR Extension: (Gmail) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-09]
CHR Profile: C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (YouTube) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-20]
CHR Extension: (Chrome YouTube Downloader) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cbdjiinahkdjdcdlgfimlcolkjpbooja [2015-03-05]
CHR Extension: (Adblock Plus) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-05-16]
CHR Extension: (Adblock for Youtube™) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2015-04-06]
CHR Extension: (Google Search) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-20]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-08-20]
CHR Extension: (EditThisCookie) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2015-04-18]
CHR Extension: (AdBlock) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-05-23]
CHR Extension: (Auto Refresh Plus) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hgeljhfekpckiiplhkigfehkdpldcggm [2015-05-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Twitch Now) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2015-04-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-20]
CHR Extension: (uMatrix) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ogfcmafjalglgifnmanfmnieipoejdcf [2014-12-17]
CHR Extension: (ScriptSafe) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oiigbmnaadbkfbmpbfijlflahbdbdgdf [2014-08-20]
CHR Extension: (Gmail) - C:\Users\Andree\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-20]

==================== Services (Nicht auf der Ausnahmeliste) =================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-02-06] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [887128 2015-07-23] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [461672 2015-07-23] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [461672 2015-07-23] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1213072 2015-07-23] (Avira Operations GmbH & Co. KG)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [218816 2015-07-02] (Avira Operations GmbH & Co. KG)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-11-17] (NVIDIA Corporation)
R2 hasplms; C:\Windows\system32\hasplms.exe [4683144 2014-04-29] (SafeNet Inc.)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 Micro Star SCM; C:\Program Files (x86)\S-Bar\MSIService.exe [160768 2012-04-27] (Micro-Star International Co., Ltd.) [Datei ist nicht signiert]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-07-17] ()
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-11-17] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19821376 2014-11-17] (NVIDIA Corporation)
S2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [492032 2012-03-07] () [Datei ist nicht signiert]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [Datei ist nicht signiert]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH)
S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\Unchecky_svc.exe [164600 2015-07-14] (RaMMicHaeL)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3377904 2013-07-17] (Intel® Corporation)
S3 wifimansvc; C:\Program Files (x86)\Mobile Partner\eap\wifimansvc.exe [X]

==================== Drivers (Nicht auf der Ausnahmeliste) ====================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)

R0 %ServiceName%; C:\Windows\System32\drivers\iusb3hcs.sys [16152 2012-02-26] (Intel Corporation)
S3 AF9035HB; C:\Windows\System32\Drivers\AF9035HB.sys [900480 2013-03-16] (AfaTech                  )
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-01] (Wondershare)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-07-23] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-07-23] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-02-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-02-25] (Avira Operations GmbH & Co. KG)
R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [75880 2012-03-07] (Bigfoot Networks, Inc.)
S3 btmaudio; C:\Windows\System32\drivers\btmaud.sys [80896 2012-05-21] (Motorola Solutions, Inc.)
S3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [111104 2012-05-21] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [849408 2012-06-09] (Motorola Solutions, Inc.) [Datei ist nicht signiert]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-26] (DT Soft Ltd)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331608 2014-04-29] (SafeNet Inc.)
S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [Datei ist nicht signiert]
S3 ibtfltcoex; C:\Windows\System32\DRIVERS\iBtFltCoex.sys [60928 2012-07-09] (Intel Corporation) [Datei ist nicht signiert]
R3 L1C; C:\Windows\System32\DRIVERS\e22w7x64.sys [161616 2012-03-07] (Qualcomm Atheros, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [35344 2012-09-22] (CACE Technologies, Inc.)
S3 NPF; C:\Windows\SysWOW64\drivers\NPF.sys [35344 2012-09-22] (CACE Technologies, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20800 2014-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38216 2014-10-03] (NVIDIA Corporation)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\rtwlanu.sys [986728 2012-02-10] (Realtek Semiconductor Corporation                           )
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
S3 skfiltv; C:\Windows\System32\drivers\skfiltv.sys [24064 2008-08-14] (Creative Technology Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2015-01-12] (Duplex Secure Ltd.)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [1093256 2013-03-12] (Acronis)
R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [166024 2013-03-12] (Acronis)
U3 alj4lhiq; C:\Windows\System32\Drivers\alj4lhiq.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (Null Byte Datei/Ordner)
U3 axj1oc45; C:\Windows\System32\Drivers\axj1oc45.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (Null Byte Datei/Ordner)
S3 cpudrv64; \??\C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwusb_cdcacm; system32\DRIVERS\ew_cdcacm.sys [X]
S3 hwusb_wwanecm; system32\DRIVERS\ew_wwanecm.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]

