DiggediDahl | 02.04.2014 13:38 | Hi Cosinus,
vielen Dank für deine schnelle Rückmeldung :daumenhoc
Ich habe wie von dir gewünscht, alle erforderlichen Protokolle durchlaufen lassen
und schicke dir diese Dateien anbei. Ich hoffe du kannst mir anhand Dessen weiterhelfen.
Solltest du noch etwas benötigen, lass es mich einfach wissen.
Nochmals vielen Dank für deine Hilfe und Bemühungen.
Viele Grüße
Christoph
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 02.04.2014
Suchlauf-Zeit: 12:41:25
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.02.03
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Merci
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 236788
Verstrichene Zeit: 24 Min, 38 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 107
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [11efe9177f811ae6b9b66dd2f1117b85],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [11efe9177f811ae6b9b66dd2f1117b85],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{39CB8175-E224-4446-8746-00566302DF8D}, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{39CB8175-E224-4446-8746-00566302DF8D}, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\esrv.deltaESrvc.1, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\esrv.deltaESrvc, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.deltaESrvc, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.deltaESrvc.1, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.dskBnd.1, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.dskBnd, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.dskBnd, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.dskBnd.1, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Löschen bei Neustart, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Löschen bei Neustart, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltadskBnd.1, In Quarantäne, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltadskBnd, In Quarantäne, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltadskBnd, In Quarantäne, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltadskBnd.1, In Quarantäne, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Löschen bei Neustart, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Löschen bei Neustart, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane.1, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaHlpr.1, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaHlpr, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaHlpr, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaHlpr.1, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, Löschen bei Neustart, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, Löschen bei Neustart, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane.1, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.SoftonicHlpr.1, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\Softonic.SoftonicHlpr, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.SoftonicHlpr, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Softonic.SoftonicHlpr.1, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, Löschen bei Neustart, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, Löschen bei Neustart, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, In Quarantäne, [3ac6cc34b7494ab696d891aebe4426da],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}, In Quarantäne, [a75934cc1be57090baa98fb055ad8878],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc, In Quarantäne, [6799669a04fcd52b9171c498897913ed],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1, In Quarantäne, [ac54ca3621df748c6b9786d653af0ff1],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc, In Quarantäne, [649c98682ed2c9373cc689d3e71b8080],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1, In Quarantäne, [8d734ab6a25e867ac240d48847bbe21e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\DELTA\DELTA\Instl, In Quarantäne, [c23e4db3817fd82851bd0185ee15847c],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\elchiiiejkobdbblfejjkbphbddgmljf, In Quarantäne, [57a914ec916f51afca3b84d8e81aa35d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\eooncjejnppfjjklapaamhcdmjbilmde, In Quarantäne, [dc24e020669aa759e702a1df09fa55ab],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\Softonic, In Quarantäne, [ad5305fbeb1525dbbf47184439c98f71],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Löschen bei Neustart, [e719c63a06fa3ac69d205a2645be7987],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, Löschen bei