Semakalda | 09.10.2013 15:05 | So.. hier kommt's... Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013
Ran by Imperator at 2013-10-09 15:52:07 Run:1
Running from C:\Users\Imperator\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
AppInit_DLLs: c:\progra~2\bitguard\261694~1.246\{c16c1~1\bitguard.dll [ 2009-07-14] ()
c:\progra~2\bitguard
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF NewTab: hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=F8FE00225FBE77CB&affID=125035&tsp=5028
FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File
FF Plugin: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll No File
CHR Extension: (BonanzaDeals) - C:\Users\IMPERA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
R2 Update Whilokii; C:\Program Files\Whilokii\updateWhilokii.exe [65304 2013-10-05] (Whilokii)
C:\Program Files\Whilokii
C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals
C:\Program Files\BonanzaDeals
Task: {18293DDC-1DC5-4A5B-8C56-274504505F25} - System32\Tasks\FGRun => C:\Users\Imperator\AppData\Roaming\pack.exe
C:\Users\Imperator\AppData\Roaming\pack.exe
Task: {2046B0E6-35E8-4861-9B83-20764CC175E7} - System32\Tasks\EHVDI => C:\Windows\system32\irftpp.dll [2013-05-30] ()
C:\Windows\system32\irftpp.dll
Task: {41DADC08-CA9F-4D02-86AE-4BF97DD29834} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe
C:\Program Files\BonanzaDealsLive
Task: {4AAD1F4D-D5F6-4D30-8CE8-EF465DD8A571} - System32\Tasks\LaunchApp => C:\Program Files\MyPC Backup\MyPC Backup.exe
C:\Program Files\MyPC Backup
Task: {75C8B8C8-BE0D-415E-9862-6F5C2338016A} - System32\Tasks\BonanzaDealsUpdate => C:\Program
Task: {B3EA8DFE-72C7-49BA-8869-90D1A111A3CA} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\EHVDI.job => C:\Windows\system32\irftpp.dll
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_client.conduit-storage.com_0.localstorage
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage-journal
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage
C:\Users\Imperator\SyncFolder\MyPC Backup Schnellstartanleitung.pdf
C:\Users\Imperator\AppData\Roaming\Mozilla\Firefox\Profiles\0mldq2ln.default\extensions\firefox@whilokii.net.xpi
C:\Users\Imperator\AppData\Roaming\Mozilla\Firefox\Profiles\zu72yf8s.default\extensions\firefox@whilokii.net.xpi
Reg: reg delete "HKEY_CURRENT_USER\Software\BonanzaDeals" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\BonanzaDeals" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\BonanzaDealsLive" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BonanzaDealsLive.exe" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D34F391D-4CB7-467F-A543-F583857C63B0}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.OneClickCtrl.9" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.Update3WebControl.3" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsync" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsync.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass.1" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass.1" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallback" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc.1.0" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{118E1BF6-6279-432F-A285-373A77B90C7A}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CC8D970-F626-4F19-815F-890032BB6606}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33BAF587-9647-4281-A34F-F4830CDC1B9F}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6802463D-636F-41FE-9924-4CAD56906590}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{806785D0-375F-4C2C-92E3-B8EE65D28E83}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{944661E7-67B9-4DF7-BFF2-05388C166D34}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B71934E5-6B93-448D-9D32-CBAA5150C5D8}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4BEF720-313C-420A-ACF6-77DD95D8F553}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D34F391D-4CB7-467F-A543-F583857C63B0}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E970727E-0508-4BEB-8B72-BBA9D0D047C7}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF1F869-D2F0-4D31-A877-386C853A9C3D}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bonanza Deals" /f
Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2634268287-1079703000-1957501563-1000\Software\Babylon" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C430996F-4AA8-4AA8-81DE-F54432CD5786}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AD79BAD6-9504-4F09-ACEC-7B319584A4C1}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\3d3b2a1d-93ed-4789-90c4-dbd315574857" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MyPC Backup_RASAPI32" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MyPC Backup_RASMANCS" /f
Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2634268287-1079703000-1957501563-1000\Software\searchgol" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4277F7CF-0000-46CF-BA49-D624465C4BAB}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9448AC19-EB62-46D5-B7DA-B059A7DB466A}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{40B325F7-2A46-41E0-BE2F-23C19F7F101E}" /f
Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite" /f
Reg: reg delete "HKEY_CURRENT_USER\Software\Whilokii" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB4DA692-F26B-403C-AF8F-FD87D121F8F1}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B0295E2-967E-439E-9560-807D9F625B57}" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updateWhilokii_RASAPI32" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updateWhilokii_RASMANCS" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Whilokii" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Whilokii" /f
Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Update Whilokii" /f
end
*****************
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
"c:\progra~2\bitguard" => File/Directory not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
Firefox newtab deleted successfully.