==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)


==================== Ein Monat: Erstellte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-07-30 13:46 - 2015-07-30 13:47 - 00026890 _____ C:\Users\Andree\Desktop\FRST.txt
2015-07-30 13:46 - 2015-07-30 13:47 - 00000000 ____D C:\FRST
2015-07-30 13:46 - 2015-07-30 13:46 - 02169856 _____ (Farbar) C:\Users\Andree\Desktop\FRST64.exe
2015-07-30 13:44 - 2015-07-30 13:44 - 00001392 _____ C:\Users\Andree\Desktop\JRT.txt
2015-07-30 13:38 - 2015-07-30 13:39 - 345017312 _____ C:\Users\Andree\Desktop\mp-unknownuser-sd.rar
2015-07-30 13:30 - 2015-07-30 13:30 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2015-07-29 14:20 - 2015-07-29 14:20 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-29 14:19 - 2015-07-29 14:19 - 01798176 _____ (Malwarebytes Corporation) C:\Users\Andree\Desktop\JRT.exe
2015-07-29 14:19 - 2015-07-29 14:19 - 00001062 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-29 14:19 - 2015-07-29 14:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-29 14:19 - 2015-07-29 14:19 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-29 14:19 - 2015-07-29 14:19 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-29 14:19 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-07-29 14:19 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-07-29 14:19 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-07-29 14:09 - 2015-07-15 05:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-07-29 14:09 - 2015-07-15 05:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-29 14:09 - 2015-07-15 05:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-07-29 14:09 - 2015-07-15 05:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-07-29 14:09 - 2015-07-15 04:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-07-29 14:09 - 2015-07-15 04:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-07-29 14:09 - 2015-07-15 04:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-07-29 14:09 - 2015-07-15 04:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-07-29 14:09 - 2015-07-15 03:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-29 14:09 - 2015-07-15 03:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-29 14:09 - 2015-07-09 19:58 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-29 14:09 - 2015-07-09 19:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-29 14:09 - 2015-07-09 19:58 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-29 14:09 - 2015-07-09 19:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-07-29 14:09 - 2015-07-09 19:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-07-29 14:09 - 2015-07-09 19:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-07-29 14:09 - 2015-07-09 19:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-07-29 14:09 - 2015-07-09 19:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-07-29 14:09 - 2015-07-04 20:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-29 14:09 - 2015-07-04 19:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-07-29 14:09 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-07-29 14:09 - 2015-07-02 23:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-07-29 14:09 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-07-29 14:09 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-29 14:09 - 2015-07-02 22:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-07-29 14:09 - 2015-07-02 22:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-07-29 14:09 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-29 14:09 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-07-29 14:09 - 2015-07-02 22:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-07-29 14:09 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-07-29 14:09 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-29 14:09 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-29 14:09 - 2015-07-01 22:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-29 14:09 - 2015-07-01 22:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-29 14:09 - 2015-07-01 22:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-07-29 14:09 - 2015-07-01 22:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-07-29 14:09 - 2015-07-01 22:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-07-29 14:09 - 2015-07-01 22:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-07-29 14:09 - 2015-07-01 22:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-07-29 14:09 - 2015-07-01 22:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-07-29 14:09 - 2015-07-01 22:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-07-29 14:09 - 2015-07-01 22:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-07-29 14:09 - 2015-07-01 22:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-07-29 14:09 - 2015-07-01 22:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-07-29 14:09 - 2015-07-01 22:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-07-29 14:09 - 2015-07-01 22:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-07-29 14:09 - 2015-07-01 22:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-07-29 14:09 - 2015-07-01 22:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-07-29 14:09 - 2015-07-01 22:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-07-29 14:09 - 2015-07-01 22:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-07-29 14:09 - 2015-07-01 21:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-29 14:09 - 2015-07-01 21:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-29 14:09 - 2015-07-01 21:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-29 14:09 - 2015-06-27 04:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-07-29 14:09 - 2015-06-27 04:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-29 14:09 - 2015-06-27 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-07-29 14:09 - 2015-06-27 03:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-07-29 14:09 - 2015-06-25 20:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-07-29 14:09 - 2015-06-25 19:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-07-29 14:09 - 2015-06-25 10:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-29 14:09 - 2015-06-20 22:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-07-29 14:09 - 2015-06-20 21:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-07-29 14:09 - 2015-06-20 21:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-29 14:09 - 2015-06-20 21:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-07-29 14:09 - 2015-06-20 21:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-07-29 14:09 - 2015-06-20 21:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-07-29 14:09 - 2015-06-20 21:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-07-29 14:09 - 2015-06-20 21:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-07-29 14:09 - 2015-06-20 21:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-29 14:09 - 2015-06-20 21:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-07-29 14:09 - 2015-06-20 21:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-07-29 14:09 - 2015-06-20 21:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-07-29 14:09 - 2015-06-20 21:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-07-29 14:09 - 2015-06-20 21:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-07-29 14:09 - 2015-06-20 21:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-07-29 14:09 - 2015-06-20 21:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-29 14:09 - 2015-06-20 21:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-29 14:09 - 2015-06-20 20:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-29 14:09 - 2015-06-20 20:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-07-29 14:09 - 2015-06-20 20:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-29 14:09 - 2015-06-20 20:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-07-29 14:09 - 2015-06-20 20:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-29 14:09 - 2015-06-20 20:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-07-29 14:09 - 2015-06-19 20:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-07-29 14:09 - 2015-06-19 20:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-07-29 14:09 - 2015-06-19 20:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-07-29 14:09 - 2015-06-19 20:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-07-29 14:09 - 2015-06-19 20:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-07-29 14:09 - 2015-06-19 20:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-07-29 14:09 - 2015-06-19 20:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-07-29 14:09 - 2015-06-19 20:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-07-29 14:09 - 2015-06-19 20:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-07-29 14:09 - 2015-06-19 20:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-07-29 14:09 - 2015-06-19 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-07-29 14:09 - 2015-06-19 19:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-07-29 14:09 - 2015-06-19 19:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-07-29 14:09 - 2015-06-19 19:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-07-29 14:09 - 2015-06-19 19:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-07-29 14:09 - 2015-06-19 19:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-07-29 14:09 - 2015-06-19 19:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-07-29 14:09 - 2015-06-19 19:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-07-29 14:09 - 2015-06-19 19:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-07-29 14:09 - 2015-06-17 19:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-29 14:09 - 2015-06-17 19:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-07-29 14:09 - 2015-06-15 23:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-07-29 14:09 - 2015-06-15 23:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-29 14:09 - 2015-06-15 23:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-29 14:09 - 2015-06-15 23:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-07-29 14:09 - 2015-06-15 23:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-07-29 14:09 - 2015-06-15 23:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-29 14:09 - 2015-06-15 23:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-07-29 14:09 - 2015-06-15 23:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-07-29 14:09 - 2015-06-15 23:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-07-29 14:09 - 2015-06-15 23:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-07-29 14:09 - 2015-06-15 23:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-07-29 14:09 - 2015-06-15 23:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-07-29 14:09 - 2015-06-11 19:57 - 06131200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-07-29 14:09 - 2015-06-11 19:57 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-07-29 14:09 - 2015-06-11 19:57 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-07-29 14:09 - 2015-06-11 19:56 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-07-29 14:09 - 2015-06-11 19:56 - 01057792 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-07-29 14:09 - 2015-06-11 19:56 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-07-29 14:09 - 2015-06-11 15:15 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-07-29 14:09 - 2015-06-09 20:03 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-29 14:09 - 2015-06-09 20:03 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-07-29 14:09 - 2015-06-02 02:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-29 14:09 - 2015-06-02 01:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-07-29 14:07 - 2015-07-25 20:07 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-29 14:07 - 2015-07-25 20:04 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-29 14:07 - 2015-07-25 20:04 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-29 14:07 - 2015-07-25 20:03 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-29 14:07 - 2015-07-25 20:03 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-29 14:07 - 2015-07-25 20:03 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-29 14:07 - 2015-07-25 20:03 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-29 14:07 - 2015-07-25 19:55 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-28 12:55 - 2015-07-28 11:14 - 00004933 _____ C:\Windows\system32\Drivers\etc\hosts.20150728-125517.backup
2015-07-28 12:50 - 2015-07-28 13:51 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-07-28 12:50 - 2015-07-28 13:08 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-07-28 12:50 - 2015-07-28 12:50 - 00001351 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-07-28 12:50 - 2015-07-28 12:50 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2015-07-28 12:50 - 2015-07-28 12:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-07-28 12:50 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-07-28 11:13 - 2015-07-29 12:42 - 00000000 ____D C:\AdwCleaner
2015-07-27 12:19 - 2015-07-30 13:40 - 00000000 ____D C:\Users\Andree\Desktop\Neuer Ordner
2015-07-23 20:05 - 2015-07-23 20:05 - 00000000 ____D C:\Users\Andree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-07-22 18:20 - 2015-07-22 18:21 - 00000000 ____D C:\Users\Andree\Desktop\Mark Lauren
2015-07-09 14:00 - 2015-07-09 14:16 - 83473451 _____ C:\Users\Andree\Documents\2234495.mp4
2015-07-09 13:45 - 2015-07-12 14:16 - 00000000 ____D C:\Users\Andree\Documents\Maik
2015-07-07 14:18 - 2015-07-22 11:53 - 00010171 _____ C:\Users\Andree\Desktop\Fitness Ergebnisse.xlsx
2015-07-04 16:59 - 2015-07-04 16:59 - 00000000 ____D C:\Users\Andree\AppData\Local\CEF