Neustart, [b64a3ec20df3926e7651bac77192e41c],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA, Löschen bei Neustart, [43bd2ad6a759d62aea6aa2dd06fd1ee2],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Löschen bei Neustart, [bb45817fe31d55ab3fdce3a1e61dc040],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Softonic, Löschen bei Neustart, [a55bfd03ac54ea16fb08065651b12bd5],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaappCore.1, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaappCore, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaappCore, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaappCore.1, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\d, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\d, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\delta, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\S, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\S, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Softonic, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
Registrierungswerte: 8
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Softonic Toolbar, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{82E1477C-B154-48D3-9891-33D83C26BCD3}, Delta Toolbar, In Quarantäne, [29d7659b718f916fde91e95555ad936d]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [48b8db255fa16d93e38caf8f42c05aa6],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [d42cfb051de321dffa1fa16801015aa6],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|tlbrSrchUrl, Löschen bei Neustart, [43bd2ad6a759d62aea6aa2dd06fd1ee2],
PUP.Optional.Delta.A, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|lastB, hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=442E00025B42036C&affID=121564&tsp=4948, Löschen bei Neustart, [7a860df359a7bf41f5e61572d82b53ad]
PUP.BProtector, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, https://www.google.de/, Löschen bei Neustart, [0bf529d7a7599967ebd49ae6a45f51af]
PUP.BProtector, HKU\S-1-5-21-1130767659-246289781-3569202006-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Löschen bei Neustart, [3cc4d8287a8637c9d0f0215f6d965ea2]
Registrierungsdaten: 1
Rogue.InternetSecurityEssentials, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll, Gut: (), Schlecht: (c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll),Ersetzt,[ab5515eb7e82dc246c0122344eb26a96]
Ordner: 18
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Roaming\Softonic, In Quarantäne, [6e922ad647b935cbd8278ad1e71b1ae6],
PUP.Optional.Delta.A, C:\Users\Merci\AppData\Roaming\Delta, In Quarantäne, [c739d62a3cc47b85b89d5b24f3106e92],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\bh, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.OpenCandy, C:\Users\Merci\AppData\Roaming\OpenCandy, In Quarantäne, [58a86898fc042dd3e535ed65a75b24dc],
PUP.Optional.OpenCandy, C:\Users\Merci\AppData\Roaming\OpenCandy\4B5274751B2D499A93FB00310049B92D, In Quarantäne, [58a86898fc042dd3e535ed65a75b24dc],
PUP.Optional.OpenCandy, C:\Users\Merci\AppData\Roaming\OpenCandy\D43CED1C240A4C838B0CB5DDB2DD0EF5, In Quarantäne, [58a86898fc042dd3e535ed65a75b24dc],
PUP.Optional.Delta.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Delta, In Quarantäne, [30d0d22e6b95bb456bcc20327092a060],
PUP.Optional.Delta.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Delta\delta, In Quarantäne, [30d0d22e6b95bb456bcc20327092a060],
PUP.Optional.Delta.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.21.5, In Quarantäne, [30d0d22e6b95bb456bcc20327092a060],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Softonic, In Quarantäne, [f20e5da3669a21df5da27bde22e005fb],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Softonic\Softonic, In Quarantäne, [f20e5da3669a21df5da27bde22e005fb],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Softonic\Softonic\1.8.21.14, In Quarantäne, [f20e5da3669a21df5da27bde22e005fb],
Dateien: 54
Rogue.InternetSecurityEssentials, C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll, Löschen bei Neustart, [ab5515eb7e82dc246c0122344eb26a96],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltasrv.exe, In Quarantäne, [46ba8c74817f29d73b7e17f5a959ca36],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll, In Quarantäne, [6898cd330000e11ffe1b55b4ab577b85],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll, In Quarantäne, [29d7659b718f916fde91e95555ad936d],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll, In Quarantäne, [b44c33cd01ff17e989e5de6021e141bf],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh\Softonic.dll, In Quarantäne, [4cb4c23e8c743ac6cc4e17f29171ed13],