HKLM\Software\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3 => Key deleted successfully.
C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll not found.
HKLM\Software\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9 => Key deleted successfully.
C:\Program Files\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll not found.
C:\Users\IMPERA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj => Moved successfully.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
Update Whilokii => Service deleted successfully.
C:\Program Files\Whilokii => Moved successfully.
C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals => Moved successfully.
C:\Program Files\BonanzaDeals => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{18293DDC-1DC5-4A5B-8C56-274504505F25} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18293DDC-1DC5-4A5B-8C56-274504505F25} => Key deleted successfully.
C:\Windows\System32\Tasks\FGRun => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FGRun => Key deleted successfully.
"C:\Users\Imperator\AppData\Roaming\pack.exe" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2046B0E6-35E8-4861-9B83-20764CC175E7} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2046B0E6-35E8-4861-9B83-20764CC175E7} => Key deleted successfully.
C:\Windows\System32\Tasks\EHVDI => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EHVDI => Key deleted successfully.
C:\Windows\system32\irftpp.dll => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{41DADC08-CA9F-4D02-86AE-4BF97DD29834} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41DADC08-CA9F-4D02-86AE-4BF97DD29834} => Key deleted successfully.
C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore => Key deleted successfully.
"C:\Program Files\BonanzaDealsLive" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AAD1F4D-D5F6-4D30-8CE8-EF465DD8A571} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AAD1F4D-D5F6-4D30-8CE8-EF465DD8A571} => Key deleted successfully.
C:\Windows\System32\Tasks\LaunchApp => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchApp => Key deleted successfully.
"C:\Program Files\MyPC Backup" => File/Directory not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{75C8B8C8-BE0D-415E-9862-6F5C2338016A} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75C8B8C8-BE0D-415E-9862-6F5C2338016A} => Key deleted successfully.
C:\Windows\System32\Tasks\BonanzaDealsUpdate => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B3EA8DFE-72C7-49BA-8869-90D1A111A3CA} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3EA8DFE-72C7-49BA-8869-90D1A111A3CA} => Key deleted successfully.
C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA => Key deleted successfully.
C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\EHVDI.job => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_client.conduit-storage.com_0.localstorage => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_facebook.conduitapps.com_0.localstorage-journal => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal => Moved successfully.
C:\Users\Imperator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage => Moved successfully.
C:\Users\Imperator\SyncFolder\MyPC Backup Schnellstartanleitung.pdf => Moved successfully.
C:\Users\Imperator\AppData\Roaming\Mozilla\Firefox\Profiles\0mldq2ln.default\extensions\firefox@whilokii.net.xpi => Moved successfully.
C:\Users\Imperator\AppData\Roaming\Mozilla\Firefox\Profiles\zu72yf8s.default\extensions\firefox@whilokii.net.xpi => Moved successfully.
========= reg delete "HKEY_CURRENT_USER\Software\BonanzaDeals" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\BonanzaDeals" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\BonanzaDealsLive" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BonanzaDealsLive.exe" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D34F391D-4CB7-467F-A543-F583857C63B0}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.OneClickCtrl.9" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLive.Update3WebControl.3" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsync" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsync.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass.1" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass.1" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallback" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc.1.0" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{118E1BF6-6279-432F-A285-373A77B90C7A}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CC8D970-F626-4F19-815F-890032BB6606}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33BAF587-9647-4281-A34F-F4830CDC1B9F}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6802463D-636F-41FE-9924-4CAD56906590}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{806785D0-375F-4C2C-92E3-B8EE65D28E83}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{944661E7-67B9-4DF7-BFF2-05388C166D34}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B71934E5-6B93-448D-9D32-CBAA5150C5D8}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4BEF720-313C-420A-ACF6-77DD95D8F553}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D34F391D-4CB7-467F-A543-F583857C63B0}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E970727E-0508-4BEB-8B72-BBA9D0D047C7}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF1F869-D2F0-4D31-A877-386C853A9C3D}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bonanza Deals" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2634268287-1079703000-1957501563-1000\Software\Babylon" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C430996F-4AA8-4AA8-81DE-F54432CD5786}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AD79BAD6-9504-4F09-ACEC-7B319584A4C1}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\3d3b2a1d-93ed-4789-90c4-dbd315574857" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MyPC Backup_RASAPI32" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\MyPC Backup_RASMANCS" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2634268287-1079703000-1957501563-1000\Software\searchgol" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4277F7CF-0000-46CF-BA49-D624465C4BAB}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9448AC19-EB62-46D5-B7DA-B059A7DB466A}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{40B325F7-2A46-41E0-BE2F-23C19F7F101E}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_CURRENT_USER\Software\Whilokii" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB4DA692-F26B-403C-AF8F-FD87D121F8F1}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8B0295E2-967E-439E-9560-807D9F625B57}" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updateWhilokii_RASAPI32" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updateWhilokii_RASMANCS" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Whilokii" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Whilokii" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\eventlog\Application\Update Whilokii" /f =========
Der Vorgang wurde erfolgreich beendet.