==================== Ein Monat: Geänderte Dateien und Ordner ========

(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)

2015-07-30 13:40 - 2013-03-26 14:25 - 00000000 ____D C:\Users\Andree\AppData\Roaming\vlc
2015-07-30 13:35 - 2013-03-12 01:00 - 00000000 ____D C:\ISOS
2015-07-30 13:34 - 2015-02-08 21:31 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2015-07-30 13:30 - 2015-03-13 13:59 - 00000000 ____D C:\ProgramData\Unchecky
2015-07-30 13:26 - 2013-03-12 14:43 - 00000000 ____D C:\Users\Andree\AppData\Roaming\Skype
2015-07-30 13:05 - 2015-05-17 10:36 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-30 13:02 - 2013-03-26 15:57 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-30 12:55 - 2015-06-20 14:55 - 00001228 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1426058691-527678139-852453726-1000UA.job
2015-07-30 12:31 - 2013-06-12 12:16 - 01348944 _____ C:\Windows\WindowsUpdate.log
2015-07-30 12:01 - 2009-07-14 06:45 - 00027328 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-30 12:01 - 2009-07-14 06:45 - 00027328 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-30 11:55 - 2015-06-20 14:55 - 00001176 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1426058691-527678139-852453726-1000Core.job
2015-07-30 11:52 - 2014-08-20 18:10 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-30 11:44 - 2015-03-13 12:14 - 00001080 _____ C:\Users\Public\Desktop\Avira.lnk
2015-07-30 11:44 - 2015-03-13 12:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-07-30 11:44 - 2013-09-20 10:56 - 00000000 ____D C:\ProgramData\Package Cache
2015-07-30 11:43 - 2015-02-07 17:07 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d042e7c6d3627a.job
2015-07-29 16:34 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-07-29 15:34 - 2014-02-05 16:38 - 00000000 ____D C:\Users\Andree\Documents\Dienstplan Programm
2015-07-29 14:41 - 2011-05-16 16:04 - 05060010 _____ C:\Windows\system32\perfh007.dat
2015-07-29 14:41 - 2011-05-16 16:04 - 01544818 _____ C:\Windows\system32\perfc007.dat
2015-07-29 14:41 - 2009-07-14 07:13 - 00006248 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-29 14:36 - 2013-03-13 13:54 - 00003182 _____ C:\Windows\System32\Tasks\FRAPS
2015-07-29 14:36 - 2013-03-12 16:08 - 00000000 ____D C:\Program Files (x86)\Fraps
2015-07-29 14:35 - 2015-03-31 15:22 - 00003250 _____ C:\Windows\setupact.log
2015-07-29 14:35 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-29 14:30 - 2015-03-31 15:22 - 00401224 _____ C:\Windows\PFRO.log
2015-07-29 14:30 - 2009-07-14 06:45 - 04968672 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-29 14:29 - 2015-06-16 14:09 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-07-29 14:29 - 2015-06-16 14:09 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-29 14:20 - 2013-10-08 14:31 - 00000000 ____D C:\Users\Andree\AppData\Roaming\IObit