PUP.Optional.Babylon.A, C:\Users\Merci\AppData\Roaming\OpenCandy\4B5274751B2D499A93FB00310049B92D\DeltaTB.exe, In Quarantäne, [3ec2ef11ad53dc24c02fe914cc34b050],
PUP.Optional.OpenCandy.A, C:\Users\Merci\AppData\Roaming\OpenCandy\D43CED1C240A4C838B0CB5DDB2DD0EF5\Setupsft_chr_p1v7.exe, In Quarantäne, [eb15d52bc63af9079173c1459c68f010],
PUP.Optional.PerformerSoft.A, C:\Users\Merci\AppData\Local\Temp\6C59.tmp, In Quarantäne, [55abe61ad22e6f91dbccba542bd644bc],
PUP.Optional.Babylon.A, C:\Users\Merci\AppData\Local\Temp\72B0.tmp, In Quarantäne, [05fb2ed21ee22cd434ec6ab449b71ae6],
PUP.Optional.Conduit.A, C:\Users\Merci\AppData\Local\Temp\D0F1.tmp, In Quarantäne, [718f9f61fe02857b2cc4e92f54ad0000],
PUP.Optional.PerformerSoft.A, C:\Users\Merci\AppData\Local\Temp\457B.tmp, In Quarantäne, [ef1113ed29d735cb1f88888644bdf50b],
PUP.Optional.OpenCandy, C:\Users\Merci\AppData\Local\Temp\FreemakeVideoConverter_4.0.2.17.exe, In Quarantäne, [f8085da3e11fa55bcce465a00bf67a86],
PUP.Optional.CRX.A, C:\Users\Merci\AppData\Local\Temp\bus7A3D\CrxUpdater_d.exe, In Quarantäne, [4cb40ff18f714bb589d96f729a69817f],
PUP.Optional.BabSolution.A, C:\Users\Merci\AppData\Local\Temp\bus7E24\BUSolution.dll, In Quarantäne, [916f9b65827eff016ef6bc482bd636ca],
PUP.Optional.CRX.A, C:\Users\Merci\AppData\Local\Temp\bus7E91\CrxUpdater_d.exe, In Quarantäne, [926e5aa6b0503dc3d19100e1bc471ce4],
PUP.Optional.CRX.A, C:\Users\Merci\AppData\Local\Temp\bus7F2D\CrxUpdater_d.exe, In Quarantäne, [629e37c9db2558a8baa82bb6689b0ff1],
PUP.Optional.CRX.A, C:\Users\Merci\AppData\Local\Temp\bus82F4\CrxUpdater_d.exe, In Quarantäne, [808045bb3ac6be42afb36879ae55a858],
PUP.Optional.Babylon.A, C:\Users\Merci\AppData\Local\Temp\AC4AF299-BAB0-7891-96D0-52045AB4F49D\Latest\BExternal.dll, In Quarantäne, [c7394cb4ba46728ed40bf032a15fe917],
PUP.Optional.Babylon.A, C:\Users\Merci\AppData\Local\Temp\AC4AF299-BAB0-7891-96D0-52045AB4F49D\Latest\ccp.exe, In Quarantäne, [0ef212eef10fab5578a8ae705da3ee12],
PUP.Optional.Babylon.A, C:\Users\Merci\AppData\Local\Temp\AC4AF299-BAB0-7891-96D0-52045AB4F49D\Latest\CrxInstaller.dll, In Quarantäne, [43bd9b656d9316ea48d0f9188c752bd5],
PUP.Optional.Delta, C:\Users\Merci\AppData\Local\Temp\AC4AF299-BAB0-7891-96D0-52045AB4F49D\Latest\MyDeltaTB.exe, In Quarantäne, [5aa612ee27d91fe183821be6b150ef11],
PUP.Optional.Babylon.A, C:\Users\Merci\AppData\Local\Temp\AC4AF299-BAB0-7891-96D0-52045AB4F49D\Latest\Setup.exe, In Quarantäne, [1ae60bf55ba59a6662c9071739c7fa06],
PUP.Optional.OpenCandy, C:\Users\Merci\Downloads\FreemakeVideoConverter14Setup.exe, In Quarantäne, [b44c0bf542bef907ab05f3129a67ef11],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Roaming\Softonic\sqlite3.dll, In Quarantäne, [6e922ad647b935cbd8278ad1e71b1ae6],
PUP.Optional.Babylon.A, C:\Windows\Tasks\EPUpdater.job, In Quarantäne, [27d96b95f808718f377793eb21e2f40c],
PUP.Optional.Delta.A, C:\Users\Merci\AppData\Roaming\Delta\sqlite3.dll, In Quarantäne, [c739d62a3cc47b85b89d5b24f3106e92],
PUP.Optional.BProtector.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data, In Quarantäne, [c43c916f0ff10ef2f12b6a1a92718f71],
PUP.Optional.BProtector.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, In Quarantäne, [27d9c33de818877995881e66bd4614ec],
PUP.Optional.BrowserDefender.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage, In Quarantäne, [b34dd9273ec29769ad736b194fb4837d],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaApp.dll, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicApp.dll, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaEng.dll, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\GUninstaller.exe, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\uninstall.exe, In Quarantäne, [699714ece31d07f90adae071a75b8977],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\appCntrl.js, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\bg.html, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\bg.js, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\chMntz.dll, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\CrmAdpt.dll, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\ct.js, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\CTB.dll, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\dpk.js, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\hprtkMsg.htm, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\hprtkMsg.js, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\json2.min.js, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\logo.png, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\manifest.json, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_1\pref.json, In Quarantäne, [19e7ee120cf44db337c6ca8f08faec14],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\softonic.crx, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicEng.dll, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\Softonicsrv.exe, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\uninstall.exe, In Quarantäne, [926e718f18e82bd5a658abae748e8878],