========= End of Reg: =========
The system needs a manual reboot.
==== End of Fixlog ==== FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by Imperator (administrator) on ELI on 09-10-2013 15:56:07
Running from C:\Users\Imperator\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe
(Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Spotify Ltd) C:\Users\Imperator\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Dropbox, Inc.) C:\Users\Imperator\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TkBellExe] - c:\program files\real\realplayer\Update\realsched.exe [295512 2013-09-18] (RealNetworks, Inc.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Imperator\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-08-06] (Spotify Ltd)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
MountPoints2: G - G:\LaunchU3.exe -a
MountPoints2: {3672b7bf-ed68-11df-b12c-90059362380b} - G:\LaunchU3.exe -a
HKU\Sam\...\Policies\system: [LogonHoursAction] 2
HKU\Sam\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Imperator\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF60D6BA858AECA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {7E708261-647F-4015-975A-8295A50F5033} URL = hxxp://www.google.de/search?q={searchTerms}&rlz=1I7ADFA_deDE367
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Imperator\AppData\Roaming\Mozilla\Firefox\Profiles\0mldq2ln.default
FF DefaultSearchEngine: Wikipedia (de)
FF SelectedSearchEngine: Wikipedia (de)
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @MagellanGPS.com/CommunicationPlugin - C:\Program Files\Magellan\Magellan Communicator\npMgnPlg.dll (Magellan Navigation, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Imperator\AppData\Roaming\Mozilla\Firefox\Profiles\0mldq2ln.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: No Name - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
Chrome:
=======
CHR Extension: (RealDownloader) - C:\Users\IMPERA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0
CHR Extension: (Skype Click to Call) - C:\Users\IMPERA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0
CHR HKLM\...\Chrome\Extension: [ahmcccagmbagkpbdgpammblejlmiempb] - C:\Program Files\Spybot - Search & Destroy 2\SDChrome.crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
========================== Services (Whitelisted) =================
R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION)
R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
R2 hasplms; C:\Windows\system32\hasplms.exe [4941768 2012-06-28] (SafeNet Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Radio.fx; C:\Program Files\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 SDHookService; C:\Program Files\Spybot - Search & Destroy 2\SDHookSvc.exe [130976 2011-10-05] (Safer-Networking Ltd.)
S2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1188896 2012-07-04] (Safer-Networking Ltd.)
S2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1395736 2012-07-04] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [166528 2012-03-22] (Safer-Networking Ltd.)
==================== Drivers (Whitelisted) ====================
R2 aksfridge; C:\Windows\system32\drivers\aksfridge.sys [362496 2012-06-28] (SafeNet Inc.)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [596424 2011-08-10] (SafeNet Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-10-09] (Malwarebytes Corporation)
R1 SDHookDriver; C:\Program Files\Spybot - Search & Destroy 2\SDHookDrv32.sys [38504 2011-10-05] ()
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S2 adfs; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-09 11:56 - 2013-10-09 12:43 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-10-08 22:06 - 2013-10-08 22:08 - 00000000 ____D C:\Users\Imperator\Desktop\Logfiles
2013-10-08 21:31 - 2013-10-08 21:31 - 00139264 _____ C:\Users\Imperator\Desktop\SystemLook.exe
2013-10-08 17:12 - 2013-10-08 17:19 - 00000000 ____D C:\ProgramData\MFAData