2015-07-29 14:16 - 2013-11-22 12:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-29 14:12 - 2015-06-16 14:09 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-29 14:12 - 2014-05-07 10:55 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-29 14:12 - 2013-07-22 15:34 - 00000000 ____D C:\Windows\system32\MRT
2015-07-29 12:18 - 2013-04-29 15:17 - 00000000 ___RD C:\Users\Andree\Dropbox
2015-07-29 12:18 - 2013-04-29 15:02 - 00000000 ____D C:\Users\Andree\AppData\Roaming\Dropbox
2015-07-29 12:05 - 2015-06-29 19:00 - 11987968 _____ C:\Users\Andree\Desktop\Bilbao.xlsx
2015-07-27 13:14 - 2013-03-26 16:27 - 00000000 ____D C:\Program Files (x86)\JDownloader 2
2015-07-26 20:29 - 2014-07-17 00:36 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-07-26 12:54 - 2014-11-13 13:41 - 00000000 ____D C:\Program Files (x86)\Steam
2015-07-23 20:47 - 2015-03-13 12:12 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-07-23 20:47 - 2015-03-13 12:12 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-07-19 18:53 - 2015-05-27 17:17 - 00009975 _____ C:\Users\Andree\Desktop\haushalt.xlsx
2015-07-18 11:50 - 2015-06-20 14:55 - 00004204 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1426058691-527678139-852453726-1000UA
2015-07-18 11:50 - 2015-06-20 14:55 - 00003808 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1426058691-527678139-852453726-1000Core
2015-07-17 10:03 - 2013-06-06 12:17 - 00000000 ____D C:\ProgramData\CanonIJPLM
2015-07-16 11:00 - 2015-05-17 10:36 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d042e7c6d3627a
2015-07-16 11:00 - 2013-06-12 10:57 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-15 17:02 - 2013-03-26 15:57 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-15 17:02 - 2013-03-12 01:08 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-15 17:02 - 2013-03-12 01:08 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-15 10:59 - 2015-04-19 14:59 - 00000000 ____D C:\Users\Andree\AppData\Roaming\Kodi
2015-07-12 23:05 - 2014-12-08 13:42 - 00000000 ____D C:\Program Files (x86)\Miranda IM
2015-07-12 23:03 - 2013-08-27 16:35 - 00412160 ___SH C:\Users\Andree\Documents\Thumbs.db
2015-07-06 09:42 - 2015-03-13 12:12 - 00000000 ____D C:\Program Files (x86)\Avira
2015-07-03 16:17 - 2015-06-29 19:26 - 00166012 _____ C:\Users\Andree\Desktop\PSO Saison 1 -Rückrunde .xlsx
2015-07-03 08:43 - 2013-03-14 15:31 - 130333168 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-07-02 22:06 - 2015-06-16 13:44 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-02 22:06 - 2013-03-12 14:43 - 00000000 ____D C:\ProgramData\Skype

==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======

2014-10-01 16:15 - 2014-10-01 16:15 - 0001315 _____ () C:\Users\Andree\AppData\Roaming\SAS7_000.DAT
2014-08-07 16:46 - 2014-08-07 16:46 - 0000058 _____ () C:\Users\Andree\AppData\Local\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2015-04-11 11:35 - 2015-04-11 11:35 - 0000845 _____ () C:\Users\Andree\AppData\Local\recently-used.xbel
2013-03-14 16:26 - 2013-03-28 19:57 - 0000097 _____ () C:\ProgramData\CameraRecorder.ini
2013-04-27 13:13 - 2013-11-19 21:30 - 0005732 _____ () C:\ProgramData\flcd_proxy.log