PUP.Optional.Softonic.A, C:\Users\Merci\AppData\Local\Temp\mt_ffx\Softonic\Softonic\1.8.21.14\softonic.xpi, In Quarantäne, [f20e5da3669a21df5da27bde22e005fb],
Physische Sektoren: 0
(No malicious items detected)
(end)
C:\AdwCleaner\AdwCleaner[Sx].txt. Code:
# AdwCleaner v3.023 - Bericht erstellt am 02/04/2014 um 12:57:32
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Merci - MERCI-PC
# Gestartet von : C:\Users\Merci\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\Program Files (x86)\Delta
Ordner Gelöscht : C:\Program Files (x86)\Softonic
Ordner Gelöscht : C:\Users\Merci\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\Merci\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Merci\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Merci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Ordner Gelöscht : C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Datei Gelöscht : C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www1.delta-search.com_0.localstorage
Datei Gelöscht : C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www1.delta-search.com_0.localstorage-journal
Datei Gelöscht : C:\Windows\System32\Tasks\BitGuard
Datei Gelöscht : C:\Windows\System32\Tasks\BrowserDefendert
Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKCU\Software\5f2dc8ce03dbf13
Schlüssel Gelöscht : HKLM\SOFTWARE\5f2dc8ce03dbf13
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16720
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
-\\ Google Chrome v
[ Datei : C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : search_url
Gelöscht : keyword
*************************
AdwCleaner[R0].txt - [7340 octets] - [02/04/2014 12:54:18]
AdwCleaner[S0].txt - [6854 octets] - [02/04/2014 12:57:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6914 octets] ##########
JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by Merci on 02.04.2014 at 13:03:49,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1130767659-246289781-3569202006-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0C4CD802-A305-4508-85C1-67115901879A}
~~~ Files
~~~ Folders
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Merci\appdata\local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.04.2014 at 13:10:36,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST.txt
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Merci (administrator) on MERCI-PC on 02-04-2014 14:09:55
Running from C:\Users\Merci\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [NVRaidService] - C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe [291944 2010-04-09] (NVIDIA Corporation)
HKLM-x32\...\Run: [RemoteControl11] - C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [230696 2011-09-14] (CyberLink Corp.)
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2489456 2010-12-17] (VIA)
HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1406248 2011-04-08] (Nero AG)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-08-27] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1130767659-246289781-3569202006-1000\...\Run: [Google Update] - C:\Users\Merci\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-08-19] (Google Inc.)
AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll File Not Found
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2072037B1E83CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{5AB22AC2-3B9A-4110-82FB-3086274302EA}: [NameServer]192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchProvider: Search the web (Softonic)
CHR DefaultSearchURL: hxxp://www.google.com
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Users\Merci\AppData\Local\Google\Chrome\Application\21.0.1180.79\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\Merci\AppData\Local\Google\Chrome\Application\33.0.1750.154\gcswf32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Merci\AppData\Local\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Merci\AppData\Local\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Google Update) - C:\Users\Merci\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Extension: (Freemake Video Converter) - C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj [2013-07-25]