2013-10-08 17:12 - 2013-10-08 17:12 - 04425448 _____ (AVG Technologies) C:\Users\Imperator\Downloads\avg_free_stb_all_2014_4116.exe
2013-10-08 17:12 - 2013-10-08 17:12 - 00000000 ____D C:\Users\Imperator\AppData\Local\MFAData
2013-10-08 17:12 - 2013-10-08 17:12 - 00000000 ____D C:\Users\Imperator\AppData\Local\Avg2014
2013-10-08 17:05 - 2013-10-08 17:05 - 02296952 _____ C:\Users\Imperator\Downloads\avira_free_antivirus(2).exe
2013-10-07 22:10 - 2013-10-07 22:10 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-07 22:10 - 2013-10-07 22:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-07 22:10 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-07 22:08 - 2013-10-07 22:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Imperator\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-07 21:57 - 2013-10-07 21:57 - 00000000 ____D C:\Windows\ERUNT
2013-10-07 21:01 - 2013-10-07 21:01 - 00000000 ____D C:\Users\Imperator\AppData\Local\avgchrome
2013-10-07 20:59 - 2013-10-07 21:01 - 00000000 ____D C:\AdwCleaner
2013-10-07 20:57 - 2013-10-07 20:57 - 01045226 _____ C:\Users\Imperator\Desktop\adwcleaner_3.0.0.6.exe
2013-10-07 20:54 - 2013-10-07 20:54 - 01032220 _____ (Thisisu) C:\Users\Imperator\Desktop\JRT.exe
2013-10-07 20:48 - 2013-10-07 20:48 - 01045226 _____ C:\Users\Imperator\Downloads\adwcleaner.exe
2013-10-07 17:22 - 2013-10-07 17:22 - 02296952 _____ C:\Users\Imperator\Downloads\avira_free_antivirus(1).exe
2013-10-07 16:18 - 2013-10-07 16:18 - 00000000 ____D C:\Qoobox
2013-10-07 16:17 - 2013-10-07 17:28 - 00000000 ___SD C:\32788R22FWJFW
2013-10-07 16:17 - 2013-10-07 16:17 - 00000000 ____D C:\Windows\erdnt
2013-10-07 14:48 - 2013-10-07 14:48 - 00000096 _____ C:\Users\Imperator\AppData\Roaming\WB.CFG
2013-10-07 14:48 - 2013-10-07 14:48 - 00000006 _____ C:\Users\Imperator\AppData\Roaming\WBPU-TTL.DAT
2013-10-07 13:20 - 2013-10-07 13:20 - 00377856 _____ C:\Users\Imperator\Desktop\gmer_2.1.19163.exe
2013-10-07 13:12 - 2013-10-09 15:52 - 00000000 ____D C:\Users\Imperator\SyncFolder
2013-10-07 13:10 - 2013-10-07 13:11 - 00000000 ____D C:\Users\Imperator\Desktop\Abrechnung EGfD
2013-10-07 13:01 - 2013-10-09 15:52 - 00000000 ____D C:\FRST
2013-10-07 13:00 - 2013-10-07 13:00 - 00000000 _____ C:\Users\Imperator\defogger_reenable
2013-10-07 12:59 - 2013-10-07 12:59 - 01087213 _____ (Farbar) C:\Users\Imperator\Desktop\FRST.exe
2013-10-07 12:59 - 2013-10-07 12:59 - 00050477 _____ C:\Users\Imperator\Desktop\Defogger.exe
2013-10-07 12:48 - 2013-10-07 12:48 - 00001144 _____ C:\Users\Imperator\Desktop\Continue Zip Extractor Installation.lnk
2013-09-26 12:42 - 2013-09-30 17:43 - 98512375 _____ C:\Windows\system32\뢻侈᭄g
2013-09-22 15:57 - 2013-09-22 15:57 - 00000165 ____H C:\Users\Imperator\Desktop\~$Stundenplanung.xlsx
2013-09-21 13:53 - 2013-09-21 13:53 - 98533985 _____ C:\Windows\system32\鼃᭄q
2013-09-18 23:31 - 2013-09-18 23:31 - 00001106 _____ C:\Users\Public\Desktop\RealPlayer.lnk
2013-09-18 23:31 - 2013-09-18 23:31 - 00000000 ____D C:\ProgramData\RealNetworks
2013-09-18 23:31 - 2013-09-18 23:31 - 00000000 ____D C:\Program Files\RealNetworks
2013-09-18 23:30 - 2013-09-18 23:30 - 00000000 ____D C:\Program Files\Common Files\xing shared
2013-09-12 12:51 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-12 12:51 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-12 12:51 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-12 12:51 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-12 12:51 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-12 12:51 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-12 07:00 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-12 07:00 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-12 07:00 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-12 07:00 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 23:39 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 23:39 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-11 23:39 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 23:39 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 23:39 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 23:39 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 23:39 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 23:39 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 23:39 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