Einige Dateien in TEMP:
====================
C:\Users\Andree\AppData\Local\Temp\avgnt.exe
C:\Users\Andree\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpukzbxe.dll
C:\Users\Andree\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Andree\AppData\Local\Temp\Quarantine.exe
C:\Users\Andree\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)

C:\Windows\System32\winlogon.exe => Datei ist digital signiert
C:\Windows\System32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\System32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\System32\services.exe => Datei ist digital signiert
C:\Windows\System32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\System32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\System32\rpcss.dll => Datei ist digital signiert
C:\Windows\System32\Drivers\volsnap.sys => Datei ist digital signiert


LastRegBack: 2013-06-03 13:52

==================== Ende von log ============================
         
--- --- ---

Geändert von Gooaly (30.07.2015 um 14:02 Uhr)

 

Themen zu Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab
bereich, browser, chrome, dllhost.exe, google, hallo zusammen, klick, klicke, launch, link, regelmäßigen, safer networking, surfe, unregelmäßige, webseite, werbe, win, win7, zusammen, öffnet




Ähnliche Themen: Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab


  1. Windows 10 / Google Chrome: watch4.de öffnet sich von selbst
    Plagegeister aller Art und deren Bekämpfung - 13.11.2015 (1)
  2. Nach Klick auf einen Link öffnet sich Werbung in einem neuen Tab (Chrome)
    Log-Analyse und Auswertung - 05.08.2015 (9)
  3. Win7 (64): Chrome stürzt ab und installiert Werbe-Erweiterungen
    Log-Analyse und Auswertung - 22.02.2015 (13)
  4. Tabs öffnet sich automatisch bei google chrome
    Log-Analyse und Auswertung - 08.02.2015 (17)
  5. Google Chrome - öffnet eine andere Seite beim Starten von Google Chrome (Win7)
    Plagegeister aller Art und deren Bekämpfung - 19.01.2015 (29)
  6. Win7: Chrome öffnet selbstständig Werbe-Tabs
    Log-Analyse und Auswertung - 10.12.2014 (21)
  7. Web-Browser Google Chrome öffnet ständig Werbe-Fenster und neue Tabs
    Plagegeister aller Art und deren Bekämpfung - 15.10.2014 (11)
  8. Google Chrome öffnet eigene Werbe-Tabs (marketittzer.net - Weiterleitung zu andere Werbeseiten)
    Plagegeister aller Art und deren Bekämpfung - 21.07.2014 (24)
  9. win7: google chrome öffnet automatisch tabs mit werbung
    Log-Analyse und Auswertung - 04.06.2014 (19)
  10. win7: google chrome öffnet automatisch tabs mit werbung, danke an M-K- D-B!
    Lob, Kritik und Wünsche - 04.06.2014 (0)
  11. Maus Klick 2x statt 1x/ Google Chrome öffnet Ads trotz Adblock pro
    Plagegeister aller Art und deren Bekämpfung - 30.05.2014 (86)
  12. Google Chrome öffnet sich...
    Plagegeister aller Art und deren Bekämpfung - 11.05.2014 (60)
  13. Google Chrome öffnet sich IMMER mit Amazon-Extra-Tab
    Log-Analyse und Auswertung - 31.01.2014 (17)
  14. Fast bei jedem Klick öffnet sich ein neuer Tab mit Werbung bei firefox und bei chrome
    Plagegeister aller Art und deren Bekämpfung - 26.10.2013 (16)
  15. Google Chrome öffnet sich nach dem Startup automatisch
    Plagegeister aller Art und deren Bekämpfung - 16.10.2013 (2)
  16. win7 Internet: bei fast jedem klick öffnet sich leeres Fenster mit JVL LIBPACK.NET Verdacht auf Spyware oder Virus!
    Log-Analyse und Auswertung - 16.09.2013 (8)
  17. Nach klick auf Google Suche öffnet sich adultfinder.c0m etc.
    Log-Analyse und Auswertung - 09.11.2005 (1)

Zum Thema Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab - Hallo zusammen, habe mir wohl was eingefangen... Wenn ich mit den Chrome Browser surfe und ich einen Link auf z.B Spiegel.de klicke - öffnet sich nach klick ein WerbeTab. Passiert - Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab...
Archiv
Du betrachtest: Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.