CHR Extension: (Google Wallet) - C:\Users\Merci\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-27]
CHR HKLM-x32\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-07-19]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2013-03-28] (Advanced Micro Devices, Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-08-19] (ASUSTeK Computer Inc.)
R2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-08-24] ()
R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [75048 2011-09-02] (CyberLink)
R2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [292136 2011-09-02] (CyberLink)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101888 2013-07-19] (Freemake)
==================== Drivers (Whitelisted) ====================
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
R0 nvrd64; C:\Windows\System32\DRIVERS\nvrd64.sys [175720 2010-04-08] (NVIDIA Corporation)
R3 SkyNetBDA_AMD64; C:\Windows\System32\DRIVERS\SkyNetBDA_AMD64.sys [605968 2009-09-11] (TechniSat Digital, S.A.)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-09-02] (CyberLink Corp.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-02 14:08 - 2014-04-02 14:08 - 00018145 _____ () C:\Users\Merci\Desktop\FRST.txt
2014-04-02 13:12 - 2014-04-02 14:10 - 00009535 _____ () C:\Users\Merci\Downloads\FRST.txt
2014-04-02 13:10 - 2014-04-02 13:10 - 00001116 _____ () C:\Users\Merci\Desktop\JRT.txt
2014-04-02 13:03 - 2014-04-02 13:03 - 00000000 ____D () C:\Windows\ERUNT
2014-04-02 13:01 - 2014-04-02 13:01 - 00007050 _____ () C:\Users\Merci\Desktop\AdwCleaner[S0].txt
2014-04-02 12:54 - 2014-04-02 12:57 - 00000000 ____D () C:\AdwCleaner
2014-04-02 12:52 - 2014-04-02 12:52 - 00030692 _____ () C:\Users\Merci\Desktop\mbam.txt
2014-04-02 12:14 - 2014-04-02 12:46 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-02 12:14 - 2014-04-02 12:14 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-02 12:14 - 2014-04-02 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-02 12:14 - 2014-04-02 12:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-02 12:14 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-02 12:14 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-02 12:14 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 12:12 - 2014-04-02 12:12 - 01038974 _____ (Thisisu) C:\Users\Merci\Downloads\JRT.exe
2014-04-02 12:11 - 2014-04-02 12:11 - 01426178 _____ () C:\Users\Merci\Downloads\adwcleaner.exe
2014-04-02 12:10 - 2014-04-02 12:11 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Merci\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-30 19:01 - 2014-03-30 19:01 - 00000704 _____ () C:\Users\Merci\Desktop\Avira.txt
2014-03-30 18:31 - 2014-03-30 18:31 - 00006422 _____ () C:\Users\Merci\Desktop\Gmer.txt
2014-03-30 16:02 - 2014-03-30 16:02 - 00380416 _____ () C:\Users\Merci\Downloads\Gmer-19357.exe
2014-03-30 15:29 - 2014-03-30 15:30 - 00024108 _____ () C:\Users\Merci\Desktop\Addition-1.txt
2014-03-30 15:28 - 2014-04-02 14:09 - 00000000 ____D () C:\FRST
2014-03-30 15:28 - 2014-03-30 15:30 - 00016339 _____ () C:\Users\Merci\Desktop\FRST-1.txt
2014-03-30 15:27 - 2014-03-30 15:27 - 02157056 _____ (Farbar) C:\Users\Merci\Downloads\FRST64.exe
2014-03-30 15:24 - 2014-03-30 15:24 - 00000472 _____ () C:\Users\Merci\Desktop\defogger_disable.log
2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 _____ () C:\Users\Merci\defogger_reenable
2014-03-30 15:22 - 2014-03-30 15:22 - 00050477 _____ () C:\Users\Merci\Downloads\Defogger.exe
==================== One Month Modified Files and Folders =======
2014-04-02 14:10 - 2014-04-02 13:12 - 00009535 _____ () C:\Users\Merci\Downloads\FRST.txt
2014-04-02 14:09 - 2014-03-30 15:28 - 00000000 ____D () C:\FRST
2014-04-02 14:08 - 2014-04-02 14:08 - 00018145 _____ () C:\Users\Merci\Desktop\FRST.txt
2014-04-02 13:53 - 2012-08-25 17:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-02 13:16 - 2012-08-19 13:26 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000UA.job
2014-04-02 13:10 - 2014-04-02 13:10 - 00001116 _____ () C:\Users\Merci\Desktop\JRT.txt
2014-04-02 13:06 - 2009-07-14 06:45 - 00015968 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-02 13:06 - 2009-07-14 06:45 - 00015968 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-02 13:04 - 2009-07-14 19:58 - 00653928 _____ () C:\Windows\system32\perfh007.dat
2014-04-02 13:04 - 2009-07-14 19:58 - 00129800 _____ () C:\Windows\system32\perfc007.dat
2014-04-02 13:04 - 2009-07-14 07:13 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-02 13:03 - 2014-04-02 13:03 - 00000000 ____D () C:\Windows\ERUNT