==================== One Month Modified Files and Folders =======
2013-10-09 15:54 - 2013-02-13 15:22 - 00000000 ___RD C:\Users\Imperator\Dropbox
2013-10-09 15:54 - 2013-02-13 15:16 - 00000000 ____D C:\Users\Imperator\AppData\Roaming\Dropbox
2013-10-09 15:54 - 2010-02-16 11:42 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-09 15:54 - 2009-07-14 06:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-09 15:54 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-09 15:54 - 2009-07-14 06:39 - 00058182 _____ C:\Windows\setupact.log
2013-10-09 15:53 - 2010-02-15 17:28 - 01179669 _____ C:\Windows\WindowsUpdate.log
2013-10-09 15:52 - 2013-10-07 13:12 - 00000000 ____D C:\Users\Imperator\SyncFolder
2013-10-09 15:52 - 2013-10-07 13:01 - 00000000 ____D C:\FRST
2013-10-09 15:33 - 2012-04-07 14:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-09 15:13 - 2009-07-14 06:34 - 00013456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-09 15:13 - 2009-07-14 06:34 - 00013456 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-09 15:09 - 2010-02-16 11:42 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-09 12:43 - 2013-10-09 11:56 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-10-09 12:33 - 2012-04-07 14:44 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-10-09 12:33 - 2011-07-14 09:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-10-08 22:08 - 2013-10-08 22:06 - 00000000 ____D C:\Users\Imperator\Desktop\Logfiles
2013-10-08 21:31 - 2013-10-08 21:31 - 00139264 _____ C:\Users\Imperator\Desktop\SystemLook.exe
2013-10-08 20:55 - 2010-02-19 07:42 - 00182316 _____ C:\Windows\PFRO.log
2013-10-08 20:55 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\schemas
2013-10-08 17:19 - 2013-10-08 17:12 - 00000000 ____D C:\ProgramData\MFAData
2013-10-08 17:12 - 2013-10-08 17:12 - 04425448 _____ (AVG Technologies) C:\Users\Imperator\Downloads\avg_free_stb_all_2014_4116.exe
2013-10-08 17:12 - 2013-10-08 17:12 - 00000000 ____D C:\Users\Imperator\AppData\Local\MFAData
2013-10-08 17:12 - 2013-10-08 17:12 - 00000000 ____D C:\Users\Imperator\AppData\Local\Avg2014
2013-10-08 17:05 - 2013-10-08 17:05 - 02296952 _____ C:\Users\Imperator\Downloads\avira_free_antivirus(2).exe
2013-10-07 22:28 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Web
2013-10-07 22:10 - 2013-10-07 22:10 - 00001071 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-07 22:10 - 2013-10-07 22:10 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-10-07 22:08 - 2013-10-07 22:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Imperator\Desktop\mbam-setup-1.75.0.1300.exe
2013-10-07 21:57 - 2013-10-07 21:57 - 00000000 ____D C:\Windows\ERUNT
2013-10-07 21:01 - 2013-10-07 21:01 - 00000000 ____D C:\Users\Imperator\AppData\Local\avgchrome
2013-10-07 21:01 - 2013-10-07 20:59 - 00000000 ____D C:\AdwCleaner
2013-10-07 21:01 - 2010-02-15 17:50 - 00001160 _____ C:\Users\Imperator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-07 21:00 - 2010-02-23 16:09 - 00000000 ____D C:\ProgramData\ICQ
2013-10-07 20:57 - 2013-10-07 20:57 - 01045226 _____ C:\Users\Imperator\Desktop\adwcleaner_3.0.0.6.exe
2013-10-07 20:54 - 2013-10-07 20:54 - 01032220 _____ (Thisisu) C:\Users\Imperator\Desktop\JRT.exe
2013-10-07 20:48 - 2013-10-07 20:48 - 01045226 _____ C:\Users\Imperator\Downloads\adwcleaner.exe
2013-10-07 17:28 - 2013-10-07 16:17 - 00000000 ___SD C:\32788R22FWJFW
2013-10-07 17:22 - 2013-10-07 17:22 - 02296952 _____ C:\Users\Imperator\Downloads\avira_free_antivirus(1).exe
2013-10-07 17:17 - 2012-05-07 23:13 - 00000000 ____D C:\Users\Imperator\AppData\Roaming\EPSON
2013-10-07 17:13 - 2013-03-15 22:42 - 00000000 ____D C:\ProgramData\Avira
2013-10-07 16:18 - 2013-10-07 16:18 - 00000000 ____D C:\Qoobox
2013-10-07 16:17 - 2013-10-07 16:17 - 00000000 ____D C:\Windows\erdnt
2013-10-07 14:48 - 2013-10-07 14:48 - 00000096 _____ C:\Users\Imperator\AppData\Roaming\WB.CFG
2013-10-07 14:48 - 2013-10-07 14:48 - 00000006 _____ C:\Users\Imperator\AppData\Roaming\WBPU-TTL.DAT
2013-10-07 13:20 - 2013-10-07 13:20 - 00377856 _____ C:\Users\Imperator\Desktop\gmer_2.1.19163.exe
2013-10-07 13:12 - 2010-02-15 17:50 - 00000000 ____D C:\Users\Imperator
2013-10-07 13:11 - 2013-10-07 13:10 - 00000000 ____D C:\Users\Imperator\Desktop\Abrechnung EGfD
2013-10-07 13:00 - 2013-10-07 13:00 - 00000000 _____ C:\Users\Imperator\defogger_reenable
2013-10-07 12:59 - 2013-10-07 12:59 - 01087213 _____ (Farbar) C:\Users\Imperator\Desktop\FRST.exe
2013-10-07 12:59 - 2013-10-07 12:59 - 00050477 _____ C:\Users\Imperator\Desktop\Defogger.exe
2013-10-07 12:48 - 2013-10-07 12:48 - 00001144 _____ C:\Users\Imperator\Desktop\Continue Zip Extractor Installation.lnk
2013-10-05 13:07 - 2013-04-02 17:14 - 00000000 ____D C:\Users\Sam\AppData\Roaming\.minecraft
2013-10-02 14:31 - 2013-08-12 11:28 - 00021183 _____ C:\Users\Imperator\Desktop\Stundenplanung.xlsx
2013-10-01 23:58 - 2013-09-05 15:02 - 00000000 ____D C:\Users\Imperator\Desktop\KAG 2013
2013-10-01 20:17 - 2013-09-05 14:50 - 00000000 ____D C:\Users\Imperator\Desktop\Projekttage
2013-10-01 09:47 - 2012-05-09 07:33 - 00000000 ____D C:\Users\Imperator\AppData\Roaming\Spotify
2013-09-30 21:15 - 2012-03-01 17:26 - 00017556 _____ C:\Users\Imperator\Desktop\Fahrtenbuch.xlsx
2013-09-30 17:43 - 2013-09-26 12:42 - 98512375 _____ C:\Windows\system32\뢻侈᭄g
2013-09-29 21:19 - 2010-02-15 17:51 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-23 20:28 - 2012-05-09 07:34 - 00000000 ____D C:\Users\Imperator\AppData\Local\Spotify
2013-09-22 15:57 - 2013-09-22 15:57 - 00000165 ____H C:\Users\Imperator\Desktop\~$Stundenplanung.xlsx
2013-09-21 13:53 - 2013-09-21 13:53 - 98533985 _____ C:\Windows\system32\鼃᭄q
2013-09-19 23:43 - 2010-08-08 21:09 - 00000000 ____D C:\Users\Imperator\AppData\Local\Mozilla
2013-09-19 23:41 - 2013-06-08 23:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-09-19 23:41 - 2013-05-22 15:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-18 23:32 - 2012-04-27 17:44 - 00000000 ____D C:\Users\Imperator\AppData\Roaming\RealNetworks
2013-09-18 23:31 - 2013-09-18 23:31 - 00001106 _____ C:\Users\Public\Desktop\RealPlayer.lnk
2013-09-18 23:31 - 2013-09-18 23:31 - 00000000 ____D C:\ProgramData\RealNetworks
2013-09-18 23:31 - 2013-09-18 23:31 - 00000000 ____D C:\Program Files\RealNetworks
2013-09-18 23:30 - 2013-09-18 23:30 - 00000000 ____D C:\Program Files\Common Files\xing shared
2013-09-18 23:30 - 2013-02-02 11:42 - 00201872 _____ (RealNetworks, Inc.) C:\Windows\system32\rmoc3260.dll
2013-09-18 23:30 - 2013-02-02 11:41 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\msvcp71.dll
2013-09-18 23:30 - 2013-02-02 11:41 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll
2013-09-18 23:30 - 2013-02-02 11:41 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\system32\pndx5016.dll
2013-09-18 23:30 - 2013-02-02 11:41 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\system32\pndx5032.dll
2013-09-18 23:30 - 2010-05-19 20:45 - 00272896 _____ (Progressive Networks) C:\Windows\system32\pncrt.dll
2013-09-18 23:30 - 2010-02-16 11:42 - 00000000 ____D C:\ProgramData\Real
2013-09-18 23:30 - 2010-02-16 11:42 - 00000000 ____D C:\Program Files\Real
2013-09-14 11:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-09-12 13:19 - 2009-07-14 06:33 - 02373048 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-12 13:17 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-09-12 13:00 - 2010-02-17 09:43 - 00000000 ____D C:\ProgramData\Microsoft Help
Some content of TEMP:
====================