2014-04-02 13:03 - 2013-01-08 19:08 - 01366123 _____ () C:\Windows\WindowsUpdate.log
2014-04-02 13:01 - 2014-04-02 13:01 - 00007050 _____ () C:\Users\Merci\Desktop\AdwCleaner[S0].txt
2014-04-02 12:58 - 2013-07-21 00:03 - 00051508 _____ () C:\Windows\PFRO.log
2014-04-02 12:58 - 2013-06-09 10:24 - 00022590 _____ () C:\Windows\setupact.log
2014-04-02 12:58 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-02 12:57 - 2014-04-02 12:54 - 00000000 ____D () C:\AdwCleaner
2014-04-02 12:52 - 2014-04-02 12:52 - 00030692 _____ () C:\Users\Merci\Desktop\mbam.txt
2014-04-02 12:46 - 2014-04-02 12:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-02 12:43 - 2012-10-21 18:11 - 00000000 ____D () C:\Windows\PCHEALTH
2014-04-02 12:14 - 2014-04-02 12:14 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-02 12:14 - 2014-04-02 12:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-02 12:14 - 2014-04-02 12:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-02 12:12 - 2014-04-02 12:12 - 01038974 _____ (Thisisu) C:\Users\Merci\Downloads\JRT.exe
2014-04-02 12:11 - 2014-04-02 12:11 - 01426178 _____ () C:\Users\Merci\Downloads\adwcleaner.exe
2014-04-02 12:11 - 2014-04-02 12:10 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Merci\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-30 19:01 - 2014-03-30 19:01 - 00000704 _____ () C:\Users\Merci\Desktop\Avira.txt
2014-03-30 18:31 - 2014-03-30 18:31 - 00006422 _____ () C:\Users\Merci\Desktop\Gmer.txt
2014-03-30 16:02 - 2014-03-30 16:02 - 00380416 _____ () C:\Users\Merci\Downloads\Gmer-19357.exe
2014-03-30 15:30 - 2014-03-30 15:29 - 00024108 _____ () C:\Users\Merci\Desktop\Addition-1.txt
2014-03-30 15:30 - 2014-03-30 15:28 - 00016339 _____ () C:\Users\Merci\Desktop\FRST-1.txt
2014-03-30 15:27 - 2014-03-30 15:27 - 02157056 _____ (Farbar) C:\Users\Merci\Downloads\FRST64.exe
2014-03-30 15:24 - 2014-03-30 15:24 - 00000472 _____ () C:\Users\Merci\Desktop\defogger_disable.log
2014-03-30 15:24 - 2014-03-30 15:24 - 00000000 _____ () C:\Users\Merci\defogger_reenable
2014-03-30 15:24 - 2012-08-18 10:39 - 00000000 ____D () C:\Users\Merci
2014-03-30 15:22 - 2014-03-30 15:22 - 00050477 _____ () C:\Users\Merci\Downloads\Defogger.exe
2014-03-30 14:16 - 2013-10-14 14:48 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000Core1cec8dbb0d3c280.job
2014-03-30 14:11 - 2013-12-08 01:58 - 00003694 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000Core1cec8dbb0d3c280
2014-03-30 14:11 - 2012-08-19 13:26 - 00004090 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000UA
2014-03-30 13:36 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-16 15:12 - 2012-08-19 13:27 - 00002356 _____ () C:\Users\Merci\Desktop\Google Chrome.lnk
2014-03-12 00:53 - 2012-08-25 17:14 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 00:53 - 2012-08-25 17:14 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-12 00:53 - 2012-08-25 17:14 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-05 09:26 - 2014-04-02 12:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-02 12:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-04-02 12:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\Merci\AppData\Local\Temp\avgnt.exe
C:\Users\Merci\AppData\Local\Temp\Quarantine.exe
C:\Users\Merci\AppData\Local\Temp\tmp7F6B.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 14:08
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by Merci at 2014-04-02 14:10:31
Running from C:\Users\Merci\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader X (10.1.7) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.7 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 12.5.100.20704 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.938.2 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{2748FDE2-7BA8-1D20-11A2-FF01CEB009A5}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2013.0328.2218.38225 - Ihr Firmenname) Hidden
AMD Media Foundation Decoders (Version: 1.0.70704.0230 - Advanced Micro Devices, Inc.) Hidden
AMD VISION Engine Control Center (x32 Version: 2013.0328.2218.38225 - Ihr Firmenname) Hidden
Apple Application Support (HKLM-x32\...\{63EC2120-1742-4625-AA47-C6A8AEC9C64C}) (Version: 2.2.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}) (Version: 6.0.0.59 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0328.2217.38225 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0328.2218.38225 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.02 - Piriform)
CyberLink PowerDVD 11 (HKLM-x32\...\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.2114.53 - CyberLink Corp.)