C:\Users\Imperator\AppData\Local\Temp\BackupSetup.exe
C:\Users\Imperator\AppData\Local\Temp\FileSystemView.dll
C:\Users\Imperator\AppData\Local\Temp\Quarantine.exe
C:\Users\Imperator\AppData\Local\Temp\rootsupd.exe
C:\Users\Imperator\AppData\Local\Temp\stubhelper.dll
C:\Users\Imperator\AppData\Local\Temp\_is3A0F.exe
C:\Users\Imperator\AppData\Local\Temp\_is6D20.exe
C:\Users\Sam\AppData\Local\Temp\drm_dyndata_7370014.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-08 21:25
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-10-2013
Ran by Imperator at 2013-10-09 15:57:56
Running from C:\Users\Imperator\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 4.65
Adobe AIR (Version: 3.7.0.1530)
Adobe Download Assistant (Version: 1.2.5)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
Adobe Media Player (Version: 1.8)
Adobe Reader 9.5.4 - Deutsch (Version: 9.5.4)
Amazon MP3-Downloader 1.0.17 (Version: 1.0.17)
Ankh
Ankh 2: Heart of Osiris
Ankh 3: Battle of the Gods
Audacity 1.2.6
Boingo Wi-Fi (Version: 1.7.0020)
Camera RAW Plug-In for EPSON Creativity Suite (Version: 2.3.0.0)
Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000)
Debut Video Capture Software
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Deinstallation (HKCU Version: 2.10a)
Dropbox (HKCU Version: 2.0.22)
EA Download Manager (Version: 7.3.7.4)
EPSON Attach To Email (Version: 1.01.0000)
EPSON Easy Photo Print (Version: 1.5.1.0)
EPSON File Manager (Version: 1.3.1.0)
EPSON Scan
EPSON Scan Assistant (Version: 1.10.00)
EPSON Stylus SX200_SX400_TX200_TX400 Manual
EPSON Stylus SX400 Series Printer Uninstall
Google Earth (Version: 7.1.1.1888)
Höllenjob XS
ICQ7 (Version: 7.0)
Java 7 Update 21 (Version: 7.0.210)
Java Auto Updater (Version: 2.1.9.5)
Java(TM) 6 Update 22 (Version: 6.0.220)
Lightworks (Version: 11.0.3.0)
Magellan Communicator (Version: 1.15.020)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Works (Version: 9.7.0621)
Mozilla Firefox 24.0 (x86 de) (Version: 24.0)
Mozilla Maintenance Service (Version: 24.0)
OpenOffice.org 3.3 (Version: 3.3.9567)
Prince of Persia The Sands of Time (Version: 1.00.181)
QuickTime (Version: 7.71.80.42)
RealDownloader (Version: 1.3.3)
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0)
RealPlayer (Version: 16.0.3)
RealUpgrade 1.1 (Version: 1.1.0)
Skype Click to Call (Version: 5.9.9216)
Skype™ 6.0 (Version: 6.0.126)
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
SPORE™ (Version: 1.00.0000)
Spotify (HKCU Version: 0.9.1.57.ge7405149)
Spybot - Search & Destroy 2 (Version: 2.0.6)
Steam (Version: 1.0.0.0)
Steamless Left4Dead Pack (Version: 1.0)
Sven 2 XXL
SWR RadioRecorder
Team Fortress 2
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
WinZip 14.5 (Version: 14.5.9095)
Zuma Deluxe
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {036E4140-F997-4276-AECC-6DC852F1A438} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {1F517853-7F01-47F9-8CA5-59DD7ADE07A0} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {250D578E-EBB9-406F-BF0D-00FB6947056F} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {36ECE4B8-0630-4DB5-9FE7-A044534980DB} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {3A793B0D-BEFC-4637-8257-2990C44B330C} - System32\Tasks\{46534AB3-33DD-42F0-9E9D-F9D9563E8E43} => C:\Program Files\Ankh\bin\release\Ankh.exe [2007-02-26] ()
Task: {4E78E0D3-CBFC-43A1-93FC-636EC32FC2D4} - System32\Tasks\Scan the system (Spybot - Search & Destroy) => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: {50CC10F1-0ECF-4587-AEC5-48400609EBC7} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {6211510C-D5A7-49D3-ACB0-D6F226E7200C} - System32\Tasks\{8C6685BF-6AB0-48C4-8079-A035CB3BDE32} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/abandoninstall?page=tsProgressBar
Task: {6DF0DBE0-1C67-418E-BF4D-A412FAA34E11} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {7D7592DC-1FA8-43EC-98F1-31CA3716B2C7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-16] (Google Inc.)
Task: {7EA62934-6728-4D39-BCF2-A230AC5608EA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {BD301609-A433-4BEA-A592-24CDACCDDB83} - System32\Tasks\Check for updates (Spybot - Search & Destroy) => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {C9223B25-13A8-4A67-B7DE-CDB449BFBAFD} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {DBA38E28-51D3-4FB5-A376-1857662BA353} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.)
Task: {DD4397C0-9E7A-44F3-891C-3954A1BF58E4} - System32\Tasks\Refresh immunization (Spybot - Search & Destroy) => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {E82BA8B7-38EA-40B1-8A5C-0A3FFC59305C} - System32\Tasks\{3AC48293-7E7F-45B2-969D-1F902B4F1291} => C:\Program Files\Skype\\Phone\Skype.exe [2012-11-09] (Skype Technologies S.A.)
Task: {E8C3F12B-55EC-4187-8EE5-850DF15B09C9} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2634268287-1079703000-1957501563-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {F0B1B21D-1C7E-409E-9EC5-283186C1836D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-16] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
==================== Loaded Modules (whitelisted) =============
2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Imperator\AppData\Roaming\Dropbox\bin\libcef.dll
2011-01-17 17:19 - 2012-02-20 15:47 - 00985088 _____ () C:\Program Files\OpenOffice.org 3\program\libxml2.dll
2013-06-08 23:12 - 2013-09-19 23:39 - 03279768 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-10-09 12:33 - 2013-10-09 12:33 - 16233864 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:F35AE645
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== Faulty Device Manager Devices =============
Name: adfs
Description: adfs
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: adfs
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/09/2013 02:57:37 PM) (Source: Application Hang) (User: )
Description: Programm mbam.exe, Version 1.75.0.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 10e0
Startzeit: 01cec4dc74cb9949
Endzeit: 60000
Anwendungspfad: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
Berichts-ID: c4c57252-30e1-11e3-80e9-febdd0bad704
Error: (10/08/2013 09:29:18 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (10/09/2013 03:54:23 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/09/2013 03:54:23 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.
Error: (10/09/2013 03:54:22 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!
Error: (10/09/2013 03:54:20 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Security Center Service" ist vom Dienst "Sicherheitscenter" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1058
Error: (10/09/2013 03:54:20 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (10/09/2013 03:54:20 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.
Error: (10/09/2013 03:54:20 PM) (Source: hasplms) (User: )
Description: ERROR: Sentinel LDK License Manager failed to start in a promptly manner!
Error: (10/09/2013 03:54:16 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "adfs" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/09/2013 03:54:11 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (10/09/2013 03:54:11 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Microsoft Office Sessions:
=========================
Error: (10/09/2013 02:57:37 PM) (Source: Application Hang)(User: )
Description: mbam.exe1.75.0.110e001cec4dc74cb994960000C:\Program Files\Malwarebytes' Anti-Malware\mbam.exec4c57252-30e1-11e3-80e9-febdd0bad704
Error: (10/08/2013 09:29:18 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe
CodeIntegrity Errors:
===================================
Date: 2013-10-08 21:30:21.257
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\SDHook32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 21:28:30.293
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 21:28:30.105
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 21:28:29.934
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 21:28:29.778
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 21:28:29.637
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 19:27:19.256
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 19:27:19.116
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 17:45:17.157
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2013-10-08 17:45:17.017
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume4\Program Files\Spybot - Search & Destroy 2\pcrelib.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 3582.36 MB
Available physical RAM: 2258.19 MB
Total Pagefile: 7163.02 MB
Available Pagefile: 5798.09 MB
Total Virtual: 2047.88 MB
Available Virtual: 1915.74 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:124.9 GB) (Free:10 GB) NTFS
Drive d: (Volume) (Fixed) (Total:158.4 GB) (Free:32.47 GB) NTFS
Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.61 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 4B9B8497)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=15 GB) - (Type=42)
Partition 3: (Active) - (Size=100 MB) - (Type=42)
Partition 4: (Not Active) - (Size=125 GB) - (Type=42)
==================== End Of Log ============================ P.S.:
1.Searchgol ist beim Tab öffnen weg!! :)
2. So wie's aussieht ist auch die falsche Weiterleitung weg! :D |