CyberLink PowerDVD 11 (x32 Version: 11.0.2114.53 - CyberLink Corp.) Hidden
DVBViewer Pro (HKLM-x32\...\DVBViewer Pro_is1) (Version: 4.9.6.20 - CM&V)
DVBViewer Recording Properties (Beta) (HKLM-x32\...\{F30F4040-D69D-4055-81AD-D08BF8138FD0}_is1) (Version: 2.0.0.0 - CM&V)
EPU-4 Engine (HKLM-x32\...\{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}) (Version: 1.02.01 - )
ffdshow v1.1.4052 [2011-11-20] (HKLM-x32\...\ffdshow_is1) (Version: 1.1.4052.0 - )
Freemake Video Converter Version 4.0.2 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.0.2 - Ellora Assets Corporation)
Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
High-Definition Video Playback (x32 Version: 7.3.10800.5.0 - Nero AG) Hidden
Hugo Retro Mania (HKLM-x32\...\{31902FF5-6B59-4768-BB7A-7F38B149A04F}) (Version: 1.0.0 - Krea Medie)
Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office Basic Edition 2003 (HKLM-x32\...\{91130407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 10 ClipartPack (HKLM-x32\...\{96ED4B78-300E-4033-AE6C-C115CEB4DF07}) (Version: 10.6.10000.11.0 - Nero AG)
Nero 10 Kwik Themes 1 (HKLM-x32\...\{43FBAB46-5969-4200-9958-1FF81FEE506F}) (Version: 10.6.10000.1.0 - Nero AG)
Nero 10 Kwik Themes 2 (HKLM-x32\...\{70F19404-B96C-4EBB-AD2B-3574F8736197}) (Version: 10.6.10000.2.0 - Nero AG)
Nero 10 Kwik Themes 3 (HKLM-x32\...\{DD238642-14C7-4D54-8BD7-FAD6DEA9999B}) (Version: 10.6.10000.1.0 - Nero AG)
Nero 10 Kwik Themes 4 (HKLM-x32\...\{A70B0C7B-3527-4D53-A694-E9492ECE9EE1}) (Version: 10.6.10000.1.0 - Nero AG)
Nero 10 Menu TemplatePack 1 (HKLM-x32\...\{42C8B7DF-FEB0-4D51-B169-506B6BEC5797}) (Version: 10.6.10000.0.0 - Nero AG)
Nero 10 Menu TemplatePack 2 (HKLM-x32\...\{E712C273-7564-4C8E-AA59-0FA19BC35117}) (Version: 10.6.10000.0.0 - Nero AG)
Nero 10 Menu TemplatePack 3 (HKLM-x32\...\{92146419-AE44-4C8B-A48B-0ABB1B5EC026}) (Version: 10.6.10000.1.0 - Nero AG)
Nero 10 Menu TemplatePack Basic (x32 Version: 10.6.10000.0.0 - Nero AG) Hidden
Nero 10 Movie ThemePack Basic (x32 Version: 10.6.10000.1.0 - Nero AG) Hidden
Nero 10 PiP EffectPack 1 (HKLM-x32\...\{EF3A4DAE-F16F-4AC1-87BB-FE00A784084F}) (Version: 10.6.10000.0.0 - Nero AG)
Nero 10 Sample ImagePack (HKLM-x32\...\{ACD15FDF-FC42-4175-B477-576F92FF2256}) (Version: 10.6.10000.11.0 - Nero AG)
Nero 10 Sample Videos (HKLM-x32\...\{92A10E9D-EA00-4A46-8F22-EEA660992D61}) (Version: 10.6.10000.11.0 - Nero AG)
Nero 10 Video TransitionPack 1 (HKLM-x32\...\{85BEC8F6-9AA3-43FF-B56B-8276277137B3}) (Version: 10.6.10000.0.0 - Nero AG)
Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.10400.4.100 - Nero AG)
Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero Burning ROM 10 (HKLM-x32\...\{7A5D731D-B4B3-490E-B339-75685712BAAB}) (Version: 10.6.10600.4.100 - Nero AG)
Nero BurningROM 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.4.10300.1.100 - Nero AG)
Nero BurnRights 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero Control Center 10 (x32 Version: 10.6.12600.0.5 - Nero AG) Hidden
Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero Core Components 10 (x32 Version: 2.0.19800.9.10 - Nero AG) Hidden
Nero CoverDesigner 10 (HKLM-x32\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.6.10500.3.100 - Nero AG)
Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.4.10400.0.100 - Nero AG)
Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero Dolby Files 10 (x32 Version: 2.0.13000.0.10 - Nero AG) Hidden
Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10600.4.100 - Nero AG)
Nero Express 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.4.10200.0.100 - Nero AG)
Nero InfoTool 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero Kwik Media (HKLM-x32\...\{1F7D9F37-C39C-486C-BDF8-8F440FFB3352}) (Version: 1.6.14000.46.100 - Nero AG)
Nero Multimedia Suite 10 Platinum HD (HKLM-x32\...\{277C1559-4CF7-44FF-8D07-98AA9C13AABD}) (Version: 10.6.11800 - Nero AG)
Nero Recode 10 (HKLM-x32\...\{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}) (Version: 4.10.10600.4.100 - Nero AG)
Nero Recode 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG)
Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero SoundTrax 10 (HKLM-x32\...\{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}) (Version: 4.10.10300.2.100 - Nero AG)
Nero SoundTrax 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.6.10400.2.100 - Nero AG)
Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden
Nero Vision 10 (HKLM-x32\...\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}) (Version: 7.4.10800.7.100 - Nero AG)
Nero Vision 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
Nero WaveEditor 10 (HKLM-x32\...\{EDCDFAD5-DF80-4600-A493-E9DAD6810230}) (Version: 5.10.10400.3.100 - Nero AG)
Nero WaveEditor 10 Help (CHM) (x32 Version: 10.6.10600 - Nero AG) Hidden
NeroKwikMedia Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA MediaShield (HKLM-x32\...\{CC452A50-5C87-4A1F-B295-445C3C69BF7D}) (Version: 11.1.0.43 - NVIDIA Corporation)
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2836939) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2836939v3) (Version: 3 - Microsoft Corporation)
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
VLC media player 2.0.2 (HKLM\...\VLC media player) (Version: 2.0.2 - VideoLAN)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
==================== Restore Points =========================
28-03-2014 21:29:12 Geplanter Prüfpunkt
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0B59409A-7E43-4BA9-A0BF-ED6F8B149E39} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {27CF4EFD-FDD7-4A43-9DBA-FD65DDDBFF2E} - \BrowserDefendert No Task File
Task: {28C8CF91-2F61-487D-9DDE-1732A4F029D1} - \BitGuard No Task File
Task: {39998F61-EA2F-4F2F-9C03-AE4966A20567} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-05-24] (Piriform Ltd)
Task: {6C5B5153-177D-4597-95F4-614D7B6F578D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000UA => C:\Users\Merci\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-19] (Google Inc.)
Task: {741764CD-7FDD-4BF8-9B8C-AF26C42F5036} - System32\Tasks\ASUS\ASUS SIX Engine => C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe [2010-02-03] (ASUSTeK Computer Inc.)
Task: {8DE68C0B-3D3F-4D0A-B109-5838FD45ED1E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000Core => C:\Users\Merci\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-19] (Google Inc.)
Task: {A5D437A8-C53F-4563-8E85-EFA52BA0C853} - \EPUpdater No Task File
Task: {B352CA64-4AC3-4E38-A339-C1AD0D9FB512} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000Core1cec8dbb0d3c280 => C:\Users\Merci\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-19] (Google Inc.)
Task: {CA8C1582-1A9D-4DC2-8D47-5F59CF837B97} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000Core1cec8dbb0d3c280.job => C:\Users\Merci\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1130767659-246289781-3569202006-1000UA.job => C:\Users\Merci\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2012-08-19 09:14 - 2011-08-24 03:13 - 00083240 _____ () C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
2012-08-19 09:43 - 2010-12-17 14:25 - 00078448 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2012-08-19 09:43 - 2010-12-17 14:25 - 00386160 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2012-08-19 09:43 - 2010-12-17 14:25 - 00105584 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll
2012-08-19 09:43 - 2010-12-17 14:25 - 64643696 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll
2013-03-28 22:30 - 2013-03-28 22:30 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2012-08-19 14:29 - 2013-04-05 22:27 - 02231296 _____ () C:\Windows\system32\ac3filter64.acm
2012-12-22 15:13 - 2012-09-19 19:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2012-08-19 09:46 - 2009-03-19 22:35 - 00208896 _____ () C:\Program Files (x86)\ASUS\EPU-4 Engine\AiNap.dll
2012-08-19 09:46 - 2009-03-19 22:35 - 00008704 _____ () C:\Program Files (x86)\ASUS\EPU-4 Engine\vvc.dll
2012-08-19 09:46 - 2009-01-15 14:55 - 00565248 _____ () C:\Program Files (x86)\ASUS\EPU-4 Engine\pngio.dll
2012-08-27 22:33 - 2012-08-27 22:33 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-08-27 22:33 - 2012-08-27 22:33 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-08-19 09:14 - 2011-08-26 06:57 - 00260096 _____ () C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\sqlite3.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 28%
Total physical RAM: 4095.23 MB
Available physical RAM: 2947.66 MB
Total Pagefile: 8188.63 MB
Available Pagefile: 6611.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:298 GB) (Free:206.89 GB) NTFS
Drive d: (THE_MONEY_PIT) (CDROM) (Total:6.23 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 4CDDAD27)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |