Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Sicheres Löschen von "PSHD-9.9" (https://www.trojaner-board.de/154981-sicheres-loeschen-pshd-9-9-a.html)

Goodfell 09.06.2014 13:54

Sicheres Löschen von "PSHD-9.9"
 
Hatte plötzlich PSHD-9.9 in meinem Browser

nach einingem Googeln hab ich Herausgefunden das es ein Virus ist.


Was muss ich nun alles tun um ihn zu entfernen ?
Brauche echt eure Hilfe...


Bin jeden einzelnem der mir hilft jetzt schonmal aus dem Herzen dankbar!!


achja mein System;
Win 7 64bit
Avast
und den Virus in Opera entdeckt

M-K-D-B 09.06.2014 14:01

:hallo:


Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 3 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo.
    Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort zu starten!


Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags:

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Danke für deine Mitarbeit!





Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Goodfell 09.06.2014 14:16

Hey Matthias,

dannke für deine Hilfe, ich schätze das wirklich sehr :)

dann wollen wir mal hier der gewünschte Log:

*wird neu gemacht

Goodfell 09.06.2014 14:17

wird neu gemacht

M-K-D-B 09.06.2014 14:20

Zitat:

S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2003-04-18] () [File not signed]
Microsoft Office 2010
Die von mir gelisteten Einträge deuten stark darauf hin, dass auf diesem Rechner Software benutzt wird, die nicht legal erworben wurde.

Supportunterbrechung
Lesestoff:
Cracks und Keygens
Den Kopierschutz von Software zu umgehen ist nach geltendem Recht illegal. Die Logfiles deuten stark darauf hin, dass du nicht legal erworbene Software einsetzt. Zudem sind Cracks und Patches aus dubioser Quelle sehr oft mit Schädlingen versehen, womit man sich also fast vorsätzlich infiziert.

Wir haben uns hier auf dem Board darauf geeinigt, dass wir an dieser Stelle nicht weiter bereinigen, da wir ein solches Vorgehen nicht unterstützen. Hinzu kommt, dass wir dich in unserer Anleitung und auch in diesem Wichtig-Thema unmissverständlich darauf hingewiesen haben, wie wir damit umgehen werden. Saubere, gute Software hat seinen Preis und die Softwarefirmen leben von diesen Einnahmen.

Unsere Hilfe beschränkt sich daher nur auf das Neuaufsetzen und Absichern deines Systems.
Fragen dazu beantworten wir dir aber weiterhin gerne und zwar in unserem Forum.


Erst wenn du deine illegale Software vom Rechner entfernt hast, können wir mit der Bereinigung fortfahren.




Wenn du die gelistete Software deinstallierst hast, führe FRST neu aus und poste wieder beide Logdateien:
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.

M-K-D-B 09.06.2014 14:31

Ändere/lösche bitte keine alten Beiträge, da ich diese Logdateien für die Recherche benötige!

Goodfell 09.06.2014 15:00

okay, sorry wusste ich nicht.

hoffe wir können nun weitermachen :)



[CODE]
FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 01
Ran by Sven (administrator) on SVEN-PC on 09-06-2014 15:55:06
Running from C:\Users\Sven\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Users\Sven\AppData\Roaming\BupSystem\bup.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Dropbox, Inc.) C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2245120 2009-07-15] (VIA)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [G Data AntiVirus Tray Application] => C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3859320 2014-06-05] (AVAST Software)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2937528 2010-05-02] ()
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Auto KTR] => C:\Users\Sven\Downloads\Dm.De.M.C.Co.Edit-PROP\Kaspersky Internet Security 2014 + Trial + Kaspersky World\Kaspersky_Internet_Security_Trial_Reset_2.1_by_Humschi_1857\KIS14 TrialReset.exe -silent
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {732ced11-838c-11df-934f-002618bca0f6} - E:\raf-skyrim.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {c6647fc0-dbee-11e1-b1d5-806e6f6e6963} - E:\setup.exe
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
AppInit_DLLs:  c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => "C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" File Not Found
Startup: C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

ProxyServer: http=;ftp=;https=;
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27BB72947FE9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}
BHO: PSHD-9.9 - {11111111-1111-1111-1111-110511291116} - C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho64.dll (PlusVHD)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: PSHD-9.9 - {11111111-1111-1111-1111-110511291116} - C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho.dll (PlusVHD)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.24.6\bh\delta.dll (Delta-search.com)
BHO-x32: OutBrowse Toolbar - {ceefadbd-a0ce-4422-a760-3b9167344e06} - C:\Users\Sven\AppData\Roaming\OutBrowseToolbar\OutBrowseToolbar.dll (Simplytech Ltd.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
BHO-x32: raving reyven - {fba50d9b-299f-43c6-9c50-55bdec9991c5} - C:\Program Files (x86)\raving reyven\ravingreyvenbho.dll (raving reyven)
BHO-x32: No Name - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} -  No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - OutBrowse Toolbar - {ceefadbd-a0ce-4422-a760-3b9167344e06} - C:\Users\Sven\AppData\Roaming\OutBrowseToolbar\OutBrowseToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
FF DefaultSearchEngine: Web Search
FF SearchEngineOrder.1: Web Search
FF SelectedSearchEngine: Web Search
FF Homepage: hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu
FF Keyword.URL: hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q=
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 - C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 - C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF user.js: detected! => C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: PSHD-9.9 - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\a54e453c-130a-4769-9333-c5ec2aa914c5@9bd7cc89-9c7c-44e9-a03b-042b92d363f0.com [2014-06-04]
FF Extension: vis - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM [2014-05-20]
FF Extension: FireJump - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\firejump@firejump.net [2012-03-10]
FF Extension: ProxTube - Unblock YouTube - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\ich@maltegoetz.de [2014-05-20]
FF Extension: Shopping-preise.de - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\mail@shopping-preise.de [2012-03-10]
FF Extension: Protegere - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\security@protegere.org [2014-06-05]
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
FF Extension: Free YouTube Download (Free Studio) Menu - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011-11-24]
FF Extension: raving reyven - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\firefox@ravingreyven.mobi.xpi [2014-03-27]
FF Extension: TrashMail.net - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\spam@trashmail.net.xpi [2011-10-11]
FF Extension: Fox!Box - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi [2011-04-03]
FF Extension: User Agent Switcher - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2011-12-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-05]
FF HKCU\...\Firefox\Extensions: [mail@shopping-preise.de] - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\mail@shopping-preise.de
FF Extension: Shopping-preise.de - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\mail@shopping-preise.de [2012-03-10]
FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\firejump@firejump.net
FF Extension: FireJump - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\firejump@firejump.net [2012-03-10]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []

Chrome:
=======
CHR Extension: (PSHD-9.9) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe [2014-06-05]
CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-05]
CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-05]
CHR Extension: (Google-Suche) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-05]
CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-05]
CHR Extension: (Google Mail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-05]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2014-05-18]
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-05]
CHR HKLM-x32\...\Chrome\Extension: [npldjlebaajpmaipffkcmdllphdglkko] - C:\Program Files (x86)\OutBrowseToolbar\chrome\OutBrowseToolbar.crx [2013-04-17]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-05] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-01] () [File not signed]
R2 bupService; C:\Users\Sven\AppData\Roaming\BupSystem\bup.exe [1005056 2014-06-04] () [File not signed]
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-06-04] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-06-04] (globalUpdate) [File not signed]
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [652360 2012-01-13] (Malwarebytes Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3772784 2010-05-10] (INCA Internet Co., Ltd.) [File not signed]
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-12] ()
S2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [97552 2012-03-22] (SANDBOXIE L.T.D)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) [File not signed]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-05] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-06-05] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-06-05] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-05] ()
R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [65912 2012-03-08] (G Data Software AG)
R3 KMWDFILTERV1; C:\Windows\System32\DRIVERS\RPGMOUSEV1.sys [24576 2009-06-10] (Windows (R) Codename Longhorn DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23152 2011-12-10] (Malwarebytes Corporation) [File not signed]
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2010-08-18] () [File not signed]
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] ()
S3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [155136 2012-05-08] (SANDBOXIE L.T.D) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.)
S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2007-10-25] () [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) [File not signed]
R2 WinRing0_1_2_0; C:\Users\Sven\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys [14544 2010-05-02] (OpenLibSys.org)
R3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
U3 ajmgdy3a; C:\Windows\System32\Drivers\ajmgdy3a.sys [0 ] (Advanced Micro Devices)
S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X]
S3 dump_wmimmc; \??\C:\Program Files (x86)\Gameforge4D\CABAL Online\GameGuard\dump_wmimmc.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-09 15:04 - 2014-06-09 15:55 - 00029774 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-09 15:04 - 2014-06-09 15:55 - 00000000 ____D () C:\FRST
2014-06-09 15:03 - 2014-06-09 15:04 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:00 - 2014-06-09 15:01 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:50 - 2014-06-09 04:50 - 00000000 ____D () C:\Windows\LastGood
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:43 - 2012-05-12 12:31 - 00121416 _____ (MotioninJoy) C:\Windows\system32\Drivers\MijXfilt.sys
2014-06-09 04:43 - 2011-12-07 19:42 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00328712 _____ (Logitech Inc.) C:\Windows\system32\MijFrc.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00074960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xusb21.sys
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-07 05:44 - 2014-06-08 06:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2014-06-07 05:44 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-06 01:14 - 2014-06-06 01:27 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-05 22:54 - 2014-06-05 22:55 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-05 10:18 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:16 - 2014-06-05 06:14 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:15 - 2014-06-05 06:14 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:15 - 2014-06-05 06:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 02:05 - 2014-06-05 02:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-05 01:52 - 2014-06-05 02:06 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:46 - 2014-06-05 04:55 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-04 15:13 - 2014-06-06 01:23 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-04 11:49 - 2014-06-09 04:51 - 00032129 _____ () C:\Windows\setupact.log
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:48 - 2014-06-05 10:13 - 00004888 _____ () C:\Windows\PFRO.log
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:21 - 2014-06-09 11:21 - 00001412 _____ () C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-5.job
2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe
2014-06-04 11:21 - 2014-06-04 11:21 - 00004442 _____ () C:\Windows\System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-5
2014-06-04 11:21 - 2014-06-04 11:21 - 00000000 ____D () C:\Program Files (x86)\raving reyven
2014-06-04 11:20 - 2014-06-09 11:25 - 00000912 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-06-04 11:20 - 2014-06-09 11:25 - 00000908 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-06-04 11:20 - 2014-06-09 11:20 - 00003440 _____ () C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-3.job
2014-06-04 11:20 - 2014-06-07 11:21 - 00000000 ____D () C:\Program Files (x86)\PSHD-9.9
2014-06-04 11:20 - 2014-06-04 11:20 - 00006470 _____ () C:\Windows\System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-3
2014-06-04 11:20 - 2014-06-04 11:20 - 00003910 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-06-04 11:20 - 2014-06-04 11:20 - 00003656 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\BupSystem
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Local\globalUpdate
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:24 - 2014-05-28 23:52 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 19:51 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 01:48 - 2014-06-04 22:12 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-05-24 19:23 - 2014-06-09 15:37 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-05-22 07:09 - 2014-05-22 07:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:11 - 2014-05-22 03:12 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:13 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini
2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini
2014-05-22 03:10 - 2014-05-22 03:13 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:09 - 2014-05-22 03:10 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-22 03:02 - 2014-05-22 03:21 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-20 02:04 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-20 02:04 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-20 02:04 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-17 02:34 - 2014-06-09 15:41 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-05-16 18:58 - 2014-05-27 03:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-15 12:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 12:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 12:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 12:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 21:46 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 21:45 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 21:45 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 21:45 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 21:45 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 21:45 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 21:45 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 21:45 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 21:45 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 21:45 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 21:45 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 16:44 - 2014-05-27 02:29 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-12 11:48 - 2014-05-27 02:27 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos

==================== One Month Modified Files and Folders =======

2014-06-09 15:56 - 2010-05-02 00:41 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-09 15:55 - 2014-06-09 15:04 - 00029774 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-09 15:55 - 2014-06-09 15:04 - 00000000 ____D () C:\FRST
2014-06-09 15:55 - 2010-05-02 11:53 - 00000000 ____D () C:\Users\Sven\AppData\Local\PMB Files
2014-06-09 15:54 - 2010-05-26 00:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-09 15:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-09 15:51 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-06-09 15:51 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-09 15:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-09 15:49 - 2009-07-14 04:34 - 00000387 _____ () C:\Windows\win.ini
2014-06-09 15:43 - 2012-02-27 23:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Dropbox
2014-06-09 15:41 - 2014-05-17 02:34 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-06-09 15:37 - 2014-05-24 19:23 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-06-09 15:35 - 2012-06-15 00:56 - 00211968 ___SH () C:\Users\Sven\Thumbs.db
2014-06-09 15:12 - 2012-07-12 11:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-09 15:04 - 2014-06-09 15:03 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:02 - 2013-04-03 00:13 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-09 15:01 - 2014-06-09 15:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 14:02 - 2013-04-03 00:13 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-09 13:42 - 2011-12-22 15:59 - 00001134 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job
2014-06-09 11:28 - 2013-04-30 15:36 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2
2014-06-09 11:25 - 2014-06-04 11:20 - 00000912 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-06-09 11:25 - 2014-06-04 11:20 - 00000908 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-06-09 11:21 - 2014-06-04 11:21 - 00001412 _____ () C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-5.job
2014-06-09 11:20 - 2014-06-04 11:20 - 00003440 _____ () C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-3.job
2014-06-09 08:17 - 2013-04-12 12:21 - 00000000 ____D () C:\Users\Sven\Downloads\01AlpaGun
2014-06-09 08:08 - 2012-08-20 16:47 - 00000000 ___RD () C:\Users\Sven\Dropbox
2014-06-09 04:52 - 2012-05-30 00:00 - 02039295 _____ () C:\Windows\WindowsUpdate.log
2014-06-09 04:52 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-09 04:52 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:51 - 2014-06-04 11:49 - 00032129 _____ () C:\Windows\setupact.log
2014-06-09 04:50 - 2014-06-09 04:50 - 00000000 ____D () C:\Windows\LastGood
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-09 01:42 - 2011-12-22 15:59 - 00001112 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job
2014-06-09 01:35 - 2010-06-20 16:07 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype
2014-06-08 23:50 - 2014-05-07 00:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DropboxMaster
2014-06-08 23:48 - 2010-05-02 00:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-08 23:48 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-08 06:33 - 2014-06-07 05:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 22:56 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-07 21:03 - 2010-08-01 05:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc
2014-06-07 11:21 - 2014-06-04 11:20 - 00000000 ____D () C:\Program Files (x86)\PSHD-9.9
2014-06-07 05:44 - 2014-06-07 05:38 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2010-05-23 16:08 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DAEMON Tools Lite
2014-06-06 06:32 - 2009-07-14 19:58 - 00717506 _____ () C:\Windows\system32\perfh007.dat
2014-06-06 06:32 - 2009-07-14 19:58 - 00155122 _____ () C:\Windows\system32\perfc007.dat
2014-06-06 06:32 - 2009-07-14 07:13 - 01657416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-06 01:27 - 2014-06-06 01:14 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-06 01:23 - 2014-06-04 15:13 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-05 23:01 - 2014-04-04 10:42 - 00000000 ____D () C:\Users\Sven\Downloads\Animus
2014-06-05 22:55 - 2014-06-05 22:54 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-05 10:18 - 2014-06-05 06:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-05 10:13 - 2014-06-04 11:48 - 00004888 _____ () C:\Windows\PFRO.log
2014-06-05 10:13 - 2012-03-07 22:30 - 00000000 ____D () C:\ProgramData\G DATA
2014-06-05 09:54 - 2012-08-20 23:32 - 00000000 ____D () C:\Users\Sven\Downloads\thc-ssl-dos
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 07:00 - 2012-10-31 02:28 - 00000000 ____D () C:\Users\Sven\Downloads\GTA 4
2014-06-05 06:56 - 2013-05-09 01:56 - 00000000 ____D () C:\Users\Sven\Downloads\DVD1
2014-06-05 06:54 - 2013-10-04 00:55 - 00000000 ____D () C:\Users\Sven\Downloads\Capo - Hallo Monaco (Fan Edition)
2014-06-05 06:53 - 2012-03-04 22:38 - 00000000 ____D () C:\Users\Sven\Downloads\Bigger.Stronger.Faster.2008.German.AC3.BRRip.Xvid-HOR
2014-06-05 06:52 - 2013-04-19 14:24 - 00000000 ____D () C:\Users\Sven\Downloads\5fu54ggrt
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:43 - 2010-05-02 01:01 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:14 - 2014-06-05 06:16 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:14 - 2014-06-05 06:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:14 - 2014-06-05 06:15 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 04:55 - 2014-06-05 01:46 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 03:13 - 2011-04-02 01:40 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Users\Sven\AppData\Local\Mozilla
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-05 03:04 - 2013-04-03 00:14 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-05 02:06 - 2014-06-05 01:52 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 02:05 - 2014-06-05 02:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-05 01:30 - 2014-03-09 11:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\JDownloader 2.0
2014-06-05 00:36 - 2012-05-25 07:38 - 00000000 ____D () C:\Users\Sven\Downloads\Celo & Abdi - Hinterhofjargon
2014-06-04 22:12 - 2014-05-29 01:48 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:24 - 2010-05-02 11:10 - 00000000 ____D () C:\Windows\pss
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:22 - 2010-05-02 01:22 - 00000000 ____D () C:\Program Files (x86)\CCleaner
2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe
2014-06-04 11:21 - 2014-06-04 11:21 - 00004442 _____ () C:\Windows\System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-5
2014-06-04 11:21 - 2014-06-04 11:21 - 00000000 ____D () C:\Program Files (x86)\raving reyven
2014-06-04 11:20 - 2014-06-04 11:20 - 00006470 _____ () C:\Windows\System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-3
2014-06-04 11:20 - 2014-06-04 11:20 - 00003910 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-06-04 11:20 - 2014-06-04 11:20 - 00003656 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\BupSystem
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Local\globalUpdate
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-31 18:15 - 2013-08-31 20:27 - 00000000 ____D () C:\Users\UpdatusUser.Sven-PC
2014-05-31 18:15 - 2013-01-23 23:29 - 00000000 ____D () C:\Users\Gast
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-30 20:02 - 2010-06-20 16:07 - 00000000 ____D () C:\ProgramData\Skype
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 20:03 - 2010-07-18 18:57 - 00000000 ____D () C:\Users\Sven\Documents\My Games
2014-05-29 19:52 - 2010-05-02 14:47 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-05-29 19:51 - 2014-05-29 08:38 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 19:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 03:49 - 2013-05-09 06:45 - 00000000 ____D () C:\Program Files (x86)\War Thunder
2014-05-28 23:52 - 2014-05-29 19:24 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-28 15:51 - 2012-08-20 16:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-28 00:55 - 2014-05-07 14:55 - 00000000 ____D () C:\Program Files (x86)\LCGenericName02
2014-05-28 00:28 - 2013-10-01 14:36 - 00000000 ____D () C:\Users\Sven\AppData\Local\ArmA 2 OA
2014-05-27 05:00 - 2012-08-21 07:08 - 00000000 ____D () C:\Users\Sven\AppData\Local\Trainer
2014-05-27 03:58 - 2014-05-16 18:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-27 02:29 - 2014-05-13 16:44 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-27 02:27 - 2014-05-12 11:48 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos
2014-05-22 18:44 - 2010-05-02 01:31 - 00168848 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-22 18:43 - 2011-09-22 15:23 - 00000000 ____D () C:\Fraps
2014-05-22 18:43 - 2009-07-14 06:45 - 00558640 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-22 07:10 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 07:05 - 2011-12-29 22:25 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-22 05:55 - 2013-09-05 05:41 - 00000000 ____D () C:\Users\Sven\Downloads\4ZuDer9
2014-05-22 03:21 - 2014-05-22 03:02 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-22 03:21 - 2012-05-07 06:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastChaosGER
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:13 - 2014-05-22 03:10 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini
2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini
2014-05-22 03:13 - 2014-05-22 03:10 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:12 - 2014-05-22 03:11 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:09 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-20 02:05 - 2014-03-09 11:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2010-05-02 14:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-20 01:49 - 2012-08-19 02:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-20 01:49 - 2012-08-19 02:55 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Wippien
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Program Files\Wippien
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-18 11:29 - 2013-06-07 06:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-18 11:29 - 2012-11-26 18:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\OpenCandy
2014-05-18 11:29 - 2011-07-16 21:42 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft
2014-05-18 11:29 - 2010-05-02 01:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-17 03:21 - 2012-07-12 11:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-17 03:21 - 2012-07-12 11:08 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-17 03:21 - 2011-10-10 11:10 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-17 03:20 - 2010-05-02 01:24 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe
2014-05-15 14:14 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 13:31 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 12:48 - 2013-08-14 04:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 12:37 - 2010-05-02 11:19 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 20:30 - 2014-05-08 18:29 - 00000000 ____D () C:\Users\Sven\Downloads\RapidLC
2014-05-12 20:46 - 2010-11-07 21:40 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-05-12 10:29 - 2013-09-30 15:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-12 10:29 - 2010-10-03 14:41 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TS3Client
2014-05-12 10:29 - 2010-05-02 01:37 - 00000000 ____D () C:\Users\Sven\Tracing
2014-05-12 10:29 - 2010-05-02 01:34 - 00000000 ____D () C:\Windows\Panther

Files to move or delete:
====================
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini


Some content of TEMP:
====================
C:\Users\Gast\AppData\Local\Temp\jre-6u39-windows-i586-iftw.exe
C:\Users\Gast\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Sven\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpp0tf5o.dll
C:\Users\Sven\AppData\Local\Temp\ose00000.exe
C:\Users\Sven\AppData\Local\Temp\proxy_vole5776260938664055177.dll
C:\Users\Sven\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Sven\AppData\Local\Temp\tmp9474.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-08 00:01

==================== End Of Log ============================

--- --- ---

--- --- ---

Goodfell 09.06.2014 15:02

FRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-06-2014 01
Ran by Sven at 2014-06-09 15:56:18
Running from C:\Users\Sven\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

7-Zip 4.65 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0465-000001000000}) (Version: 4.65.00.0 - Igor Pavlov)
Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.)
Alarm für Cobra 11 - Das Syndikat - DEMO (HKLM-x32\...\Alarm für Cobra 11 - Das Syndikat - DEMO_is1) (Version:  - dtp)
Angry Birds (HKLM-x32\...\{61637194-D4E8-45CB-8619-23CE7B637FCF}) (Version: 2.0.2 - Rovio)
Angry Birds Space (HKLM-x32\...\{40044440-4ED4-4792-8417-5EE6374F001C}) (Version: 1.1.0 - Rovio)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArmA 2 Free Uninstall (HKLM-x32\...\ArmA 2) (Version:  - )
ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\...\ARMA 2 Operation Arrowhead) (Version:  - )
ARMA 3 (HKLM-x32\...\QVJNQTM=_is1) (Version: 1 - )
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.01 - Ubisoft)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AutoHotkey 1.0.48.05 (HKLM-x32\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett)
AutoIt v3.3.8.0 (HKLM-x32\...\AutoItv3) (Version:  - AutoIt Team)
Avast License by ZeNiX [2014-03-14] (HKLM-x32\...\Avast_2050_ZeNiX [2014-03-14]_is1) (Version:  - )
avast! Pro Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2017 - Avast Software)
Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - )
AwesomiumSetup (HKLM-x32\...\{19EF99D1-7EE6-4B5E-ABEE-0B3825F703B0}) (Version: 1.00.0000 - SIX Networks GmbH)
Axife Mouse Recorder DEMO 5.01 (HKLM-x32\...\Axife Mouse Recorder DEMO_is1) (Version:  - Axife Software)
Batman Arkham City version 1.0 (HKLM-x32\...\{B531E735-8ED5-4270-ACCE-3809086FBD02}_is1) (Version: 1.0 - WB Games)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlefield 4™ Beta (HKLM-x32\...\{CFAB3721-549D-4827-A4E8-7F90192114AB}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
BattlEye (A2Free) Uninstall (HKLM-x32\...\BattlEye A2 Free) (Version:  - )
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
CPUID HWMonitor 1.21 (HKLM\...\CPUID HWMonitor_is1) (Version:  - )
Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
Cuttermaran 1.70 (HKLM-x32\...\{5F499D33-546A-442B-B0F9-4C58F3B5B6E3}) (Version: 1.7.0 - toarnold)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0337 - Disc Soft Ltd)
Dark Souls Prepare to Die Edition (HKLM-x32\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Dark Souls Prepare to Die Edition (x32 Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
DayZ Commander (HKLM-x32\...\{99C28455-E285-4639-B4C6-9F747C0C3D4C}) (Version: 0.92.90 - Dotjosh Studios)
DayZero Launcher (HKLM-x32\...\{121CAAD8-0CD7-48CC-A3E1-A1AB8C0B1086}) (Version: 01.00.004 - ZOMBIES.NU)
Delta Chrome Toolbar (HKLM-x32\...\Delta Chrome Toolbar) (Version:  - Visual Tools) <==== ATTENTION
Delta toolbar  (HKLM-x32\...\delta) (Version: 1.8.24.6 - Delta) <==== ATTENTION
Der Herr der Ringe Der Krieg im Norden Version v1.0 (HKLM-x32\...\{4F7F52F2-DFD5-4FE3-8D24-2B7CEB9980C8}_is1) (Version: v1.0 - )
Desktop Icon für Amazon (HKLM\...\DesktopIconAmazon) (Version: 1.0.1 (de) - )
DiRT 3 (HKLM-x32\...\GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}) (Version: 1.0.0000.130 - Codemasters)
DiRT 3 (x32 Version: 1.0.0000.130 - Codemasters) Hidden
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
Download Protect (HKCU\...\{132401a7-2006-4342-b43c-ccf5f02c2b01}) (Version:  - Download Protect)
Dr. Hardware 2013 13.0d (HKLM-x32\...\Dr. Hardware 2013_is1) (Version:  - Peter A. Gebhard)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
DVD Architect Studio 5.0 (HKLM-x32\...\{04DF4A51-DE2A-11E0-9AB5-F04DA23A5C58}) (Version: 5.0.156 - Sony)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2010 AI Settings (HKLM-x32\...\{C0EBA426-3C37-4DFC-B96C-1AE9263E720D}_is1) (Version: 1.0 - )
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2013 German (HKLM-x32\...\RjEyMDEz_is1) (Version: 1 - )
Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.5.0.0 - Electronic Arts)
FireJump 1.0.1.8 (HKLM-x32\...\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1) (Version: 1.0.1.8 - FireJump.net)
FLV Player 2.0 (build 25) (HKLM-x32\...\FLV Player) (Version: 2.0 (build 25) - Martijn de Visser)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free Hide IP (HKLM-x32\...\FreeHideIP) (Version: 3.9.6.6 - )
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.35.514 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.35.514 - DVDVideoSoft Ltd.)
Freemake Audio Converter Version 1.1.0 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Freemake Video Converter Version 3.0.1 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.0.1 - Ellora Assets Corporation)
German Truck Simulator 1.00 (HKLM-x32\...\German Truck Simulator) (Version: 1.00 - )
GhostMouse (HKLM-x32\...\GhostMouse_is1) (Version: Free V3.2 - ghost-mouse.com)
GIMP 2.6.8 (HKLM\...\WinGimp-2.0_is1) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Google+ RegHelper (HKLM-x32\...\de.txptr.googleplus) (Version: 1.4.0 - UNKNOWN)
Google+ RegHelper (x32 Version: 1.4.0 - UNKNOWN) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV v1.0 Eng (HKLM-x32\...\Grand Theft Auto IV_is1) (Version:  - )
GSview 4.9 (HKLM-x32\...\GSview 4.9) (Version:  - )
Gunblade Saga (HKLM-x32\...\{0AC07A77-0511-4904-9FA1-616DC9BEF50D}) (Version: 11.09.30 - Mail.Ru Games GmbH)
HyperCam 3 (HKLM-x32\...\HyperCam 3) (Version: 3.4.1205.14 - Solveig Multimedia)
IL-2 Sturmovik 1946 (HKLM-x32\...\InstallShield_{79438F1E-DEC3-443D-9DCD-FECE2D68C605}) (Version: 1.00.0000 - Ihr Firmenname)
IL-2 Sturmovik 1946 (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden
IL-2 Sturmovik Cliffs of Dover (HKLM-x32\...\IL-2 Sturmovik Cliffs of Dover_is1) (Version:  - )
Java 7 Update 21 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 27 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.270 - Sun Microsystems, Inc.)
JDownloader (HKLM-x32\...\JDownloader) (Version: 0.89 - AppWork UG (haftungsbeschränkt))
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH)
KaloMa 4.76 (HKLM-x32\...\KaloMa_is1) (Version:  - Frank Böpple)
LastChaosGER (HKLM-x32\...\{A86A50FC-7C22-478B-BAEF-82393328825F}) (Version: 1.00.000 - Barunsongames CO., LTD.)
LCGenericName02 Version 1 (HKLM-x32\...\{4AA19E32-8010-477A-8FC3-B6C1691174AD}_is1) (Version: 1 - LCGenericName02)
Macro Recorder (HKCU\...\2a7a433177cfa3a6) (Version: 5.0.0.156 - Jitbit Macro Recorder)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{368FDD4C-1D79-44B6-9E86-6A1FF6D1496E}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video Pro X6 (HKLM\...\MX.{CBC84EDA-E830-4240-9392-325C3E6D5DCA}) (Version: 13.0.3.24 - MAGIX AG)
MAGIX Video Pro X6 (Version: 13.0.3.24 - MAGIX AG) Hidden
MAGIX Video Pro X6 64 bit Update (Version: 13.0.4.2 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 1.60.1.1000 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.60.1.1000 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version:  - )
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Minecraft Beta 1.8.1 Version v1.0 (HKLM-x32\...\{1753427B-E948-4E5B-B4A1-1E7959AD9BDA}_is1) (Version: v1.0 - Godslayers)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
Mount&Blade With Fire and Sword (HKLM-x32\...\Mount&Blade With Fire and Sword) (Version:  - )
Mouse Recorder Pro 2.0.7.4 (HKLM-x32\...\{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1) (Version:  - Nemex Studios)
Move Media Player (HKCU\...\Move Media Player) (Version:  - Move Networks)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Need for Speed(TM) Hot Pursuit (HKLM-x32\...\{83A606F5-BF6F-42ED-9F33-B9F74297CDED}) (Version: 1.0.0.0 - Electronic Arts)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.43.2 - Black Tree Gaming)
NVIDIA 3D Vision Controller Driver (x32 Version: 275.33 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 326.80 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 326.80 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
NVIDIA Grafiktreiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 326.80 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA nTune (x32 Version: 1.00.0000 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2680 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 326.80 (Version: 326.80 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Next 12.01 internal build 1491 (HKLM\...\Opera 12.01.1491) (Version: 12.01.1491 - Opera Software ASA)
Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.)
OutBrowse Toolbar (HKLM-x32\...\{8462c15f-5f80-45c3-85b2-7326ab68a508}_is1) (Version:  - OutBrowse Toolbar)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.3.3.6 - Pando Networks Inc.)
PC Connectivity Solution (HKLM-x32\...\{AC599724-5755-48C1-ABE7-ABB857652930}) (Version: 8.15.0.0 - Nokia)
PC Inspector File Recovery (HKLM-x32\...\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}) (Version: 4.0 - )
Perfect Effects 3 Free (HKLM-x32\...\{B8D92680-34AC-4B76-8D95-7E95B11B5121}) (Version: 3.0.2 - onOne Software)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Pinnacle VideoSpin (HKLM-x32\...\{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}) (Version: 2.0.0.669 - Pinnacle Systems)
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
PricePeep (HKLM-x32\...\PricePeep) (Version: 2.1.0.22 - betwikx LLC) <==== ATTENTION
Pro Evolution Soccer 2010 (HKLM-x32\...\{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}) (Version: 1.03.0000 - KONAMI)
Pro Evolution Soccer 2011 (HKLM-x32\...\{1148E85C-E1AF-48E0-A29C-68DACE07E054}) (Version: 1.00.0000 - KONAMI)
Pro Evolution Soccer 2014 (HKLM-x32\...\{5EFD3544-2371-4900-8ACA-F157BA80FB0C}) (Version: 1.01.0000 - KONAMI)
Process Hacker 2.30 (r5267) (HKLM\...\Process_Hacker2_is1) (Version: 2.30.0.5267 - wj32)
Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64)
Protegere (HKLM-x32\...\Protegere) (Version:  - )
PSHD-9.9 (HKLM-x32\...\PSHD-9.9) (Version: 1.34.5.29 - PlusVHD)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden
QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version:  - )
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
raving reyven (HKLM\...\raving reyven) (Version: 2014.03.27.174842 - raving reyven)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6029 - Realtek Semiconductor Corp.)
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version:  - )
Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
SamsungConnectivityCableDriver (HKLM-x32\...\{7E84FAC8-C518-40F9-9807-7455301D6D25}) (Version: 6.83.6.2.1 - Samsung)
Sandboxie 3.66 (64-bit) (HKLM\...\Sandboxie) (Version: 3.66 - SANDBOXIE L.T.D)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.13.2.14 - Client Connect LTD) <==== ATTENTION
Ship Simulator Extremes (HKLM-x32\...\Ship Simulator Extremes_is1) (Version:  - )
shopping-preise.de - AddOn für Firefox (HKLM-x32\...\{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1) (Version: 2.81 - shopping-preise.de)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{0AA0DA00-A1D3-11E0-B9A9-005056C00008}) (Version: 10.0.176 - Sony)
StarCraft II (HKLM-x32\...\StarCraft II) (Version: 1.0.0.16117 - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strike Suit Zero (HKLM-x32\...\Strike Suit Zero) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Explorer 3.9.8 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version:  - Mister Group)
System Requirements Lab (HKLM-x32\...\{9E1BAB75-EB78-440D-94C0-A3857BE2E733}) (Version: 4.1.71.0 - Husdawg, LLC)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version:  - )
System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH)
The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00) (Version:  - )
The Elder Scrolls V: Skyrim (HKLM-x32\...\{3844035A-9429-4E54-86B0-6EE3778BA3FB}_is1) (Version: 1.1.21.0 - RAF)
The Last Remnant (HKLM-x32\...\The Last Remnant_is1) (Version:  - )
The Walking Dead: Episode 1 and 2 (HKLM-x32\...\{26B906EC-2979-4936-AED1-30CB96927F64}_is1) (Version: 1.0 - RAF)
TopSecret Biometrics Components (HKLM-x32\...\{C8BCC14C-2807-4C2D-A659-843427BF82E2}) (Version: 1.00.0000 - G DATA Software)
Tropico 4 Collectors Bundle (HKLM-x32\...\Tropico 4 Collectors Bundle_is1) (Version: 1.0 - ADDONiA)
Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version:  - Tunngle.net GmbH)
Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version:  - )
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
VIS (HKLM-x32\...\VIS) (Version:  - ) <==== ATTENTION
War Thunder Launcher 1.0.1.199 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - 2012 Gaijin Entertainment Corporation)
WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version:  - Ubisoft)
Watson (HKLM-x32\...\{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}) (Version: 1.0.0 - Windows Live Safety Center)
Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live OneCare safety scanner (HKLM-x32\...\Windows Live OneCare safety scanner) (Version:  - Microsoft Corporation)
Windows Live OneCare safety scanner (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0) (HKLM\...\BC15EA930074932BB2C4B4493C9FD4EA95087D1A) (Version: 10/12/2007 6.85.4.0 - Nokia)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )

==================== Restore Points  =========================

06-06-2014 07:03:46 Geplanter Prüfpunkt
09-06-2014 02:49:26 Gerätetreiber-Paketinstallation: www.MotioninJoy.com Microsoft Common Controller für Windows-Klasse
09-06-2014 13:45:59 Removed Microsoft Office Professional Plus 2010

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {00206791-3604-49AF-A7B6-6F9F96435F75} - System32\Tasks\{48D33453-E9D9-469F-849D-160A78897C05} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0060DF2D-C334-4E56-AC85-3BA0B4BB8C19} - System32\Tasks\{0482E8F0-DC94-4116-82C3-A524AA6EDD56} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {00DE4891-4768-4781-B8F9-D3BACDC71C60} - System32\Tasks\{5FC532AA-6E13-40F5-B394-1335CB2802E7} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {01543BE2-B3C2-432D-8625-B3E687D20ECC} - System32\Tasks\{6EA1C590-18CC-4242-A3EE-D4D863F62C44} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {028BF155-0170-4774-A4CC-20D842C89A45} - System32\Tasks\{42382861-E829-44D8-82CA-CAEE691391DD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {047FB690-D3B8-4407-BC58-CF1BEAAA9109} - System32\Tasks\{5DB0F65E-BA72-42BD-9F77-902282F494D5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {04CDF2BE-9C9E-496F-B957-1C56120C5971} - System32\Tasks\{FB0C5B4B-828E-4A3A-8E3E-5CF0415AC411} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {05290312-83EB-408E-B517-6FACAF272D54} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {05768801-9C10-4797-BA90-B0C2AFE28B74} - System32\Tasks\{3B811B6B-73E2-4C71-900E-DDFD4DF79ACD} => E:\AutoRun.exe
Task: {059CDD4F-B16C-43B6-B938-D9B530A62A51} - System32\Tasks\{9AC660E1-E379-48DA-A67E-E8AAD6BFC56E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {07DCA1A2-0AD2-4B86-B2FD-715C05CCA7AB} - System32\Tasks\{0BDE8801-35E5-4CD1-B357-8B6E6DF01DCC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {09240454-01FE-4102-9921-BBDA41827BDE} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {0A4CE36B-9B12-4B1E-B540-CA6072A90AEE} - System32\Tasks\{46F5B8DA-D479-487D-A2CB-ED1923FB1373} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0A6C2D4D-1161-4D27-B474-59BAAE8F27FB} - System32\Tasks\{531E50E7-B9D2-4660-95F5-9641C3586AAC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0A6C8C93-F7AB-43F6-A0CC-281D24D3CF72} - System32\Tasks\{E47A74B7-37CB-40DE-8AF4-D63E9E1F8C1A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0BD63AAF-49E0-4A9A-BDEF-BD66D87211E1} - System32\Tasks\{EBFB120D-5756-4184-8E28-539FF3975ED0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0C06DDDD-3F65-4B71-B0F6-EAB79FA8F6E0} - System32\Tasks\{16D23950-57D0-4260-A83C-7A9EF3BA8B10} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0D011E81-3D76-44F3-8626-D2750C23ED12} - System32\Tasks\{56327058-6A18-428D-8411-A8D80E3FD0DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0DADA3D1-96FD-46DA-A2EE-5F7F740710A8} - System32\Tasks\{C10B0F16-9D9E-44BE-B53F-2A79DD22417C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0DC20443-9129-4C90-9D0B-469A0FE8065F} - System32\Tasks\{1AD275C9-3DEC-44AE-9C34-FF6453D7FDCB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0EC1E659-64D9-4CC9-813C-2B19E5FECBF7} - System32\Tasks\{1808866F-9A73-4701-B5B8-92DDDCA1A936} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0EF04926-207E-445D-96F6-71F7BFB973C7} - System32\Tasks\{9FFEA193-9C5E-42FB-A13A-3C45B191659E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0F8CC94F-048A-4366-8240-9F01292E5C25} - System32\Tasks\{BC26F19E-C830-4EA2-85AE-3D5AA929C880} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {108C58DC-9854-44E7-A15A-E8D4A2CC38BD} - System32\Tasks\{716EAD2A-A1E3-4E82-9C02-36776753AE4D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1313A74E-8497-4CCC-B653-3430D26F947D} - System32\Tasks\{6136571D-6365-4A71-800A-9C16B89DC946} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {14CCF703-5440-4955-AE87-C0BEC0BCDF82} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-05] (AVAST Software)
Task: {151F64D7-9CE9-4B1E-B0B6-12A82939FAF7} - System32\Tasks\{8ECB201E-0FC2-497B-8C23-F10C1A93DA27} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {15666D0F-7586-4000-9932-149CDA127E6F} - System32\Tasks\{C43090F5-62C8-42D4-BADF-150BBF0A3F2B} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/go/help.faq.installer?LastError=1603
Task: {1591003B-2F48-465D-981B-7B8A41007100} - System32\Tasks\{3113EAE0-844D-46F8-A4E2-97BCA735D923} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-06-04] (globalUpdate) <==== ATTENTION
Task: {1646E41A-0620-458D-9842-6A07C0AA33EE} - System32\Tasks\{F92CFB9A-E557-47B1-A8A8-D48BF88C12E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1670DFB5-521E-472F-84EF-3AE74946A37A} - System32\Tasks\{CE9CC2D0-7509-4B2D-A43D-5BB9A1710D03} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {17BB7FAD-D2FC-49F3-AE14-A4225B06B8E3} - System32\Tasks\{28AB3BCF-EE50-484F-BE21-F66EF3461957} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {18A75256-BA65-4CDA-AB02-9A1FBCA6AC0E} - System32\Tasks\{FE6DADBB-DE8F-4BDC-87FD-D36DB2CEEAA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {18FD2294-3EDF-4904-AA67-94057FBF0BA2} - System32\Tasks\{A7523CFB-164F-4EAB-B8CC-4CADB4D534DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1B2FEB5E-2676-43C1-908A-4B640D75A679} - System32\Tasks\{86A0D00A-38FF-4988-B2A3-31B1F266576E} => C:\Program Files (x86)\Railworks 2010\RailWorks.exe
Task: {1D1F8052-52AC-44ED-B134-C4C689E7AB48} - System32\Tasks\{81E83BD6-E3AC-4909-9EAF-74158FB16614} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1D782067-0E4C-41F2-91EC-51C1CBA0F339} - System32\Tasks\{9F2389C9-E0A7-477B-9909-F031582AD6F5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1DD72608-CFA6-4AD2-B913-E3B6831F2464} - System32\Tasks\{72826905-205B-4821-8621-1D8C8E08F2BC} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe
Task: {1DF7B898-5E91-4ED8-90F1-B725BE742DCA} - System32\Tasks\{6F286A32-34B2-4E27-AF82-2D838BCB3012} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1E503B2C-0E1A-4C72-965A-09996706192C} - System32\Tasks\{4DBAEF55-EF8E-4852-B9F5-AFB4ED2630A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2199FF4C-C031-4D14-BF52-F596A11DCA8B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe
Task: {23941C5E-F5AF-4F47-ADF6-E326297ADA8A} - System32\Tasks\{F3092C73-8B09-4013-ADED-52F3D3F4B852} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {248467D6-6AE9-474E-B9D8-C2B325203880} - System32\Tasks\{C5CC5AE2-842A-40F2-BED4-FDD2C8FBED5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {258C4939-0DEC-4711-8B26-F2DAFEE63003} - System32\Tasks\{3DFE2278-9A94-4095-A89F-8E4DB9B77C0C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {25FCB770-2B27-43F5-82C6-9A99F7CF951C} - System32\Tasks\{33702D64-5E9F-4E66-B15D-57A6C7753CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {264FE3BF-A728-4ED0-8784-485E95EB9332} - System32\Tasks\{4DF0AC0C-7E9F-476A-812D-66F469EB75C5} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {26AFDCE2-62B0-4A72-9BF5-46014D9C84FE} - System32\Tasks\{C14816C9-AC1D-44B3-A1B4-2D930E834141} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {26F96DDC-18B4-4D1E-AD74-F4D4F74ABE9F} - System32\Tasks\{10C1E1CD-1BAF-4D59-A603-08BFCA24646D} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {2A71016B-03C8-4233-B859-2F22E75C79F5} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1098949856-1301053314-1890294551-1001
Task: {2C83876C-E904-40A0-BC07-504872AE2B1D} - System32\Tasks\{61B863D1-021C-4E73-897A-46FF41577FBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2CA817F9-FBB1-494E-B5BA-1A78D6C7033D} - System32\Tasks\{EF0E0319-3DD7-45C8-86EB-15DFE8C8BCDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2D6CAF9A-1CD9-4364-988E-B477F7EF5522} - System32\Tasks\{734FA937-B120-4B5C-A837-2088381DA3D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2D991809-8C7D-40DD-BDC7-D5C5636BB74C} - System32\Tasks\{48E2514F-1BB2-4C45-A316-4FBC8FD30901} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2EEFA68F-9662-4975-B6F9-786821AA4B7D} - System32\Tasks\{CBA16325-3343-4E45-8DB1-EA6FD9411E8E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2F1602D8-2D54-4CE8-AA5A-5EEF7E2A858E} - System32\Tasks\{D21EA65A-44EB-464A-9DE2-146F048CA557} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2F94047F-3A85-4824-B184-84E692DD8FDC} - System32\Tasks\{8AAC4425-84C7-473A-9176-7CDC1B945E17} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3024CA3C-1A96-4627-9537-ED118A186E67} - System32\Tasks\{E2F5210F-2631-4D91-846F-19297E04B896} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3032538E-C43C-4D03-9188-6A4F0549E71B} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {30568D3D-7971-4F36-81FD-E61631C4BB57} - System32\Tasks\{7A87D65E-FDC1-4CB9-90D4-D12D3FA46EBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {327DE954-86CA-4727-BEDB-3D552CE75DC2} - System32\Tasks\{B2F079F0-A5EA-4E87-8D44-B8520B2B3744} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {34B0DB67-D565-4912-B698-F6A3820BB42E} - System32\Tasks\{326BB3CB-2AA7-409F-8145-AE956B1109A2} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {34DC50F6-70ED-48F6-9E59-E47E80C5F6C5} - System32\Tasks\{81F3A03F-A984-4D44-8C6E-481C91E702C2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {38033478-0F98-4B7F-9FE4-F40D65526668} - System32\Tasks\{A285C147-7F6E-460C-8794-6453B4B02DDE} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {38596C41-5023-4B7B-A97A-FFCFB4638D5B} - System32\Tasks\{56D14608-B485-45C4-AFA3-D4697153A8EB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3896DA66-668F-4E13-8D8B-14701CA38B7A} - System32\Tasks\{02976DCA-3D64-4818-8AB2-D452E2EDBD39} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-3 => C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-3.exe [2014-06-04] (PlusVHD)
Task: {3BA6A538-EDC3-42E7-B0DC-94555326A0E0} - System32\Tasks\{F599B4D3-A939-427B-BFAD-41215FFA4B06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3BB70042-89B5-4A30-AC51-AB0D69BB4B48} - System32\Tasks\{3A87CEDE-5E99-4260-A802-4AA83B8A0AD3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3BC27ED0-6484-4FF7-A68A-D54328294275} - System32\Tasks\{0FEA611C-B1BF-4668-9918-41A30DF48CC3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3D42ADE7-E1E6-4302-8844-122441F4B904} - System32\Tasks\{76D5F951-BF21-4A9D-8603-7AE010F98315} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {3F5B5D63-9908-4BA1-8C99-A3C1718E5EE9} - System32\Tasks\{DBC5E996-473B-425F-9DB0-97B88D1C9349} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3FDBAE0C-A108-4561-BFDD-89C3C2F3D570} - System32\Tasks\{0BD20564-C544-4345-A074-D421C4CC49E0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {415EAC50-7423-4ECB-B27D-1D20376B9A4F} - System32\Tasks\{362EC899-4A81-4D93-96BA-13249EE94512} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {41F754B4-BA61-4685-AE07-6402385F6933} - System32\Tasks\{8AEB40A7-FA35-48F5-82EB-EA0819FB326B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {422EB8B1-2BD7-4FF0-A55D-6A3F7EBE8EDF} - System32\Tasks\{4A347536-E75E-4196-AB34-F33A32433986} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4350EF98-4350-4E0F-98FD-C4EB6ED33391} - System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618
Task: {45DC1622-0863-4EC2-8060-B48745AA713B} - System32\Tasks\{EAC80C87-0609-4B31-966F-868E17803A7B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {4737680D-7D41-4EDD-89C7-3608C0004939} - System32\Tasks\{C8071675-FABC-45F3-BF98-E3D37474BB4E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {475F81D7-458B-41BC-8A3D-9C3162F60648} - System32\Tasks\{D7CDC2B5-4F80-47C5-B6DD-1D8018821633} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {4770E7B8-7CFF-493C-9976-C434C787CD0B} - System32\Tasks\{8F1ECE0A-1A81-48B5-85BC-2B7D41547151} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {47D83C6B-CF1E-4562-96CA-C7D25840572B} - System32\Tasks\{0AA5EC75-C091-44FA-82A9-44BC0DDA59E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4A9A003A-7665-4B9E-B336-A56DE8E8789B} - System32\Tasks\{BE4896D2-6869-4B2B-8F8D-BCA1F61A2487} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B2BDB10-32EF-4B37-9AA1-B15CAD2A48F6} - System32\Tasks\{887B7566-0AAF-435D-B5EB-86E215D22677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B437054-DE44-423D-8381-6D09430DFFA9} - System32\Tasks\{CD46C27E-3FC1-4211-920C-E8A7F411CF5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B64318D-5F94-4677-BDEF-13D5B6FDFB73} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.)
Task: {4C482DEE-9E14-4738-A2C6-84243B47285E} - System32\Tasks\{65FE692F-FAE1-4833-A4E3-5B91189BDA71} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4CE83691-0839-4DF7-BB2D-16C096CA1DD9} - System32\Tasks\{DCB5B081-0D7D-4A9D-BFB6-F75BA6B4FFE4} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {4D272B4D-0F7B-4149-96B7-E92D0CE78840} - System32\Tasks\{179B45CD-DEC5-4ED2-A215-93FE8E3A3B52} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4E55A326-7F9C-456A-B061-F773C26BB4B9} - System32\Tasks\{C287E2B1-6EFF-4D09-9101-EAD7B150CB7B} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?page=tsProgressBar
Task: {4F9E67CB-A23E-4973-85EA-DC854F0C5049} - System32\Tasks\{115DA74C-5B2D-40DA-947B-BAEDFEA6A8E2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {521EC980-CAC6-4F1D-B6FA-C7BC3A98441F} - System32\Tasks\{81DCE1C0-894D-4779-A1BB-70EE95F4E4B2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {55FEEF07-8E10-45F7-85F6-11C4D8959BF6} - System32\Tasks\{B37F681A-EF3E-45CC-9F17-864119A91E65} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {56C4AFB3-803E-46C9-8C94-ACC9588F0452} - System32\Tasks\{C694B19B-E147-4FDB-9837-2D8A57B43CD8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {57D5AA40-981A-438F-B928-D3733FD29B8D} - System32\Tasks\{0D35558A-B8E3-478D-92C2-CB6CAF71D82C} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {585C0F3C-AD7C-494C-95AB-929FC93FD477} - System32\Tasks\{7D4A2968-2466-423B-8693-D892F5770BC2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {59201B3B-2CF8-44D3-BA51-AA71F9BD925B} - System32\Tasks\{2A7E476D-1AB7-4688-A479-ED4CB5FE309C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5A19A249-F795-411F-B1A5-22070127E4D8} - System32\Tasks\{3D7F2444-BC97-4FC1-A3AD-2050924AB4E4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5A75A413-5A4D-47D6-B08F-3A09AF467BA6} - System32\Tasks\{126D53C6-D39A-48FE-87A3-BE39FECA82A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5B55648B-938F-4098-AA57-C551B3F04294} - System32\Tasks\{BA7A9134-7D67-401C-8D4C-39B014EC993C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5BC20421-CD55-437D-B993-7ED3F777584D} - System32\Tasks\{92825E9C-7F09-4EF5-A901-8D20AB4C1CED} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-06-04] (globalUpdate) <==== ATTENTION
Task: {5D2C9C91-EBBD-4630-BE2B-DDB3E6EB314E} - System32\Tasks\{5CE6AC57-2F71-4A9C-B339-34847941A456} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5F627168-4146-41EC-A6E7-4139910834F3} - System32\Tasks\{0498C35C-C89F-4EDA-BA65-F25B08667C06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {63385CAB-C77F-4D19-8E64-56010138AA02} - System32\Tasks\{F9D4650D-451C-4CF7-AF96-55C9D5512DF6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {6508B54E-7342-451D-B651-920729BB2E43} - System32\Tasks\{E2A806C7-3C0D-402F-ACE6-28E8CB964BE2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {65DDD6CA-9B68-44C9-B4BC-B2360B7CB949} - System32\Tasks\{C8F7C6D2-FC04-41A4-AB21-AF4830FD735C} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {685EC281-E83D-41DF-A5CC-91A8925976AC} - System32\Tasks\{F4948F46-A30B-4C1A-B276-7F5EC91174F1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {687804B6-E9CD-4E37-9D92-D197693B397E} - System32\Tasks\{0EECE376-7CDE-44E3-84E0-72D5A5ED585D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6A8E2C17-BAEB-4DC8-A342-84DF6286A844} - System32\Tasks\{6EFAE2C9-AE73-4A53-B318-92B8924F73F6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6B8374AE-0ECA-4D2D-BB9A-45344C01B9C5} - System32\Tasks\{9325521E-959B-40C0-AE8A-DE5FABB2B06F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6BA32B1F-4293-4074-BD78-CE1A5F17ED99} - System32\Tasks\{8E72C766-9BB4-4166-9866-76139173268C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6C1979F1-AB41-4EC0-944E-0D16797FF4FD} - System32\Tasks\{454F111B-9668-405C-9D32-5B05FDF5731F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {7250271B-F6A2-470A-85A2-0168259D90A8} - System32\Tasks\{E4F229CC-7F16-4DC9-A408-AAB6CAC3F797} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {73D95EE9-648D-4C8F-8911-6B63E0A22F04} - System32\Tasks\{3E98FF82-D955-45DF-983A-3EFBA31786F9} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {757946F4-35A8-4AEC-B087-00F90BFC2B01} - System32\Tasks\{7B88D895-FA14-4844-A488-041B3EAA833E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {76212287-AAC0-4420-A612-24FD8A9DA5F9} - System32\Tasks\{A2D10B81-B079-4BC6-987C-A19BF3AF4496} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7916DCDF-AC27-4A62-892F-9DE2BAADE7BB} - System32\Tasks\{0DBAD5B0-D837-4E82-8270-D732E84B8997} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {79F6D2E3-BB87-4B16-A090-9A6AA4E273DA} - System32\Tasks\{0C33B5D8-227A-489D-9DC7-201BDC56A2CB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7A79C6A3-E123-4706-990B-7FA2A25E8334} - System32\Tasks\{C77745DF-3ABE-49EA-84BB-ACDF2CB0C172} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe
Task: {7EDE632F-8D75-4EDA-8D30-5F6D6E0DE3F0} - System32\Tasks\{0F216DE1-10A4-4121-9354-94F1FCAE0BA7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7FA4FAB4-B29B-46CB-A242-E31BD6102BC8} - System32\Tasks\{6F643769-F667-45A7-89A3-EFB78BAD30D2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {805A90DD-4661-4FA4-ACC5-9746B1FD37E9} - System32\Tasks\{899D1CD0-E191-4706-820D-6FCC78860A5D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {812EA991-4051-4066-8F6D-7657E59F6F13} - System32\Tasks\{13CC1F28-B809-4E6A-92F6-050867303E38} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {8432A04B-4B1C-4DF7-88E8-D224B18E0864} - System32\Tasks\{7D8FC48F-F5D5-41C9-A0C7-46FFDB261DF9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {843DBDDA-40BA-402E-BA69-2271D24F05F8} - System32\Tasks\{C6726A3E-D031-4D25-A625-2FB541085294} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {846792F6-E344-4F5C-8269-35876689B894} - System32\Tasks\{722EE7AC-CBDE-41B1-A4FB-3996382D0916} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85198C15-CF04-4EB5-8361-B1B6A57279E2} - System32\Tasks\{C6F24B23-E357-414F-8A77-F68FAC2F537E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85B0D0F1-A5E5-4225-91A2-6AE76820489D} - System32\Tasks\{B1D3638D-7AC5-4FDE-B0B3-8646717611E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85B242CA-8635-4CE5-8A89-BC0B930AFB26} - System32\Tasks\{3438563C-BDA2-4240-86FE-C250087D876B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {860D5616-C807-42E4-9471-34492936869C} - System32\Tasks\{0C52ACFB-76D7-4572-AC1F-5C817BC6F9B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {89C98CDB-86B4-4B1E-83FE-3BFDA3BBA61B} - System32\Tasks\{85CA7BEC-BAC3-4039-951D-6DD6897DA82A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8BDBE9D0-F1E1-4282-8D2C-595C2EB28B92} - System32\Tasks\{82A89D01-11E0-4CC3-80AE-23A6B6E0FC61} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8CB35F7E-5585-4B14-8711-11D6FAC29378} - System32\Tasks\{D2A2BD67-9A7E-4D6F-BE2C-6A8B2D0F1BA1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8D8F82B8-57B8-4BFE-A952-D123EFC13ECC} - System32\Tasks\{203C25BA-F232-4421-B3DA-A376B3774516} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8D97D69A-AD7F-493C-8DCC-7CB007C6A8F2} - System32\Tasks\{9C7168A6-031A-469A-AA01-62138FAD5C64} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8DF97B81-3559-47F4-9420-360B447E1FD0} - System32\Tasks\{FECF6647-C213-4C31-93D8-DA36CEF2D2E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8E04509E-7AFC-454D-841A-708BB706F7DC} - System32\Tasks\{3E9663A7-8201-4FF2-B1EB-833DE8AD30E6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8FA91399-CE12-4FBD-A967-DFD7D9109D84} - System32\Tasks\{9D64689E-0BD4-4A36-BD88-4A0E50CDC83F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {903E2695-1203-484C-B1FB-D551272A2574} - System32\Tasks\{8DB1831F-D69A-4DDE-831A-FAA560851E70} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {904FCA34-E617-4024-8059-1269ADC0C47F} - System32\Tasks\{4C21C9AE-2772-474A-A218-F693E2CF602B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {931B5588-6B96-408B-B873-41412BFE2B8E} - System32\Tasks\{C7652E09-4AA0-4B7F-94CB-751180B2AC84} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {9879350E-87CA-40F0-964A-DFC97AB3BC30} - System32\Tasks\{41A7B7D7-A9E8-4FDD-AB09-12810CB9DE9C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {98AF9170-2913-4F80-95D2-95B7477DE797} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-17] (Adobe Systems Incorporated)
Task: {9974FA93-556E-4FDD-ABA7-D41F1D4176D6} - System32\Tasks\{0BE877C9-7403-4859-BB65-3F99D03088A8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9ADA0808-016F-4483-B32E-F4712A3C1511} - System32\Tasks\{31210AE0-BEE0-48B0-AD32-F3DFF7AF8585} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {9B469F57-8F99-42A1-8801-E8E97EC4CDD1} - System32\Tasks\{F66DE0CE-872C-44E9-AD32-7E45842B895C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9BA28B79-CD14-416E-9A76-1B33558AAB10} - System32\Tasks\{AB2ECB65-FA3E-40E1-A023-0E8D5E03A224} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DBF7F80-5E83-4F91-91D2-32FA850EF84F} - System32\Tasks\{3CCABE20-2386-4504-81C4-4235BAAC31B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DFAF053-ECF1-4951-B8B9-D566381CF17E} - System32\Tasks\{12CBB338-12C1-4249-84A2-07241A16A2D6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9E7E9471-FE25-4DB0-99FC-8E598F78A02E} - System32\Tasks\{DE3AD989-7BFD-4AD9-8EDC-6F505EB64364} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A1B61844-B80C-4D9A-94F1-4645C98FC2B8} - System32\Tasks\{75FCFCA1-F6E7-4195-8FDB-205A363174BD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A212F777-60F2-4D21-AE31-7D8EDE725661} - System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/abandoninstall?page=tsMain
Task: {A2ED97D9-08BE-45A0-8F5E-DF79EE68E5EA} - System32\Tasks\{E792460F-EDFC-488E-8731-0BBFB1110EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A6B88D73-C7CC-4AC8-9868-003E3D1A6117} - System32\Tasks\{123ECB18-D866-4EAF-A87C-2B532824BBFF} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A88B4C8C-9BCA-4F56-B093-7BB101C93929} - System32\Tasks\{88F50087-6CF7-4A6A-B06F-AD288A88A6DA} => E:\AutoRun.exe
Task: {A97D22B7-423F-439C-9A10-3C6091CA5D1A} - System32\Tasks\{1BFCBFF7-66FB-4E87-81A8-FB7CF75207DE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {AA445193-1181-4478-AEF2-B0ED5C6C2E97} - System32\Tasks\{2FFB54D9-0F45-4439-A0AB-B2246A92D499} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ACFC14E5-8848-4358-90F5-8817059D3A5E} - System32\Tasks\{537B3161-6C44-4CA2-94A2-5BDB3B8C8D3E} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe
Task: {ADC16C61-80CB-4175-BEB7-3723F4552311} - System32\Tasks\{65BF13AD-A284-4838-9987-577314060DB0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ADCB1719-67BA-4895-9D04-8A1A0C26DEB7} - System32\Tasks\{697D2AB0-4D70-40B2-BA95-E58EF151514D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {AE410752-87F2-492D-9D1A-6D81D53BAF55} - System32\Tasks\{20EE37CD-2303-4DD3-97A5-61226D364CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B01A395C-1E4E-4257-A8F2-51DC50233552} - System32\Tasks\{A772563F-BDDC-463B-99F1-C77841420332} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B1CD2103-56BA-4745-9177-223FFDD53ADC} - System32\Tasks\{470BF604-D7FC-467D-A26E-CF0F03148BEC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B26A8951-5FE0-4FB7-873E-A0D132A2025F} - System32\Tasks\{98160B25-2EF3-494D-855C-85407974E878} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {B39BD072-35FE-4CC5-A530-A8909B6872D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.)
Task: {B408996C-AB90-4D16-848B-E5C3A70821D8} - System32\Tasks\{667B8D52-5E64-4C4A-9884-01C81DCCA5A8} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {B40A4AAC-C52E-47C0-8860-D0D8CFBF36B3} - System32\Tasks\{8528129B-330F-4FB9-BD05-0B63A185738C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B46D754A-55E2-4756-BC53-3885E70D6472} - System32\Tasks\{A379F55A-1CF2-4571-AACC-0F2431A98E00} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B5F85DB4-3143-4086-91FA-2D4D1E3681FC} - System32\Tasks\{73E77971-0011-4D43-AD03-9117C0D1EFDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B6A0B547-231E-4DD7-90D8-4EED1969E049} - System32\Tasks\{51ABC066-D83B-4170-8165-07805CC167F0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B6BFFAAD-9659-42EF-AA02-57D301DBA5A3} - System32\Tasks\{6C2FFB99-7192-428B-B38C-1D8F0B6F7FC6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {BA9030C6-4777-4D8C-AB61-76025BFA120F} - System32\Tasks\{313997D6-C748-4720-826F-E7E9A6BC21CC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {BCFF6A0A-67BC-421B-A03C-20012560E161} - System32\Tasks\{7AB46240-BDE2-4A4F-919C-21CFD95DEB91} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {BD78545A-B9EB-4AF6-AE31-BDA236D2BAE8} - System32\Tasks\{B315BDCA-1064-453A-A6CC-C79F19F7D016} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C0FF2097-FA54-4970-ABCC-D3C6970BDB8F} - System32\Tasks\{909D4AED-895C-4B2A-96DD-6CA6D80B3960} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {C1130E74-46A9-4A07-855A-CDF608DEBBF8} - System32\Tasks\{83AAA377-4550-4890-81AB-EABAA6D54F2F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C1992231-5AD6-4DEB-9429-A822E9B6459F} - System32\Tasks\{73E2DA90-10C9-4FEB-8303-D06CFBA64319} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C2180CA4-8AED-48C7-A2E9-F6AE7C2EA254} - System32\Tasks\{68575AA0-FDE2-4EFD-9481-ECADE3C34DA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C4CD2A1C-B81A-4DF8-A06D-66F8EE0C9E08} - System32\Tasks\{4954985C-7557-42F2-9DA3-44DAB4B574EA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C6B28C1E-EB4C-49E1-9C0B-AB8E2704CBA2} - System32\Tasks\{F92A9599-40B3-4A4D-AC6B-DB14C925E677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C70B179E-12FD-4FA2-9ADF-F9B845F76EBE} - System32\Tasks\{7B61AC9C-9B02-4800-95D6-DC4C2193ECA4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C956224D-737E-44AC-A135-B8A291573F99} - System32\Tasks\{C5CECD65-EFFE-4679-8ED8-9083413AF641} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C9C1E1CF-9F4F-4893-8DF5-FFD570756159} - System32\Tasks\{1F69CD65-61D9-472C-95EE-8793CAB2098E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CD835294-0684-4E85-93D7-57FA3413500A} - System32\Tasks\{7AD6CBE5-95F9-4616-B6CE-1FBF3ACBB0D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CD878935-40AC-4D8D-8C98-045CA41BB390} - System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618
Task: {CDAC83D4-811F-4165-8722-856EAE3449B3} - System32\Tasks\{E0B10180-47E9-4AB1-9FE0-6C44B2EF97A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CE724C0F-EA35-4437-9D30-1113211B6A09} - System32\Tasks\{4C940F41-C0B3-4969-884C-E442672E162D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CF2606A0-ACA7-45F9-AD40-268630067DC0} - System32\Tasks\{96124692-6A3C-4996-8C1C-D5A23375B7EE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D21F7BE1-05EB-44B3-BAA5-9BCD4AE31875} - System32\Tasks\{901FF9AA-59B7-48DE-82FE-581B7F599280} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D264BCEC-BABB-4C67-AB5E-F518C830438A} - System32\Tasks\{F600C80E-888F-4E6B-9B51-FEB3021CC358} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D360F099-830B-49E3-8626-6FA307F5DDE8} - System32\Tasks\{BC56BB0E-CC7A-4E3C-BAA7-76686DE08AC6} => C:\Program Files (x86)\il-2 sturmovik cliffs of dover\Launcher.exe [2011-04-03] (1C:SoftClub)
Task: {D4A58010-4058-414F-B75C-F534647CCADE} - System32\Tasks\{60083AE6-8669-4F76-A8C9-EC5394929A9B} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {D652DAE9-1CF0-45B1-BB5B-73CBD75E3D7A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {D71B37E9-5FF9-4CDC-8C10-90DBE9D9D2C7} - System32\Tasks\{A08D600B-BB0B-4BB7-B7E5-EFA9DBA72624} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D84CF91D-4A8A-4C38-8808-78F24EEA7D00} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {D92C729A-F461-430D-9536-06B0A6EEF5D5} - System32\Tasks\Opera scheduled Autoupdate 1401931354 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software)
Task: {D934BBFE-2B1B-462F-B25C-A7FC1696106C} - System32\Tasks\{B83314D1-CE37-47EB-93D3-5F69CE06C9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DA5E0905-D48D-4F65-A292-DCE54E3DF4DE} - System32\Tasks\{48B23608-CF81-40DF-866F-E9149F931791} => C:\Program Files (x86)\English Bid for Power Final 4.0\EBFPF 4.0.exe
Task: {DCB6E2F6-56D1-4247-8394-3366B53DBE91} - System32\Tasks\{D0C97849-AFD1-450D-A83D-E2ABAF26C11D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DD54C13C-6AA2-45C9-98FB-4F3C4F706776} - System32\Tasks\{D636E579-ECC1-48E6-8D34-0898C8B8AB88} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DF3520E2-5C0C-45C7-9E29-C0A3CF6624CD} - System32\Tasks\{F9064DAF-E8C8-42B4-872B-CF84AEB8A5A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DFDC1780-CB4B-49C6-9D0C-6A307018E041} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {E06029EB-0DB6-46F4-8D96-010660E515F6} - System32\Tasks\{6D9D7339-3B94-4B93-A4D6-B3152EBECD01} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E069F814-CBF7-4E4F-9793-7A842132DBBA} - System32\Tasks\{373EABBD-53C5-4E40-898F-4C5069D8A499} => C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe [2009-06-28] (Sony DADC Austria AG)
Task: {E13EACA4-DC9F-4ADC-9A68-67B64DFE23B6} - System32\Tasks\{DEF987AD-81AC-42EB-B412-5A8403716DDA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E1C1E3A3-A460-421D-A2A3-CD52241FD7D5} - System32\Tasks\{C0F296D8-C7D3-40E7-BE16-E643CDDEC0BC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E2191329-4BE6-4CFE-A6D1-734AF9A17EFA} - System32\Tasks\{3BA18019-EAF4-452D-A4A2-3E20F326FC0D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E3C57322-4D59-48CE-9D42-CC0D884733F7} - System32\Tasks\{BA768B60-C681-4E86-B54D-B818BB13C841} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E44DAC2B-B71A-4537-A501-996802E1A023} - System32\Tasks\{03B26415-BC1D-4284-9D4A-A178EB9B3EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E4508BB6-1429-49BD-BCBA-083AAA7E5AA8} - System32\Tasks\{BC238E47-DE85-42C8-A42A-5CAEAE4649FB} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {E4FA1C11-710B-467C-8C5B-869390DF8A61} - System32\Tasks\{699BB15C-2884-457A-BA98-A4B8698C652A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E6A13448-9338-473B-BAA0-23B9F616B6D0} - System32\Tasks\{775735C3-BC90-4F41-82D2-6C5EE14FD15A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E712900C-C47E-492D-BF1A-DE095C31D309} - System32\Tasks\{3A9C2093-CDC6-4117-A344-E59636C8D654} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E92D78D6-0882-4D25-8296-F91672232EC3} - System32\Tasks\{0B804F92-4E06-4F0B-8398-FBFF1770A638} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EAD179B7-8EFB-4C37-A13B-DAA71D740E0D} - System32\Tasks\{CEDABE9A-9564-465A-B4B1-1257AC1B2C43} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-5 => C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-5.exe [2014-06-04] (PlusVHD)
Task: {ED37749E-137A-4F1C-9FD0-3DCF709567E5} - System32\Tasks\{A4B072C7-A2B2-4870-8C3F-6B6324B02FBB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EF1BD8C8-A15F-4BC6-AD60-672E42A93C49} - System32\Tasks\{A6450515-09C9-444A-B374-6304A0A11E67} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EFC87779-05F4-4C10-8880-71EAEBE1391F} - System32\Tasks\{8A126FB2-9DF1-40B6-BF29-94BC77C74FAB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F0108CE8-B277-4C4D-BEB9-83F45F46F170} - System32\Tasks\{6E35942B-EC74-4C6C-8ECD-5787FEE77389} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {F11AE687-5F0D-4509-9E7D-904D61C5BA98} - System32\Tasks\{177FAF9C-8814-4261-A21C-CA7506F2B82F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F28B5784-80AB-4325-8C31-358E7215BB3C} - System32\Tasks\{6F04151D-6AB6-4AD1-AD9E-5AE5BB416094} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F62B21A2-FAEC-44BA-93B9-C1AE49234444} - System32\Tasks\{11514906-B372-4DBD-B566-488DF1E6F029} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {F800F910-22FD-49C7-938B-A6C0AD765100} - System32\Tasks\{88CE8631-1046-44CF-88EE-4849D81EE9E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F875476F-7142-4F9D-812C-13343492E7A1} - System32\Tasks\{D9DFF9E6-6D3B-4AE0-9D39-D0AC25C7B9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F89D7FAD-847B-495E-B7A9-1102853A0B96} - System32\Tasks\{B518FFEB-D63F-452B-82E4-F45EF890BC97} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {F8E344A2-D4C9-4CE7-98BB-521D2CA6A434} - System32\Tasks\{D691C721-D450-4C82-B4C4-495A1B64DBD3} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {F91D746E-4CF8-41DE-83CB-31432B4543D9} - System32\Tasks\{DCEAF480-641F-4ACD-A325-BDBA0CCC540B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FA2B38D9-60DC-455F-BB4A-D4810EB33769} - System32\Tasks\{0A9C2DB2-D33D-4DE9-A45C-528B8C1AEE1B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FA31A522-796E-426B-848D-E9077313AD8A} - System32\Tasks\{A0DA316A-D472-444F-A426-D6D46912C19F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FBFCFB6D-C9AD-4075-A58D-ADD617EF8D2B} - System32\Tasks\{45962B83-FB74-456E-BE05-674FB7E57069} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FCE91E30-A0CA-4991-A909-F7CF995FB676} - System32\Tasks\{B8DE84ED-80C7-4218-A29E-5B4B9E36DDAA} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe
Task: {FE3ECFB4-5ADB-4B7C-92C9-E7F27D53C159} - System32\Tasks\{08AF28EA-188F-4A3C-AA80-C8A5DC185025} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-3.job => C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-3.exe
Task: C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-5.job => C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-5.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-10-26 03:31 - 2013-08-18 21:34 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-04 11:20 - 2014-06-04 11:20 - 01005056 _____ () C:\Users\Sven\AppData\Roaming\BupSystem\bup.exe
2013-10-12 04:11 - 2013-10-12 04:11 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2010-05-02 01:34 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2010-05-02 11:53 - 2010-05-02 11:53 - 02937528 _____ () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
2010-05-02 01:13 - 2009-05-07 16:51 - 00071680 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2010-05-02 01:13 - 2009-05-07 16:53 - 00379392 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2010-05-02 01:13 - 2008-01-18 14:50 - 00098816 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll
2010-05-02 01:13 - 2009-07-10 10:48 - 47601664 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll
2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2014-06-05 03:22 - 2014-05-27 12:00 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\VERSION.dll
2014-06-08 23:49 - 2014-06-08 23:49 - 02775040 _____ () C:\Program Files\AVAST Software\Avast\defs\14060801\algo.dll
2014-06-09 09:53 - 2014-06-09 09:53 - 02775040 _____ () C:\Program Files\AVAST Software\Avast\defs\14060900\algo.dll
2011-09-27 08:23 - 2011-09-27 08:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 08:22 - 2011-09-27 08:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-06-04 11:20 - 2014-06-04 11:20 - 00374272 _____ () C:\Users\Sven\AppData\Roaming\BupSystem\sub\default.dll
2014-06-08 23:49 - 2014-06-08 23:49 - 00043008 _____ () c:\users\sven\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpp0tf5o.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Sven\AppData\Roaming\Dropbox\bin\libcef.dll
2014-06-05 06:14 - 2014-06-05 06:14 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\version.DLL
2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00877176 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libglesv2.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libegl.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk => C:\Windows\pss\GamersFirst LIVE!.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Rainmeter.lnk => C:\Windows\pss\Rainmeter.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^regsvr43.lnk => C:\Windows\pss\regsvr43.lnk.Startup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: Facebook Update => "C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: FreeCall => "C:\Program Files (x86)\FreeCall.com\FreeCall\freecall.exe" -nosplash -minimized
MSCONFIG\startupreg: ICQ => "C:\Program Files (x86)\ICQ7.1\ICQ.exe" silent loginmode=4
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: Malwarebytes' Anti-Malware => "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
MSCONFIG\startupreg: MessengerPlusLiveUninstall => "C:\Users\Sven\AppData\Local\Temp\MsgPlusUninstall.exe" /Cleanup
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent

==================== Faulty Device Manager Devices =============

Name: SbieDrv
Description: SbieDrv
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SbieDrv
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/09/2014 03:46:00 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1098949856-1301053314-1890294551-1004.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.


Vorgang:
  OnIdentify-Ereignis
  Generatordaten werden gesammelt

Kontext:
  Ausführungskontext: Shadow Copy Optimization Writer
  Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
  Generatorname: Shadow Copy Optimization Writer
  Generatorinstanz-ID: {2d9d034c-cadd-4001-a768-531fad066df4}

Error: (06/09/2014 04:49:29 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "ConvertStringSidToSid(S-1-5-21-1098949856-1301053314-1890294551-1004.bak)" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.
.


Vorgang:
  OnIdentify-Ereignis
  Generatordaten werden gesammelt

Kontext:
  Ausführungskontext: Shadow Copy Optimization Writer
  Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
  Generatorname: Shadow Copy Optimization Writer
  Generatorinstanz-ID: {a6fc6a43-d813-4ccb-b07e-cc4115bacba4}

Error: (06/08/2014 07:41:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8362

Error: (06/08/2014 07:41:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8362

Error: (06/08/2014 07:41:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/08/2014 07:41:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7363

Error: (06/08/2014 07:41:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7363

Error: (06/08/2014 07:41:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/08/2014 07:41:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6349

Error: (06/08/2014 07:41:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6349


System errors:
=============
Error: (06/08/2014 11:48:28 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/07/2014 08:24:52 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/07/2014 08:24:09 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎07.‎06.‎2014 um 13:26:51 unerwartet heruntergefahren.

Error: (06/06/2014 00:27:21 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (06/06/2014 00:27:20 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (06/06/2014 02:32:00 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (06/06/2014 01:05:11 AM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (06/05/2014 08:06:04 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/05/2014 08:05:34 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎05.‎06.‎2014 um 19:38:13 unerwartet heruntergefahren.

Error: (06/05/2014 07:24:10 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)


Microsoft Office Sessions:
=========================
Error: (06/09/2014 03:46:00 PM) (Source: VSS) (EventID: 8193) (User: )
Description: ConvertStringSidToSid(S-1-5-21-1098949856-1301053314-1890294551-1004.bak)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.


Vorgang:
  OnIdentify-Ereignis
  Generatordaten werden gesammelt

Kontext:
  Ausführungskontext: Shadow Copy Optimization Writer
  Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
  Generatorname: Shadow Copy Optimization Writer
  Generatorinstanz-ID: {2d9d034c-cadd-4001-a768-531fad066df4}

Error: (06/09/2014 04:49:29 AM) (Source: VSS) (EventID: 8193) (User: )
Description: ConvertStringSidToSid(S-1-5-21-1098949856-1301053314-1890294551-1004.bak)0x80070539, Die Struktur der Sicherheitskennung ist unzulässig.


Vorgang:
  OnIdentify-Ereignis
  Generatordaten werden gesammelt

Kontext:
  Ausführungskontext: Shadow Copy Optimization Writer
  Generatorklassen-ID: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
  Generatorname: Shadow Copy Optimization Writer
  Generatorinstanz-ID: {a6fc6a43-d813-4ccb-b07e-cc4115bacba4}

Error: (06/08/2014 07:41:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8362

Error: (06/08/2014 07:41:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8362

Error: (06/08/2014 07:41:57 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/08/2014 07:41:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7363

Error: (06/08/2014 07:41:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7363

Error: (06/08/2014 07:41:56 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/08/2014 07:41:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6349

Error: (06/08/2014 07:41:55 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6349


CodeIntegrity Errors:
===================================
  Date: 2014-06-09 15:55:34.283
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:55:33.521
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:55:32.615
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:55:31.871
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:27:29.113
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:27:28.311
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:27:27.508
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:27:26.755
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:05:26.042
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-09 15:05:25.188
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info ===========================

Percentage of memory in use: 55%
Total physical RAM: 4095.18 MB
Available physical RAM: 1824.66 MB
Total Pagefile: 8188.54 MB
Available Pagefile: 5401.21 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:234.77 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3AC77A71)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

==================== End Of Log ============================

--- --- ---

M-K-D-B 10.06.2014 08:15

Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).





Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.







Schritt 3
Bitte deaktiviere dein Anti-Viren-Programm, da es das Ergebnis beeinflussen oder ggf. die Bereinigung stören kann.
Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/ und speichere die Datei auf deinem Desktop.
  • Starte Zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und könnte andere Computer beschädigen.
  • Kopiere den Text der folgenden Box in das Skriptfenster von zoek:
    Code:

    iedefaults;
    resetIEproxy;
    FFdefaults;
    CHRdefaults;
    emptyclsid;
    autoclean;

  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchgelaufen ist.
  • Wenn das Tool fertig ist, wird sich Notepad mit der Logdatei öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:\ .
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken).





Schritt 4
  • Starte die FRST.exe erneut. Setze einen Haken vor Addition.txt und drücke auf Scan.
  • FRST erstellt wieder zwei Logdateien (FRST.txt und Addition.txt).
  • Poste mir beide Logdateien mit deiner nächsten Antwort.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von AdwCleaner,
  • die Logdatei von MBAM,
  • die Logdatei von Zoek,
  • die beiden neuen Logdateien von FRST.

Goodfell 10.06.2014 10:59

AdwCleaner Logfile:
Code:

# AdwCleaner v3.212 - Bericht erstellt am 10/06/2014 um 11:10:49
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Sven - SVEN-PC
# Gestartet von : C:\Users\Sven\Downloads\adwcleaner_3.212.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : bupService
[#] Dienst Gelöscht : globalUpdate
[#] Dienst Gelöscht : globalUpdatem

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\DSearchLink
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\ProgramData\StarApp
Ordner Gelöscht : C:\Program Files (x86)\Delta
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\OutBrowseToolbar
Ordner Gelöscht : C:\Program Files (x86)\raving reyven
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\OutBrowseToolbar
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\SimplyTech
Ordner Gelöscht : C:\Users\Sven\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Sven\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Sven\AppData\Local\Temp\raving reyven
Ordner Gelöscht : C:\Users\Sven\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\Sven\AppData\LocalLow\OutBrowseToolbar
Ordner Gelöscht : C:\Users\Sven\AppData\LocalLow\SimplyTech
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\BupSystem
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Delta
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\OutBrowseToolbar
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Windows Net Data
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Conduit
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\ConduitCommon
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\ConduitEngine
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\ICQToolbarData
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\firejump@firejump.net
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\mail@shopping-preise.de
Ordner Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\a54e453c-130a-4769-9333-c5ec2aa914c5@9bd7cc89-9c7c-44e9-a03b-042b92d363f0.com
Ordner Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\npldjlebaajpmaipffkcmdllphdglkko
Datei Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\.autoreg
Datei Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\searchplugins\Web Search.xml
Datei Gelöscht : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\user.js
Datei Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data
Datei Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Datei Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage
Datei Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage
Datei Gelöscht : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.livelyrics00.live-lyrics.com_0.localstorage-journal
Datei Gelöscht : C:\Windows\System32\Tasks\BitGuard
Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
Datei Gelöscht : C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-3.job
Datei Gelöscht : C:\Windows\System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-3
Datei Gelöscht : C:\Windows\Tasks\41220790-4b35-4753-91f3-94289344bd48-5.job
Datei Gelöscht : C:\Windows\System32\Tasks\41220790-4b35-4753-91f3-94289344bd48-5

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [mail@shopping-preise.de]
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\npldjlebaajpmaipffkcmdllphdglkko
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\PricePeep.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\d
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PricePeep.PricePeepBho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.Band
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.Band.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.NotificationSource
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.NotificationSource.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.SourceSinkImpl.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wtb.ToolbarInfo.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKCU\Software\5255d68fb76ae914
Schlüssel Gelöscht : HKLM\SOFTWARE\5255d68fb76ae914
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052916.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052916.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052916.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052916.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader29029_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader29029_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader66221_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader66221_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader70391_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader70391_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader88030_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader88030_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_axife-mouse-recorder_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_axife-mouse-recorder_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_recuva_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_recuva_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_visualboyadvance_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_visualboyadvance_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{38A066B0-DD5F-4226-AC4F-6A27C1BFB892}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3FC27B34-0C19-49DA-875E-1875DDD4A6B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FBA50D9B-299F-43C6-9C50-55BDEC9991C5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511291116}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522292216}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555295516}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566296616}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3BF3DED5-0FC8-4207-AC09-AA7B5AF4E408}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B556C954-17BC-4E50-83E9-4593D071B416}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544294416}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBA50D9B-299F-43C6-9C50-55BDEC9991C5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511291116}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511291116}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522292216}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1B97A696-5576-43AC-A73B-E1D2C78F21E8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{75BF416E-4326-45B5-8A2D-AE32D05B930B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555295516}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566296616}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511291116}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\DataMngr
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8462c15f-5f80-45c3-85b2-7326ab68a508}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PricePeep
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VIS
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17041

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [(Default)]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

-\\ Mozilla Firefox v29.0.1 (de)

[ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js ]

Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHL[...]
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJ[...]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjShy5avISrmuj[...]

[ Datei : C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js ]

Zeile gelöscht : user_pref("CT2269050..clientLogIsEnabled", true);
Zeile gelöscht : user_pref("CT2269050..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2269050..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CT2269050.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gelöscht : user_pref("CT2269050.CTID", "CT2269050");
Zeile gelöscht : user_pref("CT2269050.CurrentServerDate", "19-9-2011");
Zeile gelöscht : user_pref("CT2269050.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2269050.DialogsGetterLastCheckTime", "Mon Sep 19 2011 00:24:04 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.DownloadReferralCookieData", "");
Zeile gelöscht : user_pref("CT2269050.EMailNotifierPollDate", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.FirstServerDate", "8-8-2010");
Zeile gelöscht : user_pref("CT2269050.FirstTime", true);
Zeile gelöscht : user_pref("CT2269050.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2269050.FirstTimeSettingsDone", true);
Zeile gelöscht : user_pref("CT2269050.FixPageNotFoundErrors", true);
Zeile gelöscht : user_pref("CT2269050.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2269050.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2269050.HasUserGlobalKeys", true);
Zeile gelöscht : user_pref("CT2269050.HomePageProtectorEnabled", false);
Zeile gelöscht : user_pref("CT2269050.Initialize", true);
Zeile gelöscht : user_pref("CT2269050.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("CT2269050.InstallationAndCookieDataSentCount", 3);
Zeile gelöscht : user_pref("CT2269050.InstallationType", "UnknownIntegration");
Zeile gelöscht : user_pref("CT2269050.InstalledDate", "Sun Aug 08 2010 05:06:08 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.InvalidateCache", false);
Zeile gelöscht : user_pref("CT2269050.IsGrouping", false);
Zeile gelöscht : user_pref("CT2269050.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2269050.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("CT2269050.IsOpenUninstallPage", false);
Zeile gelöscht : user_pref("CT2269050.LanguagePackLastCheckTime", "Mon Sep 19 2011 00:24:04 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2269050.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2269050.LastLogin_2.7.0.14", "Sun Aug 08 2010 11:10:48 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.LastLogin_3.3.3.2", "Wed Apr 06 2011 19:02:05 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.LastLogin_3.6.0.10", "Mon Sep 19 2011 00:24:04 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.LatestVersion", "3.6.0.10");
Zeile gelöscht : user_pref("CT2269050.Locale", "en");
Zeile gelöscht : user_pref("CT2269050.LoginCache", 4);
Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2269050.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2269050.MyStuffEnabledAtInstallation", true);
Zeile gelöscht : user_pref("CT2269050.RadioIsPodcast", false);
Zeile gelöscht : user_pref("CT2269050.RadioLastCheckTime", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.RadioLastUpdateIPServer", "3");
Zeile gelöscht : user_pref("CT2269050.RadioLastUpdateServer", "129132338014870000");
Zeile gelöscht : user_pref("CT2269050.RadioMediaID", "12473383");
Zeile gelöscht : user_pref("CT2269050.RadioMediaType", "Media Player");
Zeile gelöscht : user_pref("CT2269050.RadioMenuSelectedID", "EBRadioMenu_CT226905012473383");
Zeile gelöscht : user_pref("CT2269050.RadioShrinkedFromSetup", false);
Zeile gelöscht : user_pref("CT2269050.RadioStationName", "Hotmix%20108");
Zeile gelöscht : user_pref("CT2269050.RadioStationURL", "hxxp://67.202.67.18:8082");
Zeile gelöscht : user_pref("CT2269050.SHRINK_TOOLBAR", 1);
Zeile gelöscht : user_pref("CT2269050.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2269050&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gelöscht : user_pref("CT2269050.SearchEngineBeforeUnload", "Google");
Zeile gelöscht : user_pref("CT2269050.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2269050.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&q=");
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabLastCheckTime", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2269050.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2269050.SearchProtectorEnabled", false);
Zeile gelöscht : user_pref("CT2269050.SearchProtectorToolbarDisabled", false);
Zeile gelöscht : user_pref("CT2269050.ServiceMapLastCheckTime", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2269050.SettingsLastCheckTime", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.SettingsLastUpdate", "1314606801");
Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastCheck", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.ThirdPartyComponentsLastUpdate", "1312887586");
Zeile gelöscht : user_pref("CT2269050.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2269050");
Zeile gelöscht : user_pref("CT2269050.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
Zeile gelöscht : user_pref("CT2269050.Uninstall", true);
Zeile gelöscht : user_pref("CT2269050.UserID", "UN68334705569743980");
Zeile gelöscht : user_pref("CT2269050.ValidationData_Toolbar", 2);
Zeile gelöscht : user_pref("CT2269050.WeatherNetwork", "");
Zeile gelöscht : user_pref("CT2269050.WeatherPollDate", "Mon Sep 19 2011 00:24:04 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.WeatherUnit", "C");
Zeile gelöscht : user_pref("CT2269050.alertChannelId", "666138");
Zeile gelöscht : user_pref("CT2269050.clientLogIsEnabled", false);
Zeile gelöscht : user_pref("CT2269050.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2269050.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
Zeile gelöscht : user_pref("CT2269050.globalFirstTimeInfoLastCheckTime", "Mon Sep 19 2011 00:24:04 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.homepageProtectorEnableByLogin", true);
Zeile gelöscht : user_pref("CT2269050.initDone", true);
Zeile gelöscht : user_pref("CT2269050.isAppTrackingManagerOn", true);
Zeile gelöscht : user_pref("CT2269050.isFirstRadioInstallation", false);
Zeile gelöscht : user_pref("CT2269050.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2269050.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2269050.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2269050.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2269050.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2269050.oldAppsList", "128834881989343894,128834881989343895,111,129391330693125668,129466585399606892,129466585396013141,129121052374999726,129023235807856892,1000082,129351672002618989,[...]
Zeile gelöscht : user_pref("CT2269050.searchProtectorDialogDelayInSec", 10);
Zeile gelöscht : user_pref("CT2269050.searchProtectorEnableByLogin", true);
Zeile gelöscht : user_pref("CT2269050.testingCtid", "");
Zeile gelöscht : user_pref("CT2269050.toolbarAppMetaDataLastCheckTime", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.toolbarContextMenuLastCheckTime", "Mon Sep 19 2011 00:24:03 GMT+0200");
Zeile gelöscht : user_pref("CT2269050.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CT2431245.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gelöscht : user_pref("CT2431245.CTID", "CT2431245");
Zeile gelöscht : user_pref("CT2431245.CurrentServerDate", "2-5-2010");
Zeile gelöscht : user_pref("CT2431245.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2431245.EMailNotifierPollDate", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedLastCount129009402595187825", 522);
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634014180506963", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634014269327586", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634014329599698", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634014537505092", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634014970726540", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634015410831318", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634015483395460", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634015636754705", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634015768347545", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634015855543602", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016030710453", "Sun May 02 2010 01:52:17 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016114705611", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016129205152", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016143724791", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016271239162", "Sun May 02 2010 01:52:20 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016568520719", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634016726993788", "Sun May 02 2010 01:52:17 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017109031809", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017132743740", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017299547668", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017302327846", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017344111490", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017478360748", "Sun May 02 2010 01:52:20 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017732797593", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634017821686064", "Sun May 02 2010 01:52:20 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedPollDate7470634018090228721", "Sun May 02 2010 01:52:19 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.FeedTTL7470634014269327586", 5);
Zeile gelöscht : user_pref("CT2431245.FeedTTL7470634014537505092", 5);
Zeile gelöscht : user_pref("CT2431245.FeedTTL7470634015636754705", 5);
Zeile gelöscht : user_pref("CT2431245.FeedTTL7470634016568520719", 30);
Zeile gelöscht : user_pref("CT2431245.FirstServerDate", "2-5-2010");
Zeile gelöscht : user_pref("CT2431245.FirstTime", true);
Zeile gelöscht : user_pref("CT2431245.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2431245.FixPageNotFoundErrors", true);
Zeile gelöscht : user_pref("CT2431245.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2431245.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2431245.Initialize", true);
Zeile gelöscht : user_pref("CT2431245.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("CT2431245.InstalledDate", "Sun May 02 2010 01:52:17 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.InvalidateCache", false);
Zeile gelöscht : user_pref("CT2431245.IsGrouping", false);
Zeile gelöscht : user_pref("CT2431245.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2431245.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("CT2431245.IsOpenUninstallPage", true);
Zeile gelöscht : user_pref("CT2431245.LanguagePackLastCheckTime", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2431245.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2431245.LastLogin_2.5.8.6", "Sun May 02 2010 01:52:17 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.LatestVersion", "2.1.0.18");
Zeile gelöscht : user_pref("CT2431245.Locale", "de-de");
Zeile gelöscht : user_pref("CT2431245.LoginCache", 4);
Zeile gelöscht : user_pref("CT2431245.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2431245.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2431245.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2431245.RadioIsPodcast", false);
Zeile gelöscht : user_pref("CT2431245.RadioLastCheckTime", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.RadioLastUpdateIPServer", "3");
Zeile gelöscht : user_pref("CT2431245.RadioLastUpdateServer", "129167771525870000");
Zeile gelöscht : user_pref("CT2431245.RadioMediaID", "20503672");
Zeile gelöscht : user_pref("CT2431245.RadioMediaType", "Media Player");
Zeile gelöscht : user_pref("CT2431245.RadioMenuSelectedID", "EBRadioMenu_CT243124520503672");
Zeile gelöscht : user_pref("CT2431245.RadioStationName", "Team%20Radio%20Deutschland");
Zeile gelöscht : user_pref("CT2431245.RadioStationURL", "hxxp://trd.stream.w-u-s.org:6666/dsl.m3u");
Zeile gelöscht : user_pref("CT2431245.SHRINK_TOOLBAR", 1);
Zeile gelöscht : user_pref("CT2431245.SearchEngine", "Suchen||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2431245&octid=EB_ORIGINAL_CTID&SearchSource=1");
Zeile gelöscht : user_pref("CT2431245.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2431245.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2431245&q=");
Zeile gelöscht : user_pref("CT2431245.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2431245.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2431245.SearchInNewTabLastCheckTime", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2431245.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2431245.SettingsCheckIntervalMin", 120);
Zeile gelöscht : user_pref("CT2431245.SettingsLastCheckTime", "Sun May 02 2010 01:52:16 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.SettingsLastUpdate", "1272296347");
Zeile gelöscht : user_pref("CT2431245.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2431245.ThirdPartyComponentsLastCheck", "Sun May 02 2010 01:52:16 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.ThirdPartyComponentsLastUpdate", "1272296347");
Zeile gelöscht : user_pref("CT2431245.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
Zeile gelöscht : user_pref("CT2431245.Uninstall", true);
Zeile gelöscht : user_pref("CT2431245.UserID", "UN79082852517519742");
Zeile gelöscht : user_pref("CT2431245.WeatherNetwork", "");
Zeile gelöscht : user_pref("CT2431245.WeatherPollDate", "Sun May 02 2010 01:52:18 GMT+0200");
Zeile gelöscht : user_pref("CT2431245.WeatherUnit", "C");
Zeile gelöscht : user_pref("CT2431245.alertChannelId", "825452");
Zeile gelöscht : user_pref("CT2431245.clientLogIsEnabled", true);
Zeile gelöscht : user_pref("CT2431245.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2431245.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2431245.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2431245.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&amp;SearchSourceOrigin=29&amp;ctid=EB_TOOLBAR_ID&amp;octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2431245.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2431245.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2431245.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "CT2269050");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/?aid=666138&fid=661999", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/666138/661999/DE", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/DE", "\"0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2269050", "\"1313041456\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "wVmmvqqOMqrv5xct1cJIHg==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "0uSPYx+Kl2jpu8sJZMeHjw==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "K4Vqu91uAzWURlxJRdXJOg==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"01ffa8b1cc6cb1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"0652eeacc6cb1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.0.10", "\"80ee9485875dcc1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2269050", "\"634515122457000000\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/2011 11:17:11 AM", "634356118310000000");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2269050/CT2269050", "\"1314606801\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer_dead.gif", "\"0a8c48d3330c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.gif", "\"0e2106f3030c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif", "\"0f475394430c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif", "\"08d9ef44430c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif", "\"066e8863030c81:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634515953213470000\"");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Zeile gelöscht : user_pref("CommunityToolbar.IsEngineShown", true);
Zeile gelöscht : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Zeile gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.2&q=");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2431245,CT2269050,ConduitEngine");
Zeile gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2431245,CT2269050");
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sun Apr 03 2011 04:37:26 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu Jul 14 2011 16:44:10 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
Zeile gelöscht : user_pref("CommunityToolbar.alert.locale", "en");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri Jul 15 2011 11:54:46 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Zeile gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Zeile gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userId", "{224c9f33-f0a1-402b-ad0b-988ca3eda640}");
Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Aug 08 2010 05:06:11 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.globalUserId", "d5584cff-5600-4c84-80ff-bd632bc071cf");
Zeile gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Zeile gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Zeile gelöscht : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Wed May 11 2011 09:34:17 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.CTID", "ConduitEngine");
Zeile gelöscht : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Thu Jul 14 2011 11:08:21 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.FirstServerDate", "04/03/2011 05");
Zeile gelöscht : user_pref("ConduitEngine.FirstTime", true);
Zeile gelöscht : user_pref("ConduitEngine.FirstTimeFF3", true);
Zeile gelöscht : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Zeile gelöscht : user_pref("ConduitEngine.Initialize", true);
Zeile gelöscht : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Zeile gelöscht : user_pref("ConduitEngine.InstalledDate", "Sun Apr 03 2011 04:37:27 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.IsMulticommunity", false);
Zeile gelöscht : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Zeile gelöscht : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri Jul 15 2011 11:08:33 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Fri Jul 15 2011 10:11:43 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri Jul 15 2011 10:11:43 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.UserID", "UN26505978643034287");
Zeile gelöscht : user_pref("ConduitEngine.componentAlertEnabled", false);
Zeile gelöscht : user_pref("ConduitEngine.engineLocale", "de");
Zeile gelöscht : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri Jul 15 2011 11:08:21 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Fri Jul 15 2011 10:11:43 GMT+0200");
Zeile gelöscht : user_pref("ConduitEngine.initDone", true);
Zeile gelöscht : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Zeile gelöscht : user_pref("ConduitEngine.usagesFlag", 1);
Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHL[...]
Zeile gelöscht : user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1466996dea30ea4dd107112a5d7842b3");
Zeile gelöscht : user_pref("icqtoolbar.engineVerified", false);
Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1272756434);
Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Zeile gelöscht : user_pref("icqtoolbar.installTime", "1272756434");
Zeile gelöscht : user_pref("icqtoolbar.installsource", "1");
Zeile gelöscht : user_pref("icqtoolbar.newtab_state", "1");
Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "171615349216517058761272756434463");
Zeile gelöscht : user_pref("icqtoolbar.version", "2.0.0.2");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJ[...]

-\\ Google Chrome v35.0.1916.114

[ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=9C8F00FF596899C6&affID=123620&tsp=5026

[ Datei : C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht [Extension] : aaipilfmheplbcghignccoiiebekkdhe
Gelöscht [Extension] : npldjlebaajpmaipffkcmdllphdglkko

*************************

AdwCleaner[R0].txt - [60043 octets] - [10/06/2014 11:06:04]
AdwCleaner[R1].txt - [60163 octets] - [10/06/2014 11:09:35]
AdwCleaner[S0].txt - [318 octets] - [10/06/2014 11:08:25]
AdwCleaner[S1].txt - [55666 octets] - [10/06/2014 11:10:49]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [55727 octets] ##########

--- --- ---

[/CODE]

Code:



Malwarebytes Anti-Malware
www.malwarebytes.org


Update, 10.06.2014 11:28:47, SYSTEM, SVEN-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.6.2.1,
Update, 10.06.2014 11:29:02, SYSTEM, SVEN-PC, Manual, Malware Database, 2014.3.4.9, 2014.6.10.2,
Protection, 10.06.2014 11:53:38, SYSTEM, SVEN-PC, Protection, Malware Protection, Starting,
Protection, 10.06.2014 11:53:38, SYSTEM, SVEN-PC, Protection, Malware Protection, Started,
Protection, 10.06.2014 11:53:38, SYSTEM, SVEN-PC, Protection, Malicious Website Protection, Starting,
Protection, 10.06.2014 11:53:39, SYSTEM, SVEN-PC, Protection, Malicious Website Protection, Started,
Detection, 10.06.2014 11:58:40, SYSTEM, SVEN-PC, Protection, Malware Protection, File, PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-5.exe, Quarantine, [4189185e2754e35346c07eff1de455ab]

(end)


M-K-D-B 10.06.2014 11:12

Servus,


das ist die falsche Logdatei von MBAM, suche unter Verlauf > Anwendungsprotokolle nach einem Suchlauf-Protokoll.

Goodfell 10.06.2014 11:23

Okay dachte ich mir schon ^^ danke für deine Geduld, ich schau nochmal.
Rest kommt auch noch gleich

Code:


Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 10.06.2014
Suchlauf-Zeit: 11:33:33
Logdatei: MMBAM TEXT.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.06.10.02
Rootkit Datenbank: v2014.06.02.01
Lizenz: Premium
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Sven

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 384797
Verstrichene Zeit: 13 Min, 54 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 18
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ceefadbd-a0ce-4422-a760-3b9167344e06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{c8b9442b-56bf-4644-861f-5cb2158aae27}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{c8b9442b-56bf-4644-861f-5cb2158aae27}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, Keine Aktion durch Benutzer, [d3f73e38ef8c191d661176fbec16f50b],
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, Keine Aktion durch Benutzer, [d3f73e38ef8c191d661176fbec16f50b],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\PSHD-9.9, Keine Aktion durch Benutzer, [6e5c4432e09bb284479f11923ac8ad53],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, Keine Aktion durch Benutzer, [c00af383e19acd69cf15594af210f20e],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Outbrowsetoolbar, Keine Aktion durch Benutzer, [a4265224215a3cfa38f2b13130d34fb1],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, Keine Aktion durch Benutzer, [0cbe7600a0db1b1b51933e656f93ce32],
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PricePeep, Keine Aktion durch Benutzer, [b317e5912f4ce74fb9866e5010f2f50b],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, Keine Aktion durch Benutzer, [b317393d5c1f0531e74a71613ec55ca4],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, Keine Aktion durch Benutzer, [3b8fc3b37dfe290d394aa3316f94e818],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSHD-9.9, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],

Registrierungswerte: 2
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{CEEFADBD-A0CE-4422-A760-3B9167344E06}, Keine Aktion durch Benutzer, [4486e393f289fd39f8a473cb1fe3b34d],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{ceefadbd-a0ce-4422-a760-3b9167344e06}, Keine Aktion durch Benutzer, [6d5dd2a426550630c2da281623df9f61],

Registrierungsdaten: 7
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu),Keine Aktion durch Benutzer,[8248245294e712243090b4bbff05d927]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Keine Aktion durch Benutzer,[9832d3a342398da9c0fe7bf459ab0df3]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Keine Aktion durch Benutzer,[d8f2512567142a0c2996d09fcd37dd23]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Keine Aktion durch Benutzer,[d7f35b1be4971e1812af6609bb49a55b]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Keine Aktion durch Benutzer,[7f4b83f3b4c7a393edd548279b692ed2]
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Keine Aktion durch Benutzer,[4d7db9bd0a712511c09a8cda0ff50df3]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s),Keine Aktion durch Benutzer,[bd0dbcba8af1ed49ee1574fd758fe21e]

Ordner: 4
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe, Keine Aktion durch Benutzer, [903ab3c3bfbc52e4673f5f2ca65c9769],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0, Keine Aktion durch Benutzer, [d0fa5d194f2cad89597a8dff28da8977],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],

Dateien: 41
PUP.Optional.SnapDo.A, C:\Windows\Installer\17f2707.msi, Keine Aktion durch Benutzer, [597143334734bf77549386ff8b76f709],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp, Keine Aktion durch Benutzer, [d2f82c4a205b6accbe5eae804db354ac],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI999F.tmp-\Smartbar.Installer.CustomActions.dll, Keine Aktion durch Benutzer, [9238d5a1017aa88edd3f0b23a35d47b9],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp-\Smartbar.Installer.CustomActions.dll, Keine Aktion durch Benutzer, [23a77ff76318b086cb510c222bd5d729],
PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, Keine Aktion durch Benutzer, [4e7c84f2b9c28caa4196663418eaff01],
PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, Keine Aktion durch Benutzer, [aa204c2acead063028af8317bd4532ce],
PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, Keine Aktion durch Benutzer, [4882ec8a7605191d7b4ec6d8c53db24e],
PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, Keine Aktion durch Benutzer, [76549dd9daa19e988d3ccfcfe61c56aa],
PUP.Optional.RavingReyven.A, C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\firefox@ravingreyven.mobi.xpi, Keine Aktion durch Benutzer, [e4e63541037895a1ab25762839c98b75],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage, Keine Aktion durch Benutzer, [95353a3c700b60d6b54f02abf0124fb1],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage-journal, Keine Aktion durch Benutzer, [eae0552143384fe7cb39b3fa05fdfa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000005.ldb, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000013.ldb, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000016.ldb, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000020.log, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\CURRENT, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOCK, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG.old, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\MANIFEST-000018, Keine Aktion durch Benutzer, [3d8d3046a7d47db9953def9d4ab8fa06],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0\3, Keine Aktion durch Benutzer, [d0fa5d194f2cad89597a8dff28da8977],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho64.dll, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\1293297481.mxaddon, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\360-52916.crx, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-3.exe, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-5.exe, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.crx, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.xpi, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\background.html, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\bgNova.html, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bg.exe, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho.dll, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-nova.dll, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9.ico, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\Uninstall.exe, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\utils.exe, Keine Aktion durch Benutzer, [903a4c2a750631055205bdd6f210f20e],
Trojan.Agent.CK, C:\Users\Sven\AppData\Roaming\KW\KW.exe, In Quarantäne, [43872f474a3157df28d81377f30d4cb4],
Trojan.Agent.CK, C:\Users\Sven\AppData\Roaming\KW\updater.exe, In Quarantäne, [a1296b0bc5b6fa3cfd032862ca365da3],
RiskWare.Tool.HCK, C:\$Recycle.Bin\S-1-5-21-1098949856-1301053314-1890294551-1001\$RJKE92S.rar, In Quarantäne, [af1b5620c2b993a3024a687e7c85cd33],
Dont.Steal.Our.Software, C:\$Recycle.Bin\S-1-5-21-1098949856-1301053314-1890294551-1001\$RWQGGN5.exe, In Quarantäne, [5b6f31457902fa3c846098b241c38b75],
Trojan.Agent.PECB, C:\$Recycle.Bin\S-1-5-21-1098949856-1301053314-1890294551-1001\$RXCD4VN.exe, In Quarantäne, [be0ce69087f4023484c69bb8a45c49b7],

Physische Sektoren: 0
(No malicious items detected)


(end)


M-K-D-B 10.06.2014 11:25

Alle Funde mit MBAM entfernen lassen !!!


Dann weiter mit Zoek.

Goodfell 10.06.2014 11:28

Ich habe sie in die Quarantäne verschoben, ok so ?


Zoek läuft gerade

M-K-D-B 10.06.2014 11:30

Zitat:

Zitat von Goodfell (Beitrag 1313621)
Ich habe sie in die Qurantäne verschoben, ok so ?

Ja ok. :) In der Logdatei steht nämlich "Keine Aktion durch Benutzer", daher hab ich das nochmal geschrieben... es gibt ja Leute, die lassen einen Suchlauf starten, entfernen aber nichts und wundern sich dann, warum es nicht besser wird. ;)


Zitat:

Zitat von Goodfell (Beitrag 1313621)
Zoek läuft gerade

Sehr gut. :applaus:

Goodfell 10.06.2014 11:35

Liste der Anhänge anzeigen (Anzahl: 1)
Ohje, jetzt verunsicherst du mich ob ich alles richtig gemacht habe :lach:
ich lad dir mal ein screenshot hoch, wundert mich nämlich das da steht keine aktion durch den benutzer.
Soll ich mbam lieber nochmal drüber laufen lassen ?




Code:




Zoek.exe v5.0.0.0 Updated 02-June-2014
Tool run by Sven on 10.06.2014 at 12:01:03,82.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Sven\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

10.06.2014 12:05:19 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully
HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js:

Added to C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js:
user_pref("browser.search.suggest.enabled", false);
user_pref("browser.search.useDBForOrder", false);

Added to C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1222_.backup

ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default

user.js not found
---- Lines aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916 removed from prefs.js ----
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.active", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbar", "NA");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbarenhanced", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb.was_copied", "true");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb.was_copied", "true");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.backgroundver", 2);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.certdomaininstaller", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.changeprevious", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.value", "%221401873642%2
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.description", "Turn YouTube videos to High Defin
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.domain", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.enablesearch", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.homepage", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.iframe", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationThankYouPage", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationTime", 1401873642);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.__defualt_browser__.value", "%22ch%22
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb._installer_additional_info.expiration
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb._installer_additional_info.value", "%
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.expiration
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastDailyReport", "1401930857390");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastUpdate", "1401930836376");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.manifesturl", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.name", "PSHD-9.9");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.newtab", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.opensearch", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsurl", "hxxp://js.datademoserv.com/plugin/
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsversion", 45);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.publisher", "PlusVHD");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.searchstatus", 0);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.setnewtab", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.thankyou", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.updateinterval", 360);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.ver", 52);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.apps", "52916");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.bic", "1466996dea30ea4dd107112a5d7842b3");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.cid", 52916);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.firstrun", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.hadappinstalled", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.installationdate", 1401930834);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.modetype", "production");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.reportInstall", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ----

prefs__1222_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\found.000 deleted
C:\found.001 deleted
C:\found.002 deleted
C:\Users\Sven\AppData\Roaming\GetRightToGo deleted
C:\PROGRA~3\ICQ deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Gast\AppData\Local\avgchrome deleted
C:\Users\Sven\AppData\Local\avgchrome deleted
C:\Users\Gast\AppData\LocalLow\store-pp.jbs deleted
C:\Users\Sven\AppData\LocalLow\store-pp.jbs deleted
C:\Windows\Launcher.exe deleted
C:\Windows\Syswow64\tmp561E.tmp deleted
C:\Windows\Syswow64\tmp564E.tmp deleted
C:\Windows\Syswow64\tmp86CF.tmp deleted
C:\Windows\Syswow64\tmp878B.tmp deleted
C:\Windows\Syswow64\tmpDC75.tmp deleted
C:\Windows\Syswow64\tmpDCE3.tmp deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\firefox@ravingreyven.mobi.xpi deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\foxydeal.sqlite deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\CT2269050 deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\CT2431245 deleted
C:\Users\Sven\Desktop\Datein\pkm\SoftonicDownloader_fuer_visualboyadvance.exe deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [05.06.2014 06:15]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [18.05.2014 11:29]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
- ProxTube - Gesperrte YouTube Videos entsperren - %ProfilePath%\extensions\ich@maltegoetz.de
- Protegere - %ProfilePath%\extensions\security@protegere.org
- OutBrowse Toolbar - %ProfilePath%\extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc}
- TrashMail.net - %ProfilePath%\extensions\spam@trashmail.net.xpi
- FoxBox - %ProfilePath%\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi
- User Agent Switcher - %ProfilePath%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
A58DE0A570148AF5FF3512B2A340D09F        - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll -        Shockwave Flash
FF0D6F82A0EC13952E83B9439100E45D        - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll -        Facebook Video Calling Plugin
2BF85B6162528E0635DD8D632EB975C8        - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll -        Facebook Desktop
546A28FBC44B984FD92530227BF6F5C2        - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll -        Shockwave for Director / Shockwave for Director
905FD4EF56FCFD83D51FFA15E3FCE51E        - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll -        Move Media Player 7


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
daanglpcpkjjlkhcbladppjphglbigam - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[05.06.2014 06:14]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"ICQ Search"="hxxp://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://www.google.com"
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://www.google.com"
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://www.google.com"
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Reset Google Chrome ======================

C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyServer"="http=;ftp=;https=;"
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF1ECEF5-E5DC-7381-F153-A1348E310A5B} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeCall deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlusLiveUninstall deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Sven\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\op2zog0l.default\Cache emptied successfully
C:\Users\Sven\AppData\Local\Mozilla\Firefox\Profiles\p4ytj1qg.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=296 folders=71 77935732 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gast\AppData\Local\Temp emptied successfully
C:\Users\Sven\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Sven\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 10.06.2014 at 12:30:43,39 ======================


M-K-D-B 10.06.2014 11:37

Zitat:

Zitat von Goodfell (Beitrag 1313632)
Soll ich mbam lieber nochmal drüber laufen lassen ?

Ja bitte... dauert ja nur ein paar Minuten.

Am besten währenddessen nichts am Rechner machen. :)

Goodfell 10.06.2014 11:59

Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 10.06.2014
Suchlauf-Zeit: 12:38:50
Logdatei: MBAM 2.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.06.10.02
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Sven

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 383357
Verstrichene Zeit: 12 Min, 35 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 12
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, In Quarantäne, [5c6e0e685823ef473a62a797c939f50b],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, In Quarantäne, [5c6e0e685823ef473a62a797c939f50b],
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, In Quarantäne, [07c3a1d5c4b71521e88fc7aa07fbb848],
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, In Quarantäne, [07c3a1d5c4b71521e88fc7aa07fbb848],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\PSHD-9.9, In Quarantäne, [1fab7105097275c1e2046e3518ea24dc],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [4288373f3f3c2c0a25bfc5de3ac8916f],
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Outbrowsetoolbar, In Quarantäne, [d1f9e591205bc076c3677969a063dc24],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [8743e690bbc07abcde06d6cd33cfd927],
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PricePeep, In Quarantäne, [48820b6b8af1c86e94abd9e561a1e31d],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [16b47ff74f2ceb4bb27f0bc745be1fe1],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, In Quarantäne, [2b9fb8be4a3184b251326272e91a4ab6],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSHD-9.9, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 6
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu),Ersetzt,[676385f12b503afc0fb1b3bc7c88f808]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[c00aa1d5314a181e8f2ffb740df7827e]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[ebdfd1a55c1f90a61aa579f6ba4a48b8]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[9139fa7c0c6f1a1cc9f8df908f757f81]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[af1b4630cbb064d200c2aec155afa957]
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[4a807ff7304bb97ddc7e8bdb976d9b65]

Ordner: 4
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe, In Quarantäne, [b9113b3b8af113232d795338a55d8878],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0, In Quarantäne, [18b26610d8a383b36d663d4fc63ce917],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],

Dateien: 34
PUP.Optional.SnapDo.A, C:\Windows\Installer\17f2707.msi, In Quarantäne, [5b6f9dd93348b18509de483dfc05a65a],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp, In Quarantäne, [7e4c1a5cef8cda5c77a58ea0b64a4cb4],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI999F.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [5377d0a67ffc0333b16b35f957a9a25e],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [14b6b6c08af1181eda4288a6b44cdf21],
PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [7654096d304bba7c8f483664936fbf41],
PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [0dbd2056077463d34e8993071be7df21],
PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [ecdee096097270c669609e00c2403cc4],
PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [1baf591d6e0d2e0824a5c3db8c76b749],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage, In Quarantäne, [56740a6c156623137b893b72e022ad53],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage-journal, In Quarantäne, [d7f3284ec1baec4a669ebcf18979956b],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000005.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000013.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000016.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000020.log, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\CURRENT, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOCK, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG.old, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\MANIFEST-000018, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789],
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0\3, In Quarantäne, [18b26610d8a383b36d663d4fc63ce917],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho64.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\1293297481.mxaddon, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\360-52916.crx, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-3.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.crx, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.xpi, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\background.html, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\bgNova.html, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bg.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-nova.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9.ico, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\Uninstall.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\utils.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71],

Physische Sektoren: 0
(No malicious items detected)


(end)


M-K-D-B 10.06.2014 12:00

Gut gemacht. :blabla:


Jetzt weiter mit Zoek bitte. :)

Goodfell 10.06.2014 12:00

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 01
Ran by Sven (administrator) on SVEN-PC on 10-06-2014 12:56:42
Running from C:\Users\Sven\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2245120 2009-07-15] (VIA)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [G Data AntiVirus Tray Application] => C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3859320 2014-06-05] (AVAST Software)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2937528 2010-05-02] ()
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Auto KTR] => C:\Users\Sven\Downloads\Dm.De.M.C.Co.Edit-PROP\Kaspersky Internet Security 2014 + Trial + Kaspersky World\Kaspersky_Internet_Security_Trial_Reset_2.1_by_Humschi_1857\KIS14 TrialReset.exe -silent
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {732ced11-838c-11df-934f-002618bca0f6} - E:\raf-skyrim.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {c6647fc0-dbee-11e1-b1d5-806e6f6e6963} - E:\setup.exe
Startup: C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27BB72947FE9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\ich@maltegoetz.de [2014-05-20]
FF Extension: Protegere - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\security@protegere.org [2014-06-05]
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
FF Extension: TrashMail.net - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\spam@trashmail.net.xpi [2011-10-11]
FF Extension: Fox!Box - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi [2011-04-03]
FF Extension: User Agent Switcher - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2011-12-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-05]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []

Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-05]
CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-05]
CHR Extension: (Google Search) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-05]
CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-05]
CHR Extension: (Gmail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-05]
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-05]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-05] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-01] () [File not signed]
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3772784 2010-05-10] (INCA Internet Co., Ltd.) [File not signed]
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-12] ()
S2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [97552 2012-03-22] (SANDBOXIE L.T.D)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) [File not signed]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-05] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-06-05] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-06-05] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-05] ()
R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [65912 2012-03-08] (G Data Software AG)
R3 KMWDFILTERV1; C:\Windows\System32\DRIVERS\RPGMOUSEV1.sys [24576 2009-06-10] (Windows (R) Codename Longhorn DDK provider)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2010-08-18] () [File not signed]
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] ()
S3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [155136 2012-05-08] (SANDBOXIE L.T.D) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.)
S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2007-10-25] () [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) [File not signed]
R2 WinRing0_1_2_0; C:\Users\Sven\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys [14544 2010-05-02] (OpenLibSys.org)
R3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
U3 ar90ehyq; C:\Windows\System32\Drivers\ar90ehyq.sys [0 ] (Advanced Micro Devices)
S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X]
S3 dump_wmimmc; \??\C:\Program Files (x86)\Gameforge4D\CABAL Online\GameGuard\dump_wmimmc.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt
2014-06-10 12:29 - 2014-06-10 12:58 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt
2014-06-10 12:04 - 2014-06-10 12:30 - 00032826 _____ () C:\zoek-results.log
2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895}
2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr
2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com
2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar
2014-06-10 12:00 - 2014-06-10 12:22 - 00000000 ____D () C:\zoek_backup
2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt
2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt
2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt
2014-06-10 11:35 - 2014-06-10 11:36 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip
2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe
2014-06-10 11:28 - 2014-06-10 12:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-10 11:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-10 11:26 - 2014-06-10 11:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-06-10 11:18 - 2014-06-10 11:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-06-10 11:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-10 11:02 - 2014-06-10 11:11 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe
2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta
2014-06-10 01:11 - 2014-06-10 02:09 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos
2014-06-10 00:01 - 2014-06-10 01:10 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip
2014-06-09 18:17 - 2014-06-09 18:22 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar
2014-06-09 15:56 - 2014-06-09 15:56 - 00090241 _____ () C:\Users\Sven\Downloads\Addition.txt
2014-06-09 15:04 - 2014-06-10 12:57 - 00020788 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-09 15:04 - 2014-06-10 12:56 - 00000000 ____D () C:\FRST
2014-06-09 15:03 - 2014-06-09 15:04 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:00 - 2014-06-09 15:01 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:43 - 2012-05-12 12:31 - 00121416 _____ (MotioninJoy) C:\Windows\system32\Drivers\MijXfilt.sys
2014-06-09 04:43 - 2011-12-07 19:42 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00328712 _____ (Logitech Inc.) C:\Windows\system32\MijFrc.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00074960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xusb21.sys
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-07 05:44 - 2014-06-08 06:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2014-06-07 05:44 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-06 01:14 - 2014-06-06 01:27 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-05 22:54 - 2014-06-10 12:03 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-10 11:51 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:16 - 2014-06-05 06:14 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:15 - 2014-06-05 06:14 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:15 - 2014-06-05 06:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 02:05 - 2014-06-10 11:49 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-05 01:52 - 2014-06-05 02:06 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:46 - 2014-06-05 04:55 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-04 15:13 - 2014-06-06 01:23 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-04 11:49 - 2014-06-10 12:53 - 00045793 _____ () C:\Windows\setupact.log
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:48 - 2014-06-10 12:53 - 00019442 _____ () C:\Windows\PFRO.log
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:24 - 2014-05-28 23:52 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 19:51 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 01:48 - 2014-06-04 22:12 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-05-24 19:23 - 2014-06-09 15:37 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-05-22 07:09 - 2014-05-22 07:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:11 - 2014-05-22 03:12 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:13 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini
2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini
2014-05-22 03:10 - 2014-05-22 03:13 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:09 - 2014-05-22 03:10 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-22 03:02 - 2014-05-22 03:21 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-20 02:04 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-20 02:04 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-20 02:04 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-17 02:34 - 2014-06-09 15:41 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-05-16 18:58 - 2014-05-27 03:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-15 12:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 12:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 12:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 12:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 21:46 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 21:45 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 21:45 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 21:45 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 21:45 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 21:45 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 21:45 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 21:45 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 21:45 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 21:45 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 21:45 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 16:44 - 2014-05-27 02:29 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-12 11:48 - 2014-05-27 02:27 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos

==================== One Month Modified Files and Folders =======

2014-06-10 12:58 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-10 12:58 - 2010-05-02 11:53 - 00000000 ____D () C:\Users\Sven\AppData\Local\PMB Files
2014-06-10 12:57 - 2014-06-09 15:04 - 00020788 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-10 12:57 - 2012-05-30 00:00 - 01050021 _____ () C:\Windows\WindowsUpdate.log
2014-06-10 12:56 - 2014-06-09 15:04 - 00000000 ____D () C:\FRST
2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt
2014-06-10 12:54 - 2014-06-10 11:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 12:54 - 2014-05-07 00:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DropboxMaster
2014-06-10 12:54 - 2012-08-20 16:47 - 00000000 ___RD () C:\Users\Sven\Dropbox
2014-06-10 12:54 - 2012-02-27 23:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Dropbox
2014-06-10 12:53 - 2014-06-04 11:49 - 00045793 _____ () C:\Windows\setupact.log
2014-06-10 12:53 - 2014-06-04 11:48 - 00019442 _____ () C:\Windows\PFRO.log
2014-06-10 12:53 - 2013-04-03 00:13 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-10 12:53 - 2010-05-02 00:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-10 12:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-10 12:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources
2014-06-10 12:38 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-10 12:38 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-10 12:35 - 2010-08-25 16:11 - 08027136 ___SH () C:\Users\Sven\Desktop\Thumbs.db
2014-06-10 12:30 - 2014-06-10 12:04 - 00032826 _____ () C:\zoek-results.log
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt
2014-06-10 12:22 - 2014-06-10 12:00 - 00000000 ____D () C:\zoek_backup
2014-06-10 12:12 - 2012-07-12 11:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895}
2014-06-10 12:03 - 2014-06-05 22:54 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar
2014-06-10 12:02 - 2013-04-03 00:13 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-10 12:00 - 2014-06-10 12:29 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt
2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt
2014-06-10 11:51 - 2014-06-05 06:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-10 11:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA
2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt
2014-06-10 11:49 - 2014-06-05 02:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-10 11:36 - 2014-06-10 11:35 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip
2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe
2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Malwarebytes
2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-10 11:27 - 2014-06-10 11:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-06-10 11:19 - 2014-06-10 11:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-06-10 11:12 - 2009-07-14 06:45 - 00554864 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-10 11:11 - 2014-06-10 11:02 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe
2014-06-10 10:42 - 2011-12-22 15:59 - 00001134 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job
2014-06-10 03:38 - 2013-04-12 12:21 - 00000000 ____D () C:\Users\Sven\Downloads\01AlpaGun
2014-06-10 03:36 - 2010-05-02 01:31 - 00166832 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-10 03:33 - 2012-06-15 00:56 - 00211968 ___SH () C:\Users\Sven\Thumbs.db
2014-06-10 02:09 - 2014-06-10 01:11 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos
2014-06-10 01:42 - 2011-12-22 15:59 - 00001112 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job
2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta
2014-06-10 01:10 - 2014-06-10 00:01 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip
2014-06-09 18:26 - 2013-04-30 15:36 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2
2014-06-09 18:22 - 2014-06-09 18:17 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar
2014-06-09 15:56 - 2014-06-09 15:56 - 00090241 _____ () C:\Users\Sven\Downloads\Addition.txt
2014-06-09 15:54 - 2010-05-26 00:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-09 15:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-09 15:51 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-06-09 15:51 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-09 15:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-09 15:49 - 2009-07-14 04:34 - 00000387 _____ () C:\Windows\win.ini
2014-06-09 15:41 - 2014-05-17 02:34 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-06-09 15:37 - 2014-05-24 19:23 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-06-09 15:04 - 2014-06-09 15:03 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:01 - 2014-06-09 15:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-09 01:35 - 2010-06-20 16:07 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype
2014-06-08 06:33 - 2014-06-07 05:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 22:56 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-07 21:03 - 2010-08-01 05:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc
2014-06-07 20:12 - 2014-06-09 18:22 - 149696502 _____ () C:\Users\Sven\Downloads\Lucy-Cat - MAGICPOINT MIT ZUNGE - geht das überhaupt 05.06.14.flv
2014-06-07 05:44 - 2014-06-07 05:38 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2010-05-23 16:08 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DAEMON Tools Lite
2014-06-06 06:32 - 2009-07-14 19:58 - 00717506 _____ () C:\Windows\system32\perfh007.dat
2014-06-06 06:32 - 2009-07-14 19:58 - 00155122 _____ () C:\Windows\system32\perfc007.dat
2014-06-06 06:32 - 2009-07-14 07:13 - 01657416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-06 01:27 - 2014-06-06 01:14 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-06 01:23 - 2014-06-04 15:13 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-05 23:01 - 2014-04-04 10:42 - 00000000 ____D () C:\Users\Sven\Downloads\Animus
2014-06-05 10:13 - 2012-03-07 22:30 - 00000000 ____D () C:\ProgramData\G DATA
2014-06-05 09:54 - 2012-08-20 23:32 - 00000000 ____D () C:\Users\Sven\Downloads\thc-ssl-dos
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 07:00 - 2012-10-31 02:28 - 00000000 ____D () C:\Users\Sven\Downloads\GTA 4
2014-06-05 06:56 - 2013-05-09 01:56 - 00000000 ____D () C:\Users\Sven\Downloads\DVD1
2014-06-05 06:54 - 2013-10-04 00:55 - 00000000 ____D () C:\Users\Sven\Downloads\Capo - Hallo Monaco (Fan Edition)
2014-06-05 06:53 - 2012-03-04 22:38 - 00000000 ____D () C:\Users\Sven\Downloads\Bigger.Stronger.Faster.2008.German.AC3.BRRip.Xvid-HOR
2014-06-05 06:52 - 2013-04-19 14:24 - 00000000 ____D () C:\Users\Sven\Downloads\5fu54ggrt
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:43 - 2010-05-02 01:01 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:14 - 2014-06-05 06:16 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:14 - 2014-06-05 06:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:14 - 2014-06-05 06:15 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 04:55 - 2014-06-05 01:46 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 03:13 - 2011-04-02 01:40 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Users\Sven\AppData\Local\Mozilla
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-05 03:04 - 2013-04-03 00:14 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-05 02:06 - 2014-06-05 01:52 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:30 - 2014-03-09 11:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\JDownloader 2.0
2014-06-05 00:36 - 2012-05-25 07:38 - 00000000 ____D () C:\Users\Sven\Downloads\Celo & Abdi - Hinterhofjargon
2014-06-04 22:12 - 2014-05-29 01:48 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:24 - 2010-05-02 11:10 - 00000000 ____D () C:\Windows\pss
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:22 - 2010-05-02 01:22 - 00000000 ____D () C:\Program Files (x86)\CCleaner
2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-31 18:15 - 2013-08-31 20:27 - 00000000 ____D () C:\Users\UpdatusUser.Sven-PC
2014-05-31 18:15 - 2013-01-23 23:29 - 00000000 ____D () C:\Users\Gast
2014-05-31 09:42 - 2014-06-09 18:09 - 97747333 _____ () C:\Users\Sven\Downloads\Lucy-Cat - 100-SEKUNDEN-ARSCHFICKWETTE! Wieviel Stöße schaffst du 31.05.14.flv
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-30 20:02 - 2010-06-20 16:07 - 00000000 ____D () C:\ProgramData\Skype
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 20:03 - 2010-07-18 18:57 - 00000000 ____D () C:\Users\Sven\Documents\My Games
2014-05-29 19:52 - 2010-05-02 14:47 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-05-29 19:51 - 2014-05-29 08:38 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 19:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 03:49 - 2013-05-09 06:45 - 00000000 ____D () C:\Program Files (x86)\War Thunder
2014-05-28 23:52 - 2014-05-29 19:24 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-28 15:51 - 2012-08-20 16:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-28 00:55 - 2014-05-07 14:55 - 00000000 ____D () C:\Program Files (x86)\LCGenericName02
2014-05-28 00:28 - 2013-10-01 14:36 - 00000000 ____D () C:\Users\Sven\AppData\Local\ArmA 2 OA
2014-05-27 05:00 - 2012-08-21 07:08 - 00000000 ____D () C:\Users\Sven\AppData\Local\Trainer
2014-05-27 03:58 - 2014-05-16 18:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-27 02:29 - 2014-05-13 16:44 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-27 02:27 - 2014-05-12 11:48 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos
2014-05-22 18:43 - 2011-09-22 15:23 - 00000000 ____D () C:\Fraps
2014-05-22 07:10 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 07:05 - 2011-12-29 22:25 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-22 05:55 - 2013-09-05 05:41 - 00000000 ____D () C:\Users\Sven\Downloads\4ZuDer9
2014-05-22 03:21 - 2014-05-22 03:02 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-22 03:21 - 2012-05-07 06:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastChaosGER
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:13 - 2014-05-22 03:10 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini
2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini
2014-05-22 03:13 - 2014-05-22 03:10 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:12 - 2014-05-22 03:11 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:09 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr
2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com
2014-05-20 02:05 - 2014-03-09 11:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2010-05-02 14:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-20 01:49 - 2012-08-19 02:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-20 01:49 - 2012-08-19 02:55 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Wippien
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Program Files\Wippien
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-18 11:29 - 2013-06-07 06:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-18 11:29 - 2011-07-16 21:42 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft
2014-05-18 11:29 - 2010-05-02 01:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-17 03:21 - 2012-07-12 11:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-17 03:21 - 2012-07-12 11:08 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-17 03:21 - 2011-10-10 11:10 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-17 03:20 - 2010-05-02 01:24 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe
2014-05-15 14:14 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 13:31 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 12:48 - 2013-08-14 04:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 12:37 - 2010-05-02 11:19 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 20:30 - 2014-05-08 18:29 - 00000000 ____D () C:\Users\Sven\Downloads\RapidLC
2014-05-12 20:46 - 2010-11-07 21:40 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-05-12 10:29 - 2013-09-30 15:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-12 10:29 - 2010-10-03 14:41 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TS3Client
2014-05-12 10:29 - 2010-05-02 01:37 - 00000000 ____D () C:\Users\Sven\Tracing
2014-05-12 10:29 - 2010-05-02 01:34 - 00000000 ____D () C:\Windows\Panther
2014-05-12 07:26 - 2014-06-10 11:28 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-10 11:28 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2012-03-08 00:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

Files to move or delete:
====================
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini


Some content of TEMP:
====================
C:\Users\Sven\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4f7lre.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-08 00:01

==================== End Of Log ============================

--- --- ---

--- --- ---

M-K-D-B 10.06.2014 12:01

Vergiss meinen letzten Beitrag.... :crazy:

Goodfell 10.06.2014 12:02

Code:



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-06-2014 01
Ran by Sven at 2014-06-10 12:58:38
Running from C:\Users\Sven\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

7-Zip 4.65 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0465-000001000000}) (Version: 4.65.00.0 - Igor Pavlov)
Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.)
Alarm für Cobra 11 - Das Syndikat - DEMO (HKLM-x32\...\Alarm für Cobra 11 - Das Syndikat - DEMO_is1) (Version:  - dtp)
Angry Birds (HKLM-x32\...\{61637194-D4E8-45CB-8619-23CE7B637FCF}) (Version: 2.0.2 - Rovio)
Angry Birds Space (HKLM-x32\...\{40044440-4ED4-4792-8417-5EE6374F001C}) (Version: 1.1.0 - Rovio)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArmA 2 Free Uninstall (HKLM-x32\...\ArmA 2) (Version:  - )
ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\...\ARMA 2 Operation Arrowhead) (Version:  - )
ARMA 3 (HKLM-x32\...\QVJNQTM=_is1) (Version: 1 - )
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.01 - Ubisoft)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AutoHotkey 1.0.48.05 (HKLM-x32\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett)
AutoIt v3.3.8.0 (HKLM-x32\...\AutoItv3) (Version:  - AutoIt Team)
Avast License by ZeNiX [2014-03-14] (HKLM-x32\...\Avast_2050_ZeNiX [2014-03-14]_is1) (Version:  - )
avast! Pro Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2017 - Avast Software)
Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - )
AwesomiumSetup (HKLM-x32\...\{19EF99D1-7EE6-4B5E-ABEE-0B3825F703B0}) (Version: 1.00.0000 - SIX Networks GmbH)
Axife Mouse Recorder DEMO 5.01 (HKLM-x32\...\Axife Mouse Recorder DEMO_is1) (Version:  - Axife Software)
Batman Arkham City version 1.0 (HKLM-x32\...\{B531E735-8ED5-4270-ACCE-3809086FBD02}_is1) (Version: 1.0 - WB Games)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlefield 4™ Beta (HKLM-x32\...\{CFAB3721-549D-4827-A4E8-7F90192114AB}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
BattlEye (A2Free) Uninstall (HKLM-x32\...\BattlEye A2 Free) (Version:  - )
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
CPUID HWMonitor 1.21 (HKLM\...\CPUID HWMonitor_is1) (Version:  - )
Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
Cuttermaran 1.70 (HKLM-x32\...\{5F499D33-546A-442B-B0F9-4C58F3B5B6E3}) (Version: 1.7.0 - toarnold)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0337 - Disc Soft Ltd)
Dark Souls Prepare to Die Edition (HKLM-x32\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Dark Souls Prepare to Die Edition (x32 Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
DayZ Commander (HKLM-x32\...\{99C28455-E285-4639-B4C6-9F747C0C3D4C}) (Version: 0.92.90 - Dotjosh Studios)
DayZero Launcher (HKLM-x32\...\{121CAAD8-0CD7-48CC-A3E1-A1AB8C0B1086}) (Version: 01.00.004 - ZOMBIES.NU)
Der Herr der Ringe Der Krieg im Norden Version v1.0 (HKLM-x32\...\{4F7F52F2-DFD5-4FE3-8D24-2B7CEB9980C8}_is1) (Version: v1.0 - )
DiRT 3 (HKLM-x32\...\GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}) (Version: 1.0.0000.130 - Codemasters)
DiRT 3 (x32 Version: 1.0.0000.130 - Codemasters) Hidden
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
Download Protect (HKCU\...\{132401a7-2006-4342-b43c-ccf5f02c2b01}) (Version:  - Download Protect)
Dr. Hardware 2013 13.0d (HKLM-x32\...\Dr. Hardware 2013_is1) (Version:  - Peter A. Gebhard)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
DVD Architect Studio 5.0 (HKLM-x32\...\{04DF4A51-DE2A-11E0-9AB5-F04DA23A5C58}) (Version: 5.0.156 - Sony)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2010 AI Settings (HKLM-x32\...\{C0EBA426-3C37-4DFC-B96C-1AE9263E720D}_is1) (Version: 1.0 - )
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2013 German (HKLM-x32\...\RjEyMDEz_is1) (Version: 1 - )
Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.5.0.0 - Electronic Arts)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free Hide IP (HKLM-x32\...\FreeHideIP) (Version: 3.9.6.6 - )
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.35.514 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.35.514 - DVDVideoSoft Ltd.)
Freemake Audio Converter Version 1.1.0 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Freemake Video Converter Version 3.0.1 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.0.1 - Ellora Assets Corporation)
German Truck Simulator 1.00 (HKLM-x32\...\German Truck Simulator) (Version: 1.00 - )
GhostMouse (HKLM-x32\...\GhostMouse_is1) (Version: Free V3.2 - ghost-mouse.com)
GIMP 2.6.8 (HKLM\...\WinGimp-2.0_is1) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Google+ RegHelper (HKLM-x32\...\de.txptr.googleplus) (Version: 1.4.0 - UNKNOWN)
Google+ RegHelper (x32 Version: 1.4.0 - UNKNOWN) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV v1.0 Eng (HKLM-x32\...\Grand Theft Auto IV_is1) (Version:  - )
GSview 4.9 (HKLM-x32\...\GSview 4.9) (Version:  - )
Gunblade Saga (HKLM-x32\...\{0AC07A77-0511-4904-9FA1-616DC9BEF50D}) (Version: 11.09.30 - Mail.Ru Games GmbH)
HyperCam 3 (HKLM-x32\...\HyperCam 3) (Version: 3.4.1205.14 - Solveig Multimedia)
IL-2 Sturmovik 1946 (HKLM-x32\...\InstallShield_{79438F1E-DEC3-443D-9DCD-FECE2D68C605}) (Version: 1.00.0000 - Ihr Firmenname)
IL-2 Sturmovik 1946 (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden
IL-2 Sturmovik Cliffs of Dover (HKLM-x32\...\IL-2 Sturmovik Cliffs of Dover_is1) (Version:  - )
Java 7 Update 21 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 27 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.270 - Sun Microsystems, Inc.)
JDownloader (HKLM-x32\...\JDownloader) (Version: 0.89 - AppWork UG (haftungsbeschränkt))
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH)
KaloMa 4.76 (HKLM-x32\...\KaloMa_is1) (Version:  - Frank Böpple)
LastChaosGER (HKLM-x32\...\{A86A50FC-7C22-478B-BAEF-82393328825F}) (Version: 1.00.000 - Barunsongames CO., LTD.)
LCGenericName02 Version 1 (HKLM-x32\...\{4AA19E32-8010-477A-8FC3-B6C1691174AD}_is1) (Version: 1 - LCGenericName02)
Macro Recorder (HKCU\...\2a7a433177cfa3a6) (Version: 5.0.0.156 - Jitbit Macro Recorder)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{368FDD4C-1D79-44B6-9E86-6A1FF6D1496E}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video Pro X6 (HKLM\...\MX.{CBC84EDA-E830-4240-9392-325C3E6D5DCA}) (Version: 13.0.3.24 - MAGIX AG)
MAGIX Video Pro X6 (Version: 13.0.3.24 - MAGIX AG) Hidden
MAGIX Video Pro X6 64 bit Update (Version: 13.0.4.2 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version:  - )
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Minecraft Beta 1.8.1 Version v1.0 (HKLM-x32\...\{1753427B-E948-4E5B-B4A1-1E7959AD9BDA}_is1) (Version: v1.0 - Godslayers)
Minecraft Cracked (HKLM-x32\...\Minecraft Cracked) (Version:  - )
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
Mount&Blade With Fire and Sword (HKLM-x32\...\Mount&Blade With Fire and Sword) (Version:  - )
Mouse Recorder Pro 2.0.7.4 (HKLM-x32\...\{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1) (Version:  - Nemex Studios)
Move Media Player (HKCU\...\Move Media Player) (Version:  - Move Networks)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Need for Speed(TM) Hot Pursuit (HKLM-x32\...\{83A606F5-BF6F-42ED-9F33-B9F74297CDED}) (Version: 1.0.0.0 - Electronic Arts)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.43.2 - Black Tree Gaming)
NVIDIA 3D Vision Controller Driver (x32 Version: 275.33 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 326.80 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 326.80 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
NVIDIA Grafiktreiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 326.80 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA nTune (x32 Version: 1.00.0000 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2680 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 326.80 (Version: 326.80 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Next 12.01 internal build 1491 (HKLM\...\Opera 12.01.1491) (Version: 12.01.1491 - Opera Software ASA)
Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.3.3.6 - Pando Networks Inc.)
PC Connectivity Solution (HKLM-x32\...\{AC599724-5755-48C1-ABE7-ABB857652930}) (Version: 8.15.0.0 - Nokia)
PC Inspector File Recovery (HKLM-x32\...\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}) (Version: 4.0 - )
Perfect Effects 3 Free (HKLM-x32\...\{B8D92680-34AC-4B76-8D95-7E95B11B5121}) (Version: 3.0.2 - onOne Software)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Pinnacle VideoSpin (HKLM-x32\...\{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}) (Version: 2.0.0.669 - Pinnacle Systems)
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
Pro Evolution Soccer 2010 (HKLM-x32\...\{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}) (Version: 1.03.0000 - KONAMI)
Pro Evolution Soccer 2011 (HKLM-x32\...\{1148E85C-E1AF-48E0-A29C-68DACE07E054}) (Version: 1.00.0000 - KONAMI)
Pro Evolution Soccer 2014 (HKLM-x32\...\{5EFD3544-2371-4900-8ACA-F157BA80FB0C}) (Version: 1.01.0000 - KONAMI)
Process Hacker 2.30 (r5267) (HKLM\...\Process_Hacker2_is1) (Version: 2.30.0.5267 - wj32)
Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64)
Protegere (HKLM-x32\...\Protegere) (Version:  - )
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden
QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version:  - )
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
raving reyven (HKLM\...\raving reyven) (Version: 2014.03.27.174842 - raving reyven)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6029 - Realtek Semiconductor Corp.)
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version:  - )
Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
SamsungConnectivityCableDriver (HKLM-x32\...\{7E84FAC8-C518-40F9-9807-7455301D6D25}) (Version: 6.83.6.2.1 - Samsung)
Sandboxie 3.66 (64-bit) (HKLM\...\Sandboxie) (Version: 3.66 - SANDBOXIE L.T.D)
Ship Simulator Extremes (HKLM-x32\...\Ship Simulator Extremes_is1) (Version:  - )
shopping-preise.de - AddOn für Firefox (HKLM-x32\...\{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1) (Version: 2.81 - shopping-preise.de)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{0AA0DA00-A1D3-11E0-B9A9-005056C00008}) (Version: 10.0.176 - Sony)
StarCraft II (HKLM-x32\...\StarCraft II) (Version: 1.0.0.16117 - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strike Suit Zero (HKLM-x32\...\Strike Suit Zero) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Explorer 3.9.8 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version:  - Mister Group)
System Requirements Lab (HKLM-x32\...\{9E1BAB75-EB78-440D-94C0-A3857BE2E733}) (Version: 4.1.71.0 - Husdawg, LLC)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version:  - )
System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH)
The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00) (Version:  - )
The Elder Scrolls V: Skyrim (HKLM-x32\...\{3844035A-9429-4E54-86B0-6EE3778BA3FB}_is1) (Version: 1.1.21.0 - RAF)
The Last Remnant (HKLM-x32\...\The Last Remnant_is1) (Version:  - )
The Walking Dead: Episode 1 and 2 (HKLM-x32\...\{26B906EC-2979-4936-AED1-30CB96927F64}_is1) (Version: 1.0 - RAF)
TopSecret Biometrics Components (HKLM-x32\...\{C8BCC14C-2807-4C2D-A659-843427BF82E2}) (Version: 1.00.0000 - G DATA Software)
Tropico 4 Collectors Bundle (HKLM-x32\...\Tropico 4 Collectors Bundle_is1) (Version: 1.0 - ADDONiA)
Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version:  - Tunngle.net GmbH)
Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version:  - )
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
War Thunder Launcher 1.0.1.199 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - 2012 Gaijin Entertainment Corporation)
WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version:  - Ubisoft)
Watson (HKLM-x32\...\{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}) (Version: 1.0.0 - Windows Live Safety Center)
Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live OneCare safety scanner (HKLM-x32\...\Windows Live OneCare safety scanner) (Version:  - Microsoft Corporation)
Windows Live OneCare safety scanner (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0) (HKLM\...\BC15EA930074932BB2C4B4493C9FD4EA95087D1A) (Version: 10/12/2007 6.85.4.0 - Nokia)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )

==================== Restore Points  =========================

09-06-2014 13:45:59 Removed Microsoft Office Professional Plus 2010
10-06-2014 10:04:54 zoek.exe restore point

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {00206791-3604-49AF-A7B6-6F9F96435F75} - System32\Tasks\{48D33453-E9D9-469F-849D-160A78897C05} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0060DF2D-C334-4E56-AC85-3BA0B4BB8C19} - System32\Tasks\{0482E8F0-DC94-4116-82C3-A524AA6EDD56} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {00DE4891-4768-4781-B8F9-D3BACDC71C60} - System32\Tasks\{5FC532AA-6E13-40F5-B394-1335CB2802E7} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {01543BE2-B3C2-432D-8625-B3E687D20ECC} - System32\Tasks\{6EA1C590-18CC-4242-A3EE-D4D863F62C44} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {028BF155-0170-4774-A4CC-20D842C89A45} - System32\Tasks\{42382861-E829-44D8-82CA-CAEE691391DD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {047FB690-D3B8-4407-BC58-CF1BEAAA9109} - System32\Tasks\{5DB0F65E-BA72-42BD-9F77-902282F494D5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {04CDF2BE-9C9E-496F-B957-1C56120C5971} - System32\Tasks\{FB0C5B4B-828E-4A3A-8E3E-5CF0415AC411} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {05290312-83EB-408E-B517-6FACAF272D54} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {05768801-9C10-4797-BA90-B0C2AFE28B74} - System32\Tasks\{3B811B6B-73E2-4C71-900E-DDFD4DF79ACD} => E:\AutoRun.exe
Task: {059CDD4F-B16C-43B6-B938-D9B530A62A51} - System32\Tasks\{9AC660E1-E379-48DA-A67E-E8AAD6BFC56E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {07DCA1A2-0AD2-4B86-B2FD-715C05CCA7AB} - System32\Tasks\{0BDE8801-35E5-4CD1-B357-8B6E6DF01DCC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {09240454-01FE-4102-9921-BBDA41827BDE} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {0A4CE36B-9B12-4B1E-B540-CA6072A90AEE} - System32\Tasks\{46F5B8DA-D479-487D-A2CB-ED1923FB1373} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0A6C2D4D-1161-4D27-B474-59BAAE8F27FB} - System32\Tasks\{531E50E7-B9D2-4660-95F5-9641C3586AAC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0A6C8C93-F7AB-43F6-A0CC-281D24D3CF72} - System32\Tasks\{E47A74B7-37CB-40DE-8AF4-D63E9E1F8C1A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0BD63AAF-49E0-4A9A-BDEF-BD66D87211E1} - System32\Tasks\{EBFB120D-5756-4184-8E28-539FF3975ED0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0C06DDDD-3F65-4B71-B0F6-EAB79FA8F6E0} - System32\Tasks\{16D23950-57D0-4260-A83C-7A9EF3BA8B10} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0D011E81-3D76-44F3-8626-D2750C23ED12} - System32\Tasks\{56327058-6A18-428D-8411-A8D80E3FD0DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0DADA3D1-96FD-46DA-A2EE-5F7F740710A8} - System32\Tasks\{C10B0F16-9D9E-44BE-B53F-2A79DD22417C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0DC20443-9129-4C90-9D0B-469A0FE8065F} - System32\Tasks\{1AD275C9-3DEC-44AE-9C34-FF6453D7FDCB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0EC1E659-64D9-4CC9-813C-2B19E5FECBF7} - System32\Tasks\{1808866F-9A73-4701-B5B8-92DDDCA1A936} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0EF04926-207E-445D-96F6-71F7BFB973C7} - System32\Tasks\{9FFEA193-9C5E-42FB-A13A-3C45B191659E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0F8CC94F-048A-4366-8240-9F01292E5C25} - System32\Tasks\{BC26F19E-C830-4EA2-85AE-3D5AA929C880} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {108C58DC-9854-44E7-A15A-E8D4A2CC38BD} - System32\Tasks\{716EAD2A-A1E3-4E82-9C02-36776753AE4D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1313A74E-8497-4CCC-B653-3430D26F947D} - System32\Tasks\{6136571D-6365-4A71-800A-9C16B89DC946} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {14CCF703-5440-4955-AE87-C0BEC0BCDF82} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-05] (AVAST Software)
Task: {151F64D7-9CE9-4B1E-B0B6-12A82939FAF7} - System32\Tasks\{8ECB201E-0FC2-497B-8C23-F10C1A93DA27} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {15666D0F-7586-4000-9932-149CDA127E6F} - System32\Tasks\{C43090F5-62C8-42D4-BADF-150BBF0A3F2B} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/go/help.faq.installer?LastError=1603
Task: {1591003B-2F48-465D-981B-7B8A41007100} - System32\Tasks\{3113EAE0-844D-46F8-A4E2-97BCA735D923} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {1646E41A-0620-458D-9842-6A07C0AA33EE} - System32\Tasks\{F92CFB9A-E557-47B1-A8A8-D48BF88C12E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1670DFB5-521E-472F-84EF-3AE74946A37A} - System32\Tasks\{CE9CC2D0-7509-4B2D-A43D-5BB9A1710D03} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {17BB7FAD-D2FC-49F3-AE14-A4225B06B8E3} - System32\Tasks\{28AB3BCF-EE50-484F-BE21-F66EF3461957} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {18A75256-BA65-4CDA-AB02-9A1FBCA6AC0E} - System32\Tasks\{FE6DADBB-DE8F-4BDC-87FD-D36DB2CEEAA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {18FD2294-3EDF-4904-AA67-94057FBF0BA2} - System32\Tasks\{A7523CFB-164F-4EAB-B8CC-4CADB4D534DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1B2FEB5E-2676-43C1-908A-4B640D75A679} - System32\Tasks\{86A0D00A-38FF-4988-B2A3-31B1F266576E} => C:\Program Files (x86)\Railworks 2010\RailWorks.exe
Task: {1D1F8052-52AC-44ED-B134-C4C689E7AB48} - System32\Tasks\{81E83BD6-E3AC-4909-9EAF-74158FB16614} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1D782067-0E4C-41F2-91EC-51C1CBA0F339} - System32\Tasks\{9F2389C9-E0A7-477B-9909-F031582AD6F5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1DD72608-CFA6-4AD2-B913-E3B6831F2464} - System32\Tasks\{72826905-205B-4821-8621-1D8C8E08F2BC} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe
Task: {1DF7B898-5E91-4ED8-90F1-B725BE742DCA} - System32\Tasks\{6F286A32-34B2-4E27-AF82-2D838BCB3012} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1E503B2C-0E1A-4C72-965A-09996706192C} - System32\Tasks\{4DBAEF55-EF8E-4852-B9F5-AFB4ED2630A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2199FF4C-C031-4D14-BF52-F596A11DCA8B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe
Task: {23941C5E-F5AF-4F47-ADF6-E326297ADA8A} - System32\Tasks\{F3092C73-8B09-4013-ADED-52F3D3F4B852} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {248467D6-6AE9-474E-B9D8-C2B325203880} - System32\Tasks\{C5CC5AE2-842A-40F2-BED4-FDD2C8FBED5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {258C4939-0DEC-4711-8B26-F2DAFEE63003} - System32\Tasks\{3DFE2278-9A94-4095-A89F-8E4DB9B77C0C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {25FCB770-2B27-43F5-82C6-9A99F7CF951C} - System32\Tasks\{33702D64-5E9F-4E66-B15D-57A6C7753CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {264FE3BF-A728-4ED0-8784-485E95EB9332} - System32\Tasks\{4DF0AC0C-7E9F-476A-812D-66F469EB75C5} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {26AFDCE2-62B0-4A72-9BF5-46014D9C84FE} - System32\Tasks\{C14816C9-AC1D-44B3-A1B4-2D930E834141} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {26F96DDC-18B4-4D1E-AD74-F4D4F74ABE9F} - System32\Tasks\{10C1E1CD-1BAF-4D59-A603-08BFCA24646D} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {2A71016B-03C8-4233-B859-2F22E75C79F5} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1098949856-1301053314-1890294551-1001
Task: {2C83876C-E904-40A0-BC07-504872AE2B1D} - System32\Tasks\{61B863D1-021C-4E73-897A-46FF41577FBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2CA817F9-FBB1-494E-B5BA-1A78D6C7033D} - System32\Tasks\{EF0E0319-3DD7-45C8-86EB-15DFE8C8BCDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2D6CAF9A-1CD9-4364-988E-B477F7EF5522} - System32\Tasks\{734FA937-B120-4B5C-A837-2088381DA3D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2D991809-8C7D-40DD-BDC7-D5C5636BB74C} - System32\Tasks\{48E2514F-1BB2-4C45-A316-4FBC8FD30901} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2EEFA68F-9662-4975-B6F9-786821AA4B7D} - System32\Tasks\{CBA16325-3343-4E45-8DB1-EA6FD9411E8E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2F1602D8-2D54-4CE8-AA5A-5EEF7E2A858E} - System32\Tasks\{D21EA65A-44EB-464A-9DE2-146F048CA557} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2F94047F-3A85-4824-B184-84E692DD8FDC} - System32\Tasks\{8AAC4425-84C7-473A-9176-7CDC1B945E17} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3024CA3C-1A96-4627-9537-ED118A186E67} - System32\Tasks\{E2F5210F-2631-4D91-846F-19297E04B896} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3032538E-C43C-4D03-9188-6A4F0549E71B} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {30568D3D-7971-4F36-81FD-E61631C4BB57} - System32\Tasks\{7A87D65E-FDC1-4CB9-90D4-D12D3FA46EBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {327DE954-86CA-4727-BEDB-3D552CE75DC2} - System32\Tasks\{B2F079F0-A5EA-4E87-8D44-B8520B2B3744} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {34B0DB67-D565-4912-B698-F6A3820BB42E} - System32\Tasks\{326BB3CB-2AA7-409F-8145-AE956B1109A2} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {34DC50F6-70ED-48F6-9E59-E47E80C5F6C5} - System32\Tasks\{81F3A03F-A984-4D44-8C6E-481C91E702C2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {38033478-0F98-4B7F-9FE4-F40D65526668} - System32\Tasks\{A285C147-7F6E-460C-8794-6453B4B02DDE} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {38596C41-5023-4B7B-A97A-FFCFB4638D5B} - System32\Tasks\{56D14608-B485-45C4-AFA3-D4697153A8EB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3896DA66-668F-4E13-8D8B-14701CA38B7A} - System32\Tasks\{02976DCA-3D64-4818-8AB2-D452E2EDBD39} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION
Task: {3BA6A538-EDC3-42E7-B0DC-94555326A0E0} - System32\Tasks\{F599B4D3-A939-427B-BFAD-41215FFA4B06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3BB70042-89B5-4A30-AC51-AB0D69BB4B48} - System32\Tasks\{3A87CEDE-5E99-4260-A802-4AA83B8A0AD3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3BC27ED0-6484-4FF7-A68A-D54328294275} - System32\Tasks\{0FEA611C-B1BF-4668-9918-41A30DF48CC3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3D42ADE7-E1E6-4302-8844-122441F4B904} - System32\Tasks\{76D5F951-BF21-4A9D-8603-7AE010F98315} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {3F5B5D63-9908-4BA1-8C99-A3C1718E5EE9} - System32\Tasks\{DBC5E996-473B-425F-9DB0-97B88D1C9349} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3FDBAE0C-A108-4561-BFDD-89C3C2F3D570} - System32\Tasks\{0BD20564-C544-4345-A074-D421C4CC49E0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {415EAC50-7423-4ECB-B27D-1D20376B9A4F} - System32\Tasks\{362EC899-4A81-4D93-96BA-13249EE94512} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {41F754B4-BA61-4685-AE07-6402385F6933} - System32\Tasks\{8AEB40A7-FA35-48F5-82EB-EA0819FB326B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {422EB8B1-2BD7-4FF0-A55D-6A3F7EBE8EDF} - System32\Tasks\{4A347536-E75E-4196-AB34-F33A32433986} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4350EF98-4350-4E0F-98FD-C4EB6ED33391} - System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618
Task: {45DC1622-0863-4EC2-8060-B48745AA713B} - System32\Tasks\{EAC80C87-0609-4B31-966F-868E17803A7B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {4737680D-7D41-4EDD-89C7-3608C0004939} - System32\Tasks\{C8071675-FABC-45F3-BF98-E3D37474BB4E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {475F81D7-458B-41BC-8A3D-9C3162F60648} - System32\Tasks\{D7CDC2B5-4F80-47C5-B6DD-1D8018821633} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {4770E7B8-7CFF-493C-9976-C434C787CD0B} - System32\Tasks\{8F1ECE0A-1A81-48B5-85BC-2B7D41547151} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {47D83C6B-CF1E-4562-96CA-C7D25840572B} - System32\Tasks\{0AA5EC75-C091-44FA-82A9-44BC0DDA59E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4A9A003A-7665-4B9E-B336-A56DE8E8789B} - System32\Tasks\{BE4896D2-6869-4B2B-8F8D-BCA1F61A2487} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B2BDB10-32EF-4B37-9AA1-B15CAD2A48F6} - System32\Tasks\{887B7566-0AAF-435D-B5EB-86E215D22677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B437054-DE44-423D-8381-6D09430DFFA9} - System32\Tasks\{CD46C27E-3FC1-4211-920C-E8A7F411CF5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B64318D-5F94-4677-BDEF-13D5B6FDFB73} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.)
Task: {4C482DEE-9E14-4738-A2C6-84243B47285E} - System32\Tasks\{65FE692F-FAE1-4833-A4E3-5B91189BDA71} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4CE83691-0839-4DF7-BB2D-16C096CA1DD9} - System32\Tasks\{DCB5B081-0D7D-4A9D-BFB6-F75BA6B4FFE4} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {4D272B4D-0F7B-4149-96B7-E92D0CE78840} - System32\Tasks\{179B45CD-DEC5-4ED2-A215-93FE8E3A3B52} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4E55A326-7F9C-456A-B061-F773C26BB4B9} - System32\Tasks\{C287E2B1-6EFF-4D09-9101-EAD7B150CB7B} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?page=tsProgressBar
Task: {4F9E67CB-A23E-4973-85EA-DC854F0C5049} - System32\Tasks\{115DA74C-5B2D-40DA-947B-BAEDFEA6A8E2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {521EC980-CAC6-4F1D-B6FA-C7BC3A98441F} - System32\Tasks\{81DCE1C0-894D-4779-A1BB-70EE95F4E4B2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {55FEEF07-8E10-45F7-85F6-11C4D8959BF6} - System32\Tasks\{B37F681A-EF3E-45CC-9F17-864119A91E65} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {56C4AFB3-803E-46C9-8C94-ACC9588F0452} - System32\Tasks\{C694B19B-E147-4FDB-9837-2D8A57B43CD8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {57D5AA40-981A-438F-B928-D3733FD29B8D} - System32\Tasks\{0D35558A-B8E3-478D-92C2-CB6CAF71D82C} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {585C0F3C-AD7C-494C-95AB-929FC93FD477} - System32\Tasks\{7D4A2968-2466-423B-8693-D892F5770BC2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {59201B3B-2CF8-44D3-BA51-AA71F9BD925B} - System32\Tasks\{2A7E476D-1AB7-4688-A479-ED4CB5FE309C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5A19A249-F795-411F-B1A5-22070127E4D8} - System32\Tasks\{3D7F2444-BC97-4FC1-A3AD-2050924AB4E4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5A75A413-5A4D-47D6-B08F-3A09AF467BA6} - System32\Tasks\{126D53C6-D39A-48FE-87A3-BE39FECA82A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5B55648B-938F-4098-AA57-C551B3F04294} - System32\Tasks\{BA7A9134-7D67-401C-8D4C-39B014EC993C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5BC20421-CD55-437D-B993-7ED3F777584D} - System32\Tasks\{92825E9C-7F09-4EF5-A901-8D20AB4C1CED} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {5D2C9C91-EBBD-4630-BE2B-DDB3E6EB314E} - System32\Tasks\{5CE6AC57-2F71-4A9C-B339-34847941A456} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5F627168-4146-41EC-A6E7-4139910834F3} - System32\Tasks\{0498C35C-C89F-4EDA-BA65-F25B08667C06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {63385CAB-C77F-4D19-8E64-56010138AA02} - System32\Tasks\{F9D4650D-451C-4CF7-AF96-55C9D5512DF6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {6508B54E-7342-451D-B651-920729BB2E43} - System32\Tasks\{E2A806C7-3C0D-402F-ACE6-28E8CB964BE2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {65DDD6CA-9B68-44C9-B4BC-B2360B7CB949} - System32\Tasks\{C8F7C6D2-FC04-41A4-AB21-AF4830FD735C} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {685EC281-E83D-41DF-A5CC-91A8925976AC} - System32\Tasks\{F4948F46-A30B-4C1A-B276-7F5EC91174F1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {687804B6-E9CD-4E37-9D92-D197693B397E} - System32\Tasks\{0EECE376-7CDE-44E3-84E0-72D5A5ED585D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6A8E2C17-BAEB-4DC8-A342-84DF6286A844} - System32\Tasks\{6EFAE2C9-AE73-4A53-B318-92B8924F73F6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6B8374AE-0ECA-4D2D-BB9A-45344C01B9C5} - System32\Tasks\{9325521E-959B-40C0-AE8A-DE5FABB2B06F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6BA32B1F-4293-4074-BD78-CE1A5F17ED99} - System32\Tasks\{8E72C766-9BB4-4166-9866-76139173268C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6C1979F1-AB41-4EC0-944E-0D16797FF4FD} - System32\Tasks\{454F111B-9668-405C-9D32-5B05FDF5731F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {7250271B-F6A2-470A-85A2-0168259D90A8} - System32\Tasks\{E4F229CC-7F16-4DC9-A408-AAB6CAC3F797} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {73D95EE9-648D-4C8F-8911-6B63E0A22F04} - System32\Tasks\{3E98FF82-D955-45DF-983A-3EFBA31786F9} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {757946F4-35A8-4AEC-B087-00F90BFC2B01} - System32\Tasks\{7B88D895-FA14-4844-A488-041B3EAA833E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {76212287-AAC0-4420-A612-24FD8A9DA5F9} - System32\Tasks\{A2D10B81-B079-4BC6-987C-A19BF3AF4496} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7916DCDF-AC27-4A62-892F-9DE2BAADE7BB} - System32\Tasks\{0DBAD5B0-D837-4E82-8270-D732E84B8997} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {79F6D2E3-BB87-4B16-A090-9A6AA4E273DA} - System32\Tasks\{0C33B5D8-227A-489D-9DC7-201BDC56A2CB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7A79C6A3-E123-4706-990B-7FA2A25E8334} - System32\Tasks\{C77745DF-3ABE-49EA-84BB-ACDF2CB0C172} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe
Task: {7EDE632F-8D75-4EDA-8D30-5F6D6E0DE3F0} - System32\Tasks\{0F216DE1-10A4-4121-9354-94F1FCAE0BA7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7FA4FAB4-B29B-46CB-A242-E31BD6102BC8} - System32\Tasks\{6F643769-F667-45A7-89A3-EFB78BAD30D2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {805A90DD-4661-4FA4-ACC5-9746B1FD37E9} - System32\Tasks\{899D1CD0-E191-4706-820D-6FCC78860A5D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {812EA991-4051-4066-8F6D-7657E59F6F13} - System32\Tasks\{13CC1F28-B809-4E6A-92F6-050867303E38} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {8432A04B-4B1C-4DF7-88E8-D224B18E0864} - System32\Tasks\{7D8FC48F-F5D5-41C9-A0C7-46FFDB261DF9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {843DBDDA-40BA-402E-BA69-2271D24F05F8} - System32\Tasks\{C6726A3E-D031-4D25-A625-2FB541085294} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {846792F6-E344-4F5C-8269-35876689B894} - System32\Tasks\{722EE7AC-CBDE-41B1-A4FB-3996382D0916} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85198C15-CF04-4EB5-8361-B1B6A57279E2} - System32\Tasks\{C6F24B23-E357-414F-8A77-F68FAC2F537E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85B0D0F1-A5E5-4225-91A2-6AE76820489D} - System32\Tasks\{B1D3638D-7AC5-4FDE-B0B3-8646717611E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85B242CA-8635-4CE5-8A89-BC0B930AFB26} - System32\Tasks\{3438563C-BDA2-4240-86FE-C250087D876B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {860D5616-C807-42E4-9471-34492936869C} - System32\Tasks\{0C52ACFB-76D7-4572-AC1F-5C817BC6F9B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {89C98CDB-86B4-4B1E-83FE-3BFDA3BBA61B} - System32\Tasks\{85CA7BEC-BAC3-4039-951D-6DD6897DA82A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8BDBE9D0-F1E1-4282-8D2C-595C2EB28B92} - System32\Tasks\{82A89D01-11E0-4CC3-80AE-23A6B6E0FC61} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8CB35F7E-5585-4B14-8711-11D6FAC29378} - System32\Tasks\{D2A2BD67-9A7E-4D6F-BE2C-6A8B2D0F1BA1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8D8F82B8-57B8-4BFE-A952-D123EFC13ECC} - System32\Tasks\{203C25BA-F232-4421-B3DA-A376B3774516} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8D97D69A-AD7F-493C-8DCC-7CB007C6A8F2} - System32\Tasks\{9C7168A6-031A-469A-AA01-62138FAD5C64} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8DF97B81-3559-47F4-9420-360B447E1FD0} - System32\Tasks\{FECF6647-C213-4C31-93D8-DA36CEF2D2E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8E04509E-7AFC-454D-841A-708BB706F7DC} - System32\Tasks\{3E9663A7-8201-4FF2-B1EB-833DE8AD30E6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8FA91399-CE12-4FBD-A967-DFD7D9109D84} - System32\Tasks\{9D64689E-0BD4-4A36-BD88-4A0E50CDC83F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {903E2695-1203-484C-B1FB-D551272A2574} - System32\Tasks\{8DB1831F-D69A-4DDE-831A-FAA560851E70} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {904FCA34-E617-4024-8059-1269ADC0C47F} - System32\Tasks\{4C21C9AE-2772-474A-A218-F693E2CF602B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {931B5588-6B96-408B-B873-41412BFE2B8E} - System32\Tasks\{C7652E09-4AA0-4B7F-94CB-751180B2AC84} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {9879350E-87CA-40F0-964A-DFC97AB3BC30} - System32\Tasks\{41A7B7D7-A9E8-4FDD-AB09-12810CB9DE9C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {98AF9170-2913-4F80-95D2-95B7477DE797} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-17] (Adobe Systems Incorporated)
Task: {9974FA93-556E-4FDD-ABA7-D41F1D4176D6} - System32\Tasks\{0BE877C9-7403-4859-BB65-3F99D03088A8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9ADA0808-016F-4483-B32E-F4712A3C1511} - System32\Tasks\{31210AE0-BEE0-48B0-AD32-F3DFF7AF8585} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {9B469F57-8F99-42A1-8801-E8E97EC4CDD1} - System32\Tasks\{F66DE0CE-872C-44E9-AD32-7E45842B895C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9BA28B79-CD14-416E-9A76-1B33558AAB10} - System32\Tasks\{AB2ECB65-FA3E-40E1-A023-0E8D5E03A224} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DBF7F80-5E83-4F91-91D2-32FA850EF84F} - System32\Tasks\{3CCABE20-2386-4504-81C4-4235BAAC31B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DFAF053-ECF1-4951-B8B9-D566381CF17E} - System32\Tasks\{12CBB338-12C1-4249-84A2-07241A16A2D6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9E7E9471-FE25-4DB0-99FC-8E598F78A02E} - System32\Tasks\{DE3AD989-7BFD-4AD9-8EDC-6F505EB64364} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A1B61844-B80C-4D9A-94F1-4645C98FC2B8} - System32\Tasks\{75FCFCA1-F6E7-4195-8FDB-205A363174BD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A212F777-60F2-4D21-AE31-7D8EDE725661} - System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/abandoninstall?page=tsMain
Task: {A2ED97D9-08BE-45A0-8F5E-DF79EE68E5EA} - System32\Tasks\{E792460F-EDFC-488E-8731-0BBFB1110EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A6B88D73-C7CC-4AC8-9868-003E3D1A6117} - System32\Tasks\{123ECB18-D866-4EAF-A87C-2B532824BBFF} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A88B4C8C-9BCA-4F56-B093-7BB101C93929} - System32\Tasks\{88F50087-6CF7-4A6A-B06F-AD288A88A6DA} => E:\AutoRun.exe
Task: {A97D22B7-423F-439C-9A10-3C6091CA5D1A} - System32\Tasks\{1BFCBFF7-66FB-4E87-81A8-FB7CF75207DE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {AA445193-1181-4478-AEF2-B0ED5C6C2E97} - System32\Tasks\{2FFB54D9-0F45-4439-A0AB-B2246A92D499} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ACFC14E5-8848-4358-90F5-8817059D3A5E} - System32\Tasks\{537B3161-6C44-4CA2-94A2-5BDB3B8C8D3E} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe
Task: {ADC16C61-80CB-4175-BEB7-3723F4552311} - System32\Tasks\{65BF13AD-A284-4838-9987-577314060DB0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ADCB1719-67BA-4895-9D04-8A1A0C26DEB7} - System32\Tasks\{697D2AB0-4D70-40B2-BA95-E58EF151514D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {AE410752-87F2-492D-9D1A-6D81D53BAF55} - System32\Tasks\{20EE37CD-2303-4DD3-97A5-61226D364CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B01A395C-1E4E-4257-A8F2-51DC50233552} - System32\Tasks\{A772563F-BDDC-463B-99F1-C77841420332} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B1CD2103-56BA-4745-9177-223FFDD53ADC} - System32\Tasks\{470BF604-D7FC-467D-A26E-CF0F03148BEC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B26A8951-5FE0-4FB7-873E-A0D132A2025F} - System32\Tasks\{98160B25-2EF3-494D-855C-85407974E878} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {B39BD072-35FE-4CC5-A530-A8909B6872D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.)
Task: {B408996C-AB90-4D16-848B-E5C3A70821D8} - System32\Tasks\{667B8D52-5E64-4C4A-9884-01C81DCCA5A8} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {B40A4AAC-C52E-47C0-8860-D0D8CFBF36B3} - System32\Tasks\{8528129B-330F-4FB9-BD05-0B63A185738C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B46D754A-55E2-4756-BC53-3885E70D6472} - System32\Tasks\{A379F55A-1CF2-4571-AACC-0F2431A98E00} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B5F85DB4-3143-4086-91FA-2D4D1E3681FC} - System32\Tasks\{73E77971-0011-4D43-AD03-9117C0D1EFDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B6A0B547-231E-4DD7-90D8-4EED1969E049} - System32\Tasks\{51ABC066-D83B-4170-8165-07805CC167F0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B6BFFAAD-9659-42EF-AA02-57D301DBA5A3} - System32\Tasks\{6C2FFB99-7192-428B-B38C-1D8F0B6F7FC6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {BA9030C6-4777-4D8C-AB61-76025BFA120F} - System32\Tasks\{313997D6-C748-4720-826F-E7E9A6BC21CC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {BCFF6A0A-67BC-421B-A03C-20012560E161} - System32\Tasks\{7AB46240-BDE2-4A4F-919C-21CFD95DEB91} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {BD78545A-B9EB-4AF6-AE31-BDA236D2BAE8} - System32\Tasks\{B315BDCA-1064-453A-A6CC-C79F19F7D016} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C0FF2097-FA54-4970-ABCC-D3C6970BDB8F} - System32\Tasks\{909D4AED-895C-4B2A-96DD-6CA6D80B3960} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {C1130E74-46A9-4A07-855A-CDF608DEBBF8} - System32\Tasks\{83AAA377-4550-4890-81AB-EABAA6D54F2F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C1992231-5AD6-4DEB-9429-A822E9B6459F} - System32\Tasks\{73E2DA90-10C9-4FEB-8303-D06CFBA64319} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C2180CA4-8AED-48C7-A2E9-F6AE7C2EA254} - System32\Tasks\{68575AA0-FDE2-4EFD-9481-ECADE3C34DA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C4CD2A1C-B81A-4DF8-A06D-66F8EE0C9E08} - System32\Tasks\{4954985C-7557-42F2-9DA3-44DAB4B574EA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C6B28C1E-EB4C-49E1-9C0B-AB8E2704CBA2} - System32\Tasks\{F92A9599-40B3-4A4D-AC6B-DB14C925E677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C70B179E-12FD-4FA2-9ADF-F9B845F76EBE} - System32\Tasks\{7B61AC9C-9B02-4800-95D6-DC4C2193ECA4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C956224D-737E-44AC-A135-B8A291573F99} - System32\Tasks\{C5CECD65-EFFE-4679-8ED8-9083413AF641} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C9C1E1CF-9F4F-4893-8DF5-FFD570756159} - System32\Tasks\{1F69CD65-61D9-472C-95EE-8793CAB2098E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CD835294-0684-4E85-93D7-57FA3413500A} - System32\Tasks\{7AD6CBE5-95F9-4616-B6CE-1FBF3ACBB0D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CD878935-40AC-4D8D-8C98-045CA41BB390} - System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618
Task: {CDAC83D4-811F-4165-8722-856EAE3449B3} - System32\Tasks\{E0B10180-47E9-4AB1-9FE0-6C44B2EF97A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CE724C0F-EA35-4437-9D30-1113211B6A09} - System32\Tasks\{4C940F41-C0B3-4969-884C-E442672E162D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CF2606A0-ACA7-45F9-AD40-268630067DC0} - System32\Tasks\{96124692-6A3C-4996-8C1C-D5A23375B7EE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D21F7BE1-05EB-44B3-BAA5-9BCD4AE31875} - System32\Tasks\{901FF9AA-59B7-48DE-82FE-581B7F599280} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D264BCEC-BABB-4C67-AB5E-F518C830438A} - System32\Tasks\{F600C80E-888F-4E6B-9B51-FEB3021CC358} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D360F099-830B-49E3-8626-6FA307F5DDE8} - System32\Tasks\{BC56BB0E-CC7A-4E3C-BAA7-76686DE08AC6} => C:\Program Files (x86)\il-2 sturmovik cliffs of dover\Launcher.exe [2011-04-03] (1C:SoftClub)
Task: {D4A58010-4058-414F-B75C-F534647CCADE} - System32\Tasks\{60083AE6-8669-4F76-A8C9-EC5394929A9B} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {D652DAE9-1CF0-45B1-BB5B-73CBD75E3D7A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {D71B37E9-5FF9-4CDC-8C10-90DBE9D9D2C7} - System32\Tasks\{A08D600B-BB0B-4BB7-B7E5-EFA9DBA72624} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D84CF91D-4A8A-4C38-8808-78F24EEA7D00} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {D92C729A-F461-430D-9536-06B0A6EEF5D5} - System32\Tasks\Opera scheduled Autoupdate 1401931354 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software)
Task: {D934BBFE-2B1B-462F-B25C-A7FC1696106C} - System32\Tasks\{B83314D1-CE37-47EB-93D3-5F69CE06C9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DA5E0905-D48D-4F65-A292-DCE54E3DF4DE} - System32\Tasks\{48B23608-CF81-40DF-866F-E9149F931791} => C:\Program Files (x86)\English Bid for Power Final 4.0\EBFPF 4.0.exe
Task: {DCB6E2F6-56D1-4247-8394-3366B53DBE91} - System32\Tasks\{D0C97849-AFD1-450D-A83D-E2ABAF26C11D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DD54C13C-6AA2-45C9-98FB-4F3C4F706776} - System32\Tasks\{D636E579-ECC1-48E6-8D34-0898C8B8AB88} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DF3520E2-5C0C-45C7-9E29-C0A3CF6624CD} - System32\Tasks\{F9064DAF-E8C8-42B4-872B-CF84AEB8A5A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DFDC1780-CB4B-49C6-9D0C-6A307018E041} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {E06029EB-0DB6-46F4-8D96-010660E515F6} - System32\Tasks\{6D9D7339-3B94-4B93-A4D6-B3152EBECD01} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E069F814-CBF7-4E4F-9793-7A842132DBBA} - System32\Tasks\{373EABBD-53C5-4E40-898F-4C5069D8A499} => C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe [2009-06-28] (Sony DADC Austria AG)
Task: {E13EACA4-DC9F-4ADC-9A68-67B64DFE23B6} - System32\Tasks\{DEF987AD-81AC-42EB-B412-5A8403716DDA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E1C1E3A3-A460-421D-A2A3-CD52241FD7D5} - System32\Tasks\{C0F296D8-C7D3-40E7-BE16-E643CDDEC0BC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E2191329-4BE6-4CFE-A6D1-734AF9A17EFA} - System32\Tasks\{3BA18019-EAF4-452D-A4A2-3E20F326FC0D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E3C57322-4D59-48CE-9D42-CC0D884733F7} - System32\Tasks\{BA768B60-C681-4E86-B54D-B818BB13C841} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E44DAC2B-B71A-4537-A501-996802E1A023} - System32\Tasks\{03B26415-BC1D-4284-9D4A-A178EB9B3EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E4508BB6-1429-49BD-BCBA-083AAA7E5AA8} - System32\Tasks\{BC238E47-DE85-42C8-A42A-5CAEAE4649FB} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {E4FA1C11-710B-467C-8C5B-869390DF8A61} - System32\Tasks\{699BB15C-2884-457A-BA98-A4B8698C652A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E6A13448-9338-473B-BAA0-23B9F616B6D0} - System32\Tasks\{775735C3-BC90-4F41-82D2-6C5EE14FD15A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E712900C-C47E-492D-BF1A-DE095C31D309} - System32\Tasks\{3A9C2093-CDC6-4117-A344-E59636C8D654} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E92D78D6-0882-4D25-8296-F91672232EC3} - System32\Tasks\{0B804F92-4E06-4F0B-8398-FBFF1770A638} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EAD179B7-8EFB-4C37-A13B-DAA71D740E0D} - System32\Tasks\{CEDABE9A-9564-465A-B4B1-1257AC1B2C43} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION
Task: {ED37749E-137A-4F1C-9FD0-3DCF709567E5} - System32\Tasks\{A4B072C7-A2B2-4870-8C3F-6B6324B02FBB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EF1BD8C8-A15F-4BC6-AD60-672E42A93C49} - System32\Tasks\{A6450515-09C9-444A-B374-6304A0A11E67} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EFC87779-05F4-4C10-8880-71EAEBE1391F} - System32\Tasks\{8A126FB2-9DF1-40B6-BF29-94BC77C74FAB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F0108CE8-B277-4C4D-BEB9-83F45F46F170} - System32\Tasks\{6E35942B-EC74-4C6C-8ECD-5787FEE77389} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {F11AE687-5F0D-4509-9E7D-904D61C5BA98} - System32\Tasks\{177FAF9C-8814-4261-A21C-CA7506F2B82F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F28B5784-80AB-4325-8C31-358E7215BB3C} - System32\Tasks\{6F04151D-6AB6-4AD1-AD9E-5AE5BB416094} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F62B21A2-FAEC-44BA-93B9-C1AE49234444} - System32\Tasks\{11514906-B372-4DBD-B566-488DF1E6F029} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {F800F910-22FD-49C7-938B-A6C0AD765100} - System32\Tasks\{88CE8631-1046-44CF-88EE-4849D81EE9E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F875476F-7142-4F9D-812C-13343492E7A1} - System32\Tasks\{D9DFF9E6-6D3B-4AE0-9D39-D0AC25C7B9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F89D7FAD-847B-495E-B7A9-1102853A0B96} - System32\Tasks\{B518FFEB-D63F-452B-82E4-F45EF890BC97} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {F8E344A2-D4C9-4CE7-98BB-521D2CA6A434} - System32\Tasks\{D691C721-D450-4C82-B4C4-495A1B64DBD3} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {F91D746E-4CF8-41DE-83CB-31432B4543D9} - System32\Tasks\{DCEAF480-641F-4ACD-A325-BDBA0CCC540B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FA2B38D9-60DC-455F-BB4A-D4810EB33769} - System32\Tasks\{0A9C2DB2-D33D-4DE9-A45C-528B8C1AEE1B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FA31A522-796E-426B-848D-E9077313AD8A} - System32\Tasks\{A0DA316A-D472-444F-A426-D6D46912C19F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FBFCFB6D-C9AD-4075-A58D-ADD617EF8D2B} - System32\Tasks\{45962B83-FB74-456E-BE05-674FB7E57069} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FCE91E30-A0CA-4991-A909-F7CF995FB676} - System32\Tasks\{B8DE84ED-80C7-4218-A29E-5B4B9E36DDAA} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe
Task: {FE3ECFB4-5ADB-4B7C-92C9-E7F27D53C159} - System32\Tasks\{08AF28EA-188F-4A3C-AA80-C8A5DC185025} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-10-26 03:31 - 2013-08-18 21:34 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-10-12 04:11 - 2013-10-12 04:11 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2010-05-02 11:53 - 2010-05-02 11:53 - 02937528 _____ () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
2010-05-02 01:13 - 2009-05-07 16:51 - 00071680 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2010-05-02 01:13 - 2009-05-07 16:53 - 00379392 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2010-05-02 01:13 - 2008-01-18 14:50 - 00098816 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll
2010-05-02 01:13 - 2009-07-10 10:48 - 47601664 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\VERSION.dll
2014-06-10 11:51 - 2014-06-10 11:51 - 02775040 _____ () C:\Program Files\AVAST Software\Avast\defs\14061001\algo.dll
2011-09-27 08:23 - 2011-09-27 08:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 08:22 - 2011-09-27 08:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-06-05 06:14 - 2014-06-05 06:14 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\version.DLL
2014-06-10 12:53 - 2014-06-10 12:53 - 00043008 _____ () c:\users\sven\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4f7lre.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Sven\AppData\Roaming\Dropbox\bin\libcef.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00877176 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libglesv2.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libegl.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk => C:\Windows\pss\GamersFirst LIVE!.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Rainmeter.lnk => C:\Windows\pss\Rainmeter.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^regsvr43.lnk => C:\Windows\pss\regsvr43.lnk.Startup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: Facebook Update => "C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent

==================== Faulty Device Manager Devices =============

Name: SbieDrv
Description: SbieDrv
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SbieDrv
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/10/2014 11:08:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: adwcleaner_3.212.exe, Version: 3.2.1.2, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: adwcleaner_3.212.exe, Version: 3.2.1.2, Zeitstempel: 0x4f25baec
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000111c9
ID des fehlerhaften Prozesses: 0x13c8
Startzeit der fehlerhaften Anwendung: 0xadwcleaner_3.212.exe0
Pfad der fehlerhaften Anwendung: adwcleaner_3.212.exe1
Pfad des fehlerhaften Moduls: adwcleaner_3.212.exe2
Berichtskennung: adwcleaner_3.212.exe3

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (06/10/2014 00:53:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/10/2014 00:53:30 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/10/2014 00:31:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (06/10/2014 00:30:50 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/10/2014 00:22:23 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:22 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:20 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 11:50:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2


Microsoft Office Sessions:
=========================
Error: (06/10/2014 11:08:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: adwcleaner_3.212.exe3.2.1.24f25baecadwcleaner_3.212.exe3.2.1.24f25baecc0000005000111c913c801cf848aa06ca209C:\Users\Sven\Downloads\adwcleaner_3.212.exeC:\Users\Sven\Downloads\adwcleaner_3.212.exec8693396-f07e-11e3-95c1-002618bca0f6

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


CodeIntegrity Errors:
===================================
  Date: 2014-06-10 12:57:09.216
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:57:08.175
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:57:07.156
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:57:05.415
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:53:30.820
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-10 12:53:30.414
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-10 12:39:35.652
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:39:34.877
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:30:50.021
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-10 12:30:49.693
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 56%
Total physical RAM: 4095.18 MB
Available physical RAM: 1766.4 MB
Total Pagefile: 8188.54 MB
Available Pagefile: 5871.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:229.38 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3AC77A71)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

==================== End Of Log ============================

hab nichts gesehen :abklatsch:

M-K-D-B 10.06.2014 12:05

Zitat:

Zitat von Goodfell (Beitrag 1313648)
hab nichts gesehen :abklatsch:

ok :)


bevor es weitergeht, habe ich eine Frage:

Zitat:

FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
Hast du diesen Proxy-Server in firefox gesetzt?

Goodfell 10.06.2014 12:07

Zitat:

Zitat von M-K-D-B (Beitrag 1313650)
ok :)


bevor es weitergeht, habe ich eine Frage:


Hast du diesen Proxy-Server in firefox gesetzt?

Nein habe ich nicht.. benutze Firefox schon länger nicht mehr, weil sich mit ihm keine websiten mehr laden lassen.

M-K-D-B 10.06.2014 12:14

Zitat:

Zitat von Goodfell (Beitrag 1313651)
Nein habe ich nicht.. benutze Firefox schon länger nicht mehr

Dachte ich mir... dann geht es so weiter:





Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 3 h) dauern.
Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg.




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:

start
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
C:\Windows\System32\DlProtectSvc.exe
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION
Reboot:
end


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Schritt 2
Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:

    :folderfind
    *PSHD-9.9*

    :regfind
    PSHD-9.9

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.







Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset







Schritt 4
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von FRST,
  • die Logdatei von SystemLook,
  • die Logdatei von ESET,
  • die Logdatei von SecurityCheck.

Goodfell 10.06.2014 12:25

Code:


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-06-2014 01
Ran by Sven at 2014-06-10 13:18:36 Run:1
Running from C:\Users\Sven\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
C:\Windows\System32\DlProtectSvc.exe
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION
Reboot:
end
*****************

DlProtectSvc => Service deleted successfully.
C:\Windows\System32\DlProtectSvc.exe => Moved successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NextSTART => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Workshelf => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => value deleted successfully.
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Upgrade => value deleted successfully.
C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F} => Moved successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19} => Value not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} => Moved successfully.
KMService => Service deleted successfully.
Winstep Xtreme Service => Service stopped successfully.
Winstep Xtreme Service => Service deleted successfully.
X6va003 => Service deleted successfully.
X6va011 => Service deleted successfully.
X6va012 => Service deleted successfully.
C:\Users\Sven\AppData\Roaming\CamLayout.ini => Moved successfully.
C:\Users\Sven\AppData\Roaming\CamShapes.ini => Moved successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15CC64F6-C57C-4E1B-B266-D0FAEB366850}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15CC64F6-C57C-4E1B-B266-D0FAEB366850}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3AAFDACA-05D8-49D7-A834-1DBEB4447E00}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AAFDACA-05D8-49D7-A834-1DBEB4447E00}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\41220790-4b35-4753-91f3-94289344bd48-3' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5BF5E050-9C81-448E-B218-B99FBEE1D85B}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BF5E050-9C81-448E-B218-B99FBEE1D85B}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB6B115F-67DB-4599-B4F8-8766B8ED346F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB6B115F-67DB-4599-B4F8-8766B8ED346F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\41220790-4b35-4753-91f3-94289344bd48-5' => Key deleted successfully.


The system needed a reboot.

==== End of Fixlog ====


Also haben wir es bald ja geschafft, danke dir für deine Geduld und Hilfe nochmals :)

M-K-D-B 10.06.2014 12:26

Gut gemacht. :)


Immer weiter, eins nach dem anderen.

Goodfell 10.06.2014 12:35

Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 13:27 on 10/06/2014 by Sven
Administrator - Elevation successful

========== folderfind ==========

Searching for "*PSHD-9.9*"
No folders found.

========== regfind ==========

Searching for "PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19E6B430-8939-486D-A9B4-C81AB83A54B0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{204114BF-9D1E-4F5C-95A2-5D7FC75C5553}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{225A1E1C-39C6-4FEA-807B-65C050E34218}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2522F635-E0DA-40E7-80E0-1957BDFF1224}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28E606E4-13F1-45BF-80DA-AE5153B162AD}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2937F19F-FBEA-46E1-A843-3194414595}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{295B128F-80B8-4C89-A9E2-419A42803738}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B5C22CF-8368-4D4F-8CA9-E17917EC9EF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34C62A0B-9CE6-4130-8361-AA4A7FE5F3}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354CFB61-739B-4CCD-9D14-23224A32A4AE}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD62C28-6327-47C0-BB18-974F2A5BD248}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41536BE9-239A-4B2D-A82C-88DB5AA6C192}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43773D51-CA30-48E7-A36-4F322D8DBEA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{460211B7-E7FA-430C-8C33-1698A338DF50}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56ABEB18-6BD3-496D-96E9-7938C3BB3D6B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56CE1A96-624-42A0-9BEC-144E78DB565F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{57D55C1E-BEDE-4058-992B-9B6543F1BE7}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E5132D9-76B3-4080-91A9-59D1AD1E7448}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61FD3EAB-F4A7-4B49-A44E-84CA4BC2DA8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6278C536-F890-4B7E-A242-19F4CCA9D9C9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645607EE-466D-40C4-901A-B65848C4EFD5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65D2E6F9-1396-4430-93EC-9BFF6107156}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A200C98-6B0A-4715-ADDD-3E241B5E201D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAAA66-D001-4031-8358-16BFBCDA154}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4D2BE9-46C2-424E-B00-96E2CFB71D49}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3CBD17-1AD5-4CE7-B721-E2376EBCE732}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{718E603-1AAC-40E9-8915-24E69CC6778E}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{720A7F6C-4CB0-4225-AE1E-D4FC62BE3355}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75AA3E2D-E831-4A39-8F68-33133DE982C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78020622-6B73-4B60-816C-85CBDE4232A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7840DA43-E56D-47D9-96D3-C37DB97F2E2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79C744DB-1C9B-4DBC-B3BD-E8A5A5C8BEE5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F516459-6056-4106-A3E2-6715AE811D65}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{924E1C60-F131-4EED-8FD2-247BBC4568D8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93500650-CFBE-4ECE-AC59-7138B4EC79E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{950588AC-4F98-4479-89A4-7813AF1D477D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95CCA599-BDB3-4909-AAAD-372958F767A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CBE1CD3-99B-4E61-BE25-A7111D511A6D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB3D095-A184-44BE-8B28-47582431D2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F8CE472-726E-4126-B3A7-8E1932E3183}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2BFADEF-2DD0-45B2-9C33-C5311158FF9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4384461-4B10-4BD8-B6CC-CCE6DF618E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5039154-BAB-4409-9AA8-B45E6981EA11}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88AC80E-1AD4-4C4E-90D9-2F76678F1DF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A984BA40-EB90-455E-A61A-5C865AC25E7D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC476297-55E3-43EF-8DE2-B3EB1E41D02}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF4CAA4C-4EE1-4C8C-A784-16CACE8494F6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3406F8A-99CD-48E9-B82A-A22B44565E0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B787AF2A-EB75-402D-8E66-C0A33BABD89F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA89C16-B97D-4DD8-8B24-D47F167712B2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1609283-FD8A-4317-B9DE-4ECC199E24F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ED9D17-6923-4087-99B3-C7D261D99E71}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FC765B-13EE-4B5E-B540-E3A472461532}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C576D330-6FE0-4695-9778-D04A32E35C3D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C80C0F4-D216-4B33-A058-604AD982A773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D099CE66-920D-4D91-8BAB-ED3C3D3342E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D249689B-4959-496F-B97C-4E59F88688C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BAF6EC-C708-4C00-A9A4-90F23BAC8AFB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB3DC33D-829D-404E-81F6-05C99BED2D2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD22B052-D0F2-4C8F-87F4-3C1E52D82CB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD282AA7-652B-41CB-91A1-57F0A1477865}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE94E69-980A-4CC4-B8A-F2738BA2AE4C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E58E90C6-ED93-4E5E-95F-B82224899C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7808D13-3A9D-4531-B3A4-C57D5C889773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E84EB0FA-DDEF-47D3-8AB4-1EB8804ED159}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA1E5BDE-F92B-46B7-8683-2E192D126CA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC1B7EA3-73C0-4C83-A944-2BE27ADC0DB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEFD29F8-7061-4EDC-A723-5D302AADFD4A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF4840EB-E2A7-4F36-B635-5361678D4A4}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFBF6720-F576-4C15-A829-83B9E4E66199}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA150BE7-B443-434A-9184-C8497414A257}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB009888-631A-4BD0-BBBF-B73AA1E42C5D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19E6B430-8939-486D-A9B4-C81AB83A54B0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{204114BF-9D1E-4F5C-95A2-5D7FC75C5553}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{225A1E1C-39C6-4FEA-807B-65C050E34218}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2522F635-E0DA-40E7-80E0-1957BDFF1224}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28E606E4-13F1-45BF-80DA-AE5153B162AD}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2937F19F-FBEA-46E1-A843-3194414595}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{295B128F-80B8-4C89-A9E2-419A42803738}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B5C22CF-8368-4D4F-8CA9-E17917EC9EF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34C62A0B-9CE6-4130-8361-AA4A7FE5F3}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354CFB61-739B-4CCD-9D14-23224A32A4AE}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD62C28-6327-47C0-BB18-974F2A5BD248}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41536BE9-239A-4B2D-A82C-88DB5AA6C192}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43773D51-CA30-48E7-A36-4F322D8DBEA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{460211B7-E7FA-430C-8C33-1698A338DF50}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56ABEB18-6BD3-496D-96E9-7938C3BB3D6B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56CE1A96-624-42A0-9BEC-144E78DB565F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{57D55C1E-BEDE-4058-992B-9B6543F1BE7}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E5132D9-76B3-4080-91A9-59D1AD1E7448}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61FD3EAB-F4A7-4B49-A44E-84CA4BC2DA8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6278C536-F890-4B7E-A242-19F4CCA9D9C9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645607EE-466D-40C4-901A-B65848C4EFD5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65D2E6F9-1396-4430-93EC-9BFF6107156}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A200C98-6B0A-4715-ADDD-3E241B5E201D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAAA66-D001-4031-8358-16BFBCDA154}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4D2BE9-46C2-424E-B00-96E2CFB71D49}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3CBD17-1AD5-4CE7-B721-E2376EBCE732}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{718E603-1AAC-40E9-8915-24E69CC6778E}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{720A7F6C-4CB0-4225-AE1E-D4FC62BE3355}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75AA3E2D-E831-4A39-8F68-33133DE982C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78020622-6B73-4B60-816C-85CBDE4232A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7840DA43-E56D-47D9-96D3-C37DB97F2E2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79C744DB-1C9B-4DBC-B3BD-E8A5A5C8BEE5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F516459-6056-4106-A3E2-6715AE811D65}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{924E1C60-F131-4EED-8FD2-247BBC4568D8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93500650-CFBE-4ECE-AC59-7138B4EC79E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{950588AC-4F98-4479-89A4-7813AF1D477D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95CCA599-BDB3-4909-AAAD-372958F767A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CBE1CD3-99B-4E61-BE25-A7111D511A6D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB3D095-A184-44BE-8B28-47582431D2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F8CE472-726E-4126-B3A7-8E1932E3183}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2BFADEF-2DD0-45B2-9C33-C5311158FF9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4384461-4B10-4BD8-B6CC-CCE6DF618E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5039154-BAB-4409-9AA8-B45E6981EA11}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88AC80E-1AD4-4C4E-90D9-2F76678F1DF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A984BA40-EB90-455E-A61A-5C865AC25E7D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC476297-55E3-43EF-8DE2-B3EB1E41D02}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF4CAA4C-4EE1-4C8C-A784-16CACE8494F6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3406F8A-99CD-48E9-B82A-A22B44565E0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B787AF2A-EB75-402D-8E66-C0A33BABD89F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA89C16-B97D-4DD8-8B24-D47F167712B2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1609283-FD8A-4317-B9DE-4ECC199E24F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ED9D17-6923-4087-99B3-C7D261D99E71}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FC765B-13EE-4B5E-B540-E3A472461532}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C576D330-6FE0-4695-9778-D04A32E35C3D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C80C0F4-D216-4B33-A058-604AD982A773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D099CE66-920D-4D91-8BAB-ED3C3D3342E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D249689B-4959-496F-B97C-4E59F88688C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BAF6EC-C708-4C00-A9A4-90F23BAC8AFB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB3DC33D-829D-404E-81F6-05C99BED2D2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD22B052-D0F2-4C8F-87F4-3C1E52D82CB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD282AA7-652B-41CB-91A1-57F0A1477865}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE94E69-980A-4CC4-B8A-F2738BA2AE4C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E58E90C6-ED93-4E5E-95F-B82224899C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7808D13-3A9D-4531-B3A4-C57D5C889773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E84EB0FA-DDEF-47D3-8AB4-1EB8804ED159}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA1E5BDE-F92B-46B7-8683-2E192D126CA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC1B7EA3-73C0-4C83-A944-2BE27ADC0DB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEFD29F8-7061-4EDC-A723-5D302AADFD4A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF4840EB-E2A7-4F36-B635-5361678D4A4}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFBF6720-F576-4C15-A829-83B9E4E66199}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA150BE7-B443-434A-9184-C8497414A257}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB009888-631A-4BD0-BBBF-B73AA1E42C5D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]

-= EOF =-


M-K-D-B 10.06.2014 13:37

Gut, fehlen nur noch 2 Schritte.

Goodfell 10.06.2014 13:57

Liste der Anhänge anzeigen (Anzahl: 1)
Ja bin gerade dabei, ESET läuft. :pfeiff:

Goodfell 10.06.2014 20:22

puuh. das hat gedauert.

Hier das Ergebniss:


Code:


ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=d65e174207ca9a4e94d1c9514011f35b
# engine=18648
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-06-10 05:45:13
# local_time=2014-06-10 07:45:13 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=782 16777213 100 95 480293 480758 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 26126 154052163 0 0
# scanned=1073483
# found=44
# cleaned=0
# scan_time=21829
sh=34622C0C9B0F72AB2F67AE3BD7CF94EF76B2B54D ft=1 fh=422f90d5b5335443 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Delta\delta\1.8.24.6\deltaApp.dll.vir"
sh=80C8F13A1918FAEEAB9673C1CCF96E52325EE695 ft=1 fh=0aefb751d92be997 vn="möglicherweise Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Delta\delta\1.8.24.6\deltaEng.dll.vir"
sh=4400797578E17E511E6164469770A80E828DDA3A ft=1 fh=56dbbea16253a143 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Delta\delta\1.8.24.6\deltasrv.exe.vir"
sh=610CDC3A03DA21A83EB90193BACF1347AAA39A0F ft=1 fh=6544723ffe1f3f66 vn="Variante von Win32/Toolbar.Montiera.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Delta\delta\1.8.24.6\deltaTlbr.dll.vir"
sh=AFD5B25F86CFD3045CCFF940A249A1DA89DEDE5D ft=1 fh=c55a3c08e5709f9a vn="Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Delta\delta\1.8.24.6\uninstall.exe.vir"
sh=66AE7973E507FF0471DECFFF3BF7FFD40EA4D00D ft=1 fh=1b697967a44eb4e0 vn="Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Delta\delta\1.8.24.6\bh\delta.dll.vir"
sh=2900BFFDB9BA25B5F8B0C5DB9B3FBF2584630BD8 ft=1 fh=13f46184ac52d101 vn="Variante von Win32/BrowseFox.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\raving reyven\ravingreyvenBHO.dll.vir"
sh=BC7F5A4FDB3AABC310EE7335EBDCF93718D7892D ft=1 fh=dd8bcf7fac821ec8 vn="Win32/BrowseFox.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\raving reyven\ravingreyvenUninstall.exe.vir"
sh=246DDBC3A2C223A6B9072637D93DC2A2832D097A ft=1 fh=c71c0011b04f613a vn="Win32/Toolbar.Babylon.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir"
sh=410A648EB8392D7407D264CF6C1090D044D044D6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.52_0\extensionData\plugins\266.js.vir"
sh=B563BEC7EC0608AB8EBC51C5E228C9270DAC0A09 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.52_0\extensionData\plugins\91.js.vir"
sh=1549CF4F9282F1B42A58B5E050E12EF0AD669798 ft=1 fh=ffe6693d8bc7d6c5 vn="Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir"
sh=410A648EB8392D7407D264CF6C1090D044D044D6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\a54e453c-130a-4769-9333-c5ec2aa914c5@9bd7cc89-9c7c-44e9-a03b-042b92d363f0.com\extensionData\plugins\266.js.vir"
sh=B563BEC7EC0608AB8EBC51C5E228C9270DAC0A09 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\a54e453c-130a-4769-9333-c5ec2aa914c5@9bd7cc89-9c7c-44e9-a03b-042b92d363f0.com\extensionData\plugins\91.js.vir"
sh=C6856C32ECEF81A37AFEE5929F0AF5CBB7F4029C ft=1 fh=1edb99ab84c070e7 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\OpenCandy\047B6AD5218541D8887FB63F787F45A7\Installer.exe.vir"
sh=C4420C6E94B8CAACCB3811384280D8A93CB0A37D ft=1 fh=25f111c507a31a21 vn="Win32/Toolbar.Conduit.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\OpenCandy\9704D4A78C99416F8C1A80799D37D167\sp-downloader.exe.vir"
sh=829D808C091045F45C513A6E4AB17055A52A9320 ft=1 fh=282fb76e1825b814 vn="Variante von Win32/Toolbar.Babylon.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\OpenCandy\CF0345E8436546F3A1A4EF36E3BD3BD5\DeltaTB.exe.vir"
sh=829D808C091045F45C513A6E4AB17055A52A9320 ft=1 fh=282fb76e1825b814 vn="Variante von Win32/Toolbar.Babylon.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Sven\AppData\Roaming\OpenCandy\D07680A3D8C647DB910A520A76BF62FE\DeltaTB.exe.vir"
sh=DE1BAF2B3031DDBD4A49E25A98146255826050DD ft=1 fh=757c80b16141ae2a vn="Variante von Win64/Agent.BR Trojaner" ac=I fn="C:\FRST\Quarantine\C\Windows\System32\DlProtectSvc.exe.xBAD"
sh=21C23C470BDABB763D2FC372D86E9D3FB9F923AE ft=1 fh=1a43b0206fc57ad6 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="C:\Program Files (x86)\Codemasters\DiRT 3\paul.dll"
sh=5B31FB5741304E8486ACFD81E30B314B87A28E9F ft=1 fh=b4b60b69ec22cbd1 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="C:\Program Files (x86)\Codemasters\DiRT 3\SKIDROW.dll"
sh=21C23C470BDABB763D2FC372D86E9D3FB9F923AE ft=1 fh=1a43b0206fc57ad6 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="C:\Program Files (x86)\Codemasters\DiRT 3\SKIDROW\paul.dll"
sh=5B31FB5741304E8486ACFD81E30B314B87A28E9F ft=1 fh=b4b60b69ec22cbd1 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="C:\Program Files (x86)\Codemasters\DiRT 3\SKIDROW\SKIDROW.dll"
sh=125B9DE3FAAD6CF9EE69248A68BA8985F4FFF7A3 ft=1 fh=ed34fb4d2d3beb95 vn="Variante von Win32/Packed.VMProtect.AAD Trojaner" ac=I fn="C:\Program Files (x86)\EA\Bulletstorm\Binaries\Win32\xlive.dll"
sh=6009080E755AC30EB0ADFEBB4D333D531A6E64AE ft=1 fh=5cf9708d1424091a vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\FIFA 13\FIFA.13.Update.v1.7.MULTI5.exe"
sh=A32AA942597786B380ABDA361918B5E6BF4F26D1 ft=1 fh=e10233d53431d7f2 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\FIFA 13\Game\rld.dll"
sh=38E88012B276963FABD68B69A9FDBAE98EF98B0B ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2014\Pro.Evolution.Soccer.2014.Update.v1.01-RELOADED (1).rar"
sh=26A4D8D46950F6A36CE4C678DC1BA36F63980EAB ft=1 fh=5b1a47320b91d0bf vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2014\rld.dll"
sh=26A4D8D46950F6A36CE4C678DC1BA36F63980EAB ft=1 fh=5b1a47320b91d0bf vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="C:\Program Files (x86)\KONAMI\Pro Evolution Soccer 2014\Crack\rld.dll"
sh=3F129A11DB1B7E30E5C5F87EBEE81DB9BE6FE1E1 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAN Trojaner" ac=I fn="C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\Fairlight.rar"
sh=38EB819B95824087D6C7B888A3EECDF91BE61BBB ft=1 fh=f998eb64c89b246b vn="Variante von Win32/Packed.VMProtect.AAN Trojaner" ac=I fn="C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\xlive.dll"
sh=3F129A11DB1B7E30E5C5F87EBEE81DB9BE6FE1E1 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAN Trojaner" ac=I fn="C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\Fairlight\Fairlight.rar"
sh=38EB819B95824087D6C7B888A3EECDF91BE61BBB ft=1 fh=f998eb64c89b246b vn="Variante von Win32/Packed.VMProtect.AAN Trojaner" ac=I fn="C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\Fairlight\xlive.dll"
sh=38EB819B95824087D6C7B888A3EECDF91BE61BBB ft=1 fh=f998eb64c89b246b vn="Variante von Win32/Packed.VMProtect.AAN Trojaner" ac=I fn="C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\Fairlight\Fairlight\xlive.dll"
sh=90E222E0B9C756F60EC259673B2D8B4A8730A548 ft=1 fh=3d9a751a37302964 vn="Win32/Adware.1ClickDownload.W Anwendung" ac=I fn="C:\Users\Gast\Downloads\spring_breakers.exe"
sh=410A648EB8392D7407D264CF6C1090D044D044D6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Sicherungsstandart\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.52_0\extensionData\plugins\266.js"
sh=B563BEC7EC0608AB8EBC51C5E228C9270DAC0A09 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Sicherungsstandart\Extensions\aaipilfmheplbcghignccoiiebekkdhe\1.26.52_0\extensionData\plugins\91.js"
sh=ADE8C9E01E2E3344E9A3CD08635B42B76A72FC27 ft=1 fh=c3985d9fc1a4e828 vn="Variante von Win32/DomaIQ.BB evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Sicherungsstandart\File System\007\t\00\00000001"
sh=C82B2281A285CCA916CEFD093BB0D656B7AA19E7 ft=0 fh=0000000000000000 vn="Win32/HackTool.Dhos.A Trojaner" ac=I fn="C:\Users\Sven\Desktop\Datein\lc next trailer\thc-ssl-dos-1.4-win-bin.zip"
sh=5B03CCE8ECEFFBD580FA27EF231F26A77B87B4C0 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAM Trojaner" ac=I fn="C:\Users\Sven\Desktop\Datein\loe\Lord_of_the_Rings_War_in_the_North_Kecks.rar"
sh=53710D0AF5A0F57FA49F7183EA0395D3AC1D4791 ft=1 fh=d5332291d75852c0 vn="Variante von MSIL/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI6E5.tmp-\Smartbar.Resources.LanguageSettings.resources.dll"
sh=A11FFA5A1D425D910E4D8170EB6FA24797931534 ft=1 fh=d53347eea837f487 vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI6E5.tmp-\srbs.dll"
sh=672193D67875EDDA3C0B7D7A5E96A1730FFA718D ft=1 fh=e8f98f8756d96124 vn="Variante von MSIL/Toolbar.Linkury.C evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\MSI999F.tmp-\Smartbar.Resources.SetBrowsersSettings.dll"
sh=4FDD66ECAAFBCC53B9CEFEB9B5544F5B9106BFB8 ft=1 fh=29ea3da0b198764a vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\zoek_backup\C_Users_Sven_Desktop_Datein_pkm_SoftonicDownloader_fuer_visualboyadvance.exe.vir"

Code:


 Results of screen317's Security Check version 0.99.83 
 Windows 7 Service Pack 1 x64 (UAC is disabled!) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus 
 Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````
 Java(TM) 6 Update 27 
 Java 7 Update 55 
 Adobe Flash Player 13.0.0.214 
 Adobe Reader 9 Adobe Reader out of Date!
 Mozilla Firefox (AddOn.)
 Google Chrome 35.0.1916.114 
````````Process Check: objlist.exe by Laurent```````` 
 AVAST Software Avast AvastSvc.exe 
 AVAST Software Avast AvastUI.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````


FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 01
Ran by Sven (administrator) on SVEN-PC on 10-06-2014 21:18:33
Running from C:\Users\Sven\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2245120 2009-07-15] (VIA)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [G Data AntiVirus Tray Application] => C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe
HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3859320 2014-06-05] (AVAST Software)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2937528 2010-05-02] ()
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Auto KTR] => C:\Users\Sven\Downloads\Dm.De.M.C.Co.Edit-PROP\Kaspersky Internet Security 2014 + Trial + Kaspersky World\Kaspersky_Internet_Security_Trial_Reset_2.1_by_Humschi_1857\KIS14 TrialReset.exe -silent
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {732ced11-838c-11df-934f-002618bca0f6} - E:\raf-skyrim.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {c6647fc0-dbee-11e1-b1d5-806e6f6e6963} - E:\setup.exe
Startup: C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27BB72947FE9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\ich@maltegoetz.de [2014-05-20]
FF Extension: Protegere - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\security@protegere.org [2014-06-05]
FF Extension: TrashMail.net - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\spam@trashmail.net.xpi [2011-10-11]
FF Extension: Fox!Box - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi [2011-04-03]
FF Extension: User Agent Switcher - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2011-12-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-05]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []

Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-05]
CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-05]
CHR Extension: (Google Search) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-05]
CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-05]
CHR Extension: (Gmail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-05]
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-05]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-05] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-01] () [File not signed]
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3772784 2010-05-10] (INCA Internet Co., Ltd.) [File not signed]
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-12] ()
S2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [97552 2012-03-22] (SANDBOXIE L.T.D)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) [File not signed]

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-05] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-06-05] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-06-05] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-05] ()
R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [65912 2012-03-08] (G Data Software AG)
R3 KMWDFILTERV1; C:\Windows\System32\DRIVERS\RPGMOUSEV1.sys [24576 2009-06-10] (Windows (R) Codename Longhorn DDK provider)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2010-08-18] () [File not signed]
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] ()
S3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [155136 2012-05-08] (SANDBOXIE L.T.D) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.)
S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2007-10-25] () [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) [File not signed]
R2 WinRing0_1_2_0; C:\Users\Sven\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys [14544 2010-05-02] (OpenLibSys.org)
R3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
U3 a242qqk6; C:\Windows\System32\Drivers\a242qqk6.sys [0 ] (Advanced Micro Devices)
S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X]
S3 dump_wmimmc; \??\C:\Program Files (x86)\Gameforge4D\CABAL Online\GameGuard\dump_wmimmc.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-10 21:01 - 2014-06-10 20:56 - 00854367 _____ () C:\Users\Sven\Desktop\SecurityCheck.exe
2014-06-10 20:56 - 2014-06-10 20:56 - 00854367 _____ () C:\Users\Sven\Downloads\SecurityCheck.exe
2014-06-10 13:38 - 2014-06-10 13:38 - 02347384 _____ (ESET) C:\Users\Sven\Downloads\esetsmartinstaller_deu.exe
2014-06-10 13:27 - 2014-06-10 13:34 - 00062170 _____ () C:\Users\Sven\Desktop\SystemLook.txt
2014-06-10 13:26 - 2014-06-10 13:26 - 00165376 _____ () C:\Users\Sven\Downloads\SystemLook_x64.exe
2014-06-10 13:26 - 2014-06-10 13:26 - 00165376 _____ () C:\Users\Sven\Desktop\SystemLook_x64.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt
2014-06-10 12:29 - 2014-06-10 21:19 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt
2014-06-10 12:04 - 2014-06-10 12:30 - 00032826 _____ () C:\zoek-results.log
2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895}
2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr
2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com
2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar
2014-06-10 12:00 - 2014-06-10 12:22 - 00000000 ____D () C:\zoek_backup
2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt
2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt
2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt
2014-06-10 11:35 - 2014-06-10 11:36 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip
2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe
2014-06-10 11:28 - 2014-06-10 12:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-10 11:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-10 11:26 - 2014-06-10 11:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-06-10 11:18 - 2014-06-10 11:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-06-10 11:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-10 11:02 - 2014-06-10 11:11 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe
2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta
2014-06-10 01:11 - 2014-06-10 02:09 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos
2014-06-10 00:01 - 2014-06-10 01:10 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip
2014-06-09 15:56 - 2014-06-10 12:59 - 00087456 _____ () C:\Users\Sven\Downloads\Addition.txt
2014-06-09 15:04 - 2014-06-10 21:19 - 00018982 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-09 15:04 - 2014-06-10 21:18 - 00000000 ____D () C:\FRST
2014-06-09 15:03 - 2014-06-09 15:04 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:00 - 2014-06-09 15:01 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:43 - 2012-05-12 12:31 - 00121416 _____ (MotioninJoy) C:\Windows\system32\Drivers\MijXfilt.sys
2014-06-09 04:43 - 2011-12-07 19:42 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00328712 _____ (Logitech Inc.) C:\Windows\system32\MijFrc.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00074960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xusb21.sys
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-07 05:44 - 2014-06-08 06:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2014-06-07 05:44 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-06 01:14 - 2014-06-06 01:27 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-05 22:54 - 2014-06-10 17:22 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-10 11:51 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:16 - 2014-06-05 06:14 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:15 - 2014-06-05 06:14 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:15 - 2014-06-05 06:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 02:05 - 2014-06-10 11:49 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-05 01:52 - 2014-06-05 02:06 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:46 - 2014-06-05 04:55 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-04 15:13 - 2014-06-06 01:23 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-04 11:49 - 2014-06-10 20:02 - 00048537 _____ () C:\Windows\setupact.log
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:48 - 2014-06-10 13:19 - 00019796 _____ () C:\Windows\PFRO.log
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:24 - 2014-05-28 23:52 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 19:51 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 01:48 - 2014-06-04 22:12 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-05-24 19:23 - 2014-06-09 15:37 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-05-22 07:09 - 2014-05-22 07:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:11 - 2014-05-22 03:12 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:13 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:10 - 2014-05-22 03:13 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:09 - 2014-05-22 03:10 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-22 03:02 - 2014-05-22 03:21 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-20 02:04 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-20 02:04 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-20 02:04 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-17 02:34 - 2014-06-09 15:41 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-05-16 18:58 - 2014-05-27 03:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-15 12:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 12:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 12:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 12:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 21:46 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 21:45 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 21:45 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 21:45 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 21:45 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 21:45 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 21:45 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 21:45 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 21:45 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 21:45 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 21:45 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 16:44 - 2014-05-27 02:29 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-12 11:48 - 2014-05-27 02:27 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos

==================== One Month Modified Files and Folders =======

2014-06-10 21:19 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-10 21:19 - 2014-06-09 15:04 - 00018982 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-10 21:19 - 2010-05-02 11:53 - 00000000 ____D () C:\Users\Sven\AppData\Local\PMB Files
2014-06-10 21:18 - 2014-06-09 15:04 - 00000000 ____D () C:\FRST
2014-06-10 21:12 - 2012-07-12 11:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-10 21:02 - 2013-04-03 00:13 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-10 20:56 - 2014-06-10 21:01 - 00854367 _____ () C:\Users\Sven\Desktop\SecurityCheck.exe
2014-06-10 20:56 - 2014-06-10 20:56 - 00854367 _____ () C:\Users\Sven\Downloads\SecurityCheck.exe
2014-06-10 20:16 - 2012-05-30 00:00 - 01094370 _____ () C:\Windows\WindowsUpdate.log
2014-06-10 20:02 - 2014-06-04 11:49 - 00048537 _____ () C:\Windows\setupact.log
2014-06-10 19:42 - 2011-12-22 15:59 - 00001134 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job
2014-06-10 17:22 - 2014-06-05 22:54 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-10 14:56 - 2010-08-25 16:11 - 08029696 ___SH () C:\Users\Sven\Desktop\Thumbs.db
2014-06-10 14:55 - 2012-08-20 16:47 - 00000000 ___RD () C:\Users\Sven\Dropbox
2014-06-10 14:55 - 2012-02-27 23:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Dropbox
2014-06-10 14:02 - 2013-04-03 00:13 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-10 13:38 - 2014-06-10 13:38 - 02347384 _____ (ESET) C:\Users\Sven\Downloads\esetsmartinstaller_deu.exe
2014-06-10 13:34 - 2014-06-10 13:27 - 00062170 _____ () C:\Users\Sven\Desktop\SystemLook.txt
2014-06-10 13:27 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-10 13:27 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-10 13:26 - 2014-06-10 13:26 - 00165376 _____ () C:\Users\Sven\Downloads\SystemLook_x64.exe
2014-06-10 13:26 - 2014-06-10 13:26 - 00165376 _____ () C:\Users\Sven\Desktop\SystemLook_x64.exe
2014-06-10 13:20 - 2014-05-07 00:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DropboxMaster
2014-06-10 13:19 - 2014-06-04 11:48 - 00019796 _____ () C:\Windows\PFRO.log
2014-06-10 13:19 - 2010-05-02 00:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-10 13:19 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-10 13:18 - 2011-02-21 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Sun
2014-06-10 13:06 - 2014-06-10 13:06 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-06-10 13:06 - 2014-06-10 13:06 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-06-10 12:59 - 2014-06-09 15:56 - 00087456 _____ () C:\Users\Sven\Downloads\Addition.txt
2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt
2014-06-10 12:54 - 2014-06-10 11:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 12:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources
2014-06-10 12:30 - 2014-06-10 12:04 - 00032826 _____ () C:\zoek-results.log
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt
2014-06-10 12:22 - 2014-06-10 12:00 - 00000000 ____D () C:\zoek_backup
2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895}
2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar
2014-06-10 12:00 - 2014-06-10 12:29 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt
2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt
2014-06-10 11:51 - 2014-06-05 06:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-10 11:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA
2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt
2014-06-10 11:49 - 2014-06-05 02:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-10 11:36 - 2014-06-10 11:35 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip
2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe
2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Malwarebytes
2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-10 11:27 - 2014-06-10 11:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-06-10 11:19 - 2014-06-10 11:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-06-10 11:12 - 2009-07-14 06:45 - 00554864 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-10 11:11 - 2014-06-10 11:02 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe
2014-06-10 03:38 - 2013-04-12 12:21 - 00000000 ____D () C:\Users\Sven\Downloads\01AlpaGun
2014-06-10 03:36 - 2010-05-02 01:31 - 00166832 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-10 03:33 - 2012-06-15 00:56 - 00211968 ___SH () C:\Users\Sven\Thumbs.db
2014-06-10 02:09 - 2014-06-10 01:11 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos
2014-06-10 01:42 - 2011-12-22 15:59 - 00001112 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job
2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta
2014-06-10 01:10 - 2014-06-10 00:01 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip
2014-06-09 18:26 - 2013-04-30 15:36 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2
2014-06-09 18:22 - 2014-06-09 18:17 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar
2014-06-09 15:54 - 2010-05-26 00:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-09 15:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-09 15:51 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-06-09 15:51 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-09 15:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-09 15:49 - 2009-07-14 04:34 - 00000387 _____ () C:\Windows\win.ini
2014-06-09 15:41 - 2014-05-17 02:34 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-06-09 15:37 - 2014-05-24 19:23 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-06-09 15:04 - 2014-06-09 15:03 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:01 - 2014-06-09 15:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-09 01:35 - 2010-06-20 16:07 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype
2014-06-08 06:33 - 2014-06-07 05:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 22:56 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-07 21:03 - 2010-08-01 05:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc
2014-06-07 20:12 - 2014-06-09 18:22 - 149696502 _____ () C:\Users\Sven\Downloads\Lucy-Cat - MAGICPOINT MIT ZUNGE - geht das überhaupt 05.06.14.flv
2014-06-07 05:44 - 2014-06-07 05:38 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2010-05-23 16:08 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DAEMON Tools Lite
2014-06-06 06:32 - 2009-07-14 19:58 - 00717506 _____ () C:\Windows\system32\perfh007.dat
2014-06-06 06:32 - 2009-07-14 19:58 - 00155122 _____ () C:\Windows\system32\perfc007.dat
2014-06-06 06:32 - 2009-07-14 07:13 - 01657416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-06 01:27 - 2014-06-06 01:14 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-06 01:23 - 2014-06-04 15:13 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-05 23:01 - 2014-04-04 10:42 - 00000000 ____D () C:\Users\Sven\Downloads\Animus
2014-06-05 10:13 - 2012-03-07 22:30 - 00000000 ____D () C:\ProgramData\G DATA
2014-06-05 09:54 - 2012-08-20 23:32 - 00000000 ____D () C:\Users\Sven\Downloads\thc-ssl-dos
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 07:00 - 2012-10-31 02:28 - 00000000 ____D () C:\Users\Sven\Downloads\GTA 4
2014-06-05 06:56 - 2013-05-09 01:56 - 00000000 ____D () C:\Users\Sven\Downloads\DVD1
2014-06-05 06:54 - 2013-10-04 00:55 - 00000000 ____D () C:\Users\Sven\Downloads\Capo - Hallo Monaco (Fan Edition)
2014-06-05 06:53 - 2012-03-04 22:38 - 00000000 ____D () C:\Users\Sven\Downloads\Bigger.Stronger.Faster.2008.German.AC3.BRRip.Xvid-HOR
2014-06-05 06:52 - 2013-04-19 14:24 - 00000000 ____D () C:\Users\Sven\Downloads\5fu54ggrt
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:43 - 2010-05-02 01:01 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:14 - 2014-06-05 06:16 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:14 - 2014-06-05 06:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:14 - 2014-06-05 06:15 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 04:55 - 2014-06-05 01:46 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 03:13 - 2011-04-02 01:40 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Users\Sven\AppData\Local\Mozilla
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-05 03:04 - 2013-04-03 00:14 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-05 02:06 - 2014-06-05 01:52 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:30 - 2014-03-09 11:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\JDownloader 2.0
2014-06-05 00:36 - 2012-05-25 07:38 - 00000000 ____D () C:\Users\Sven\Downloads\Celo & Abdi - Hinterhofjargon
2014-06-04 22:12 - 2014-05-29 01:48 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:24 - 2010-05-02 11:10 - 00000000 ____D () C:\Windows\pss
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:22 - 2010-05-02 01:22 - 00000000 ____D () C:\Program Files (x86)\CCleaner
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-31 18:15 - 2013-08-31 20:27 - 00000000 ____D () C:\Users\UpdatusUser.Sven-PC
2014-05-31 18:15 - 2013-01-23 23:29 - 00000000 ____D () C:\Users\Gast
2014-05-31 09:42 - 2014-06-09 18:09 - 97747333 _____ () C:\Users\Sven\Downloads\Lucy-Cat - 100-SEKUNDEN-ARSCHFICKWETTE! Wieviel Stöße schaffst du 31.05.14.flv
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-30 20:02 - 2010-06-20 16:07 - 00000000 ____D () C:\ProgramData\Skype
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 20:03 - 2010-07-18 18:57 - 00000000 ____D () C:\Users\Sven\Documents\My Games
2014-05-29 19:52 - 2010-05-02 14:47 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-05-29 19:51 - 2014-05-29 08:38 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 19:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 03:49 - 2013-05-09 06:45 - 00000000 ____D () C:\Program Files (x86)\War Thunder
2014-05-28 23:52 - 2014-05-29 19:24 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-28 15:51 - 2012-08-20 16:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-28 00:55 - 2014-05-07 14:55 - 00000000 ____D () C:\Program Files (x86)\LCGenericName02
2014-05-28 00:28 - 2013-10-01 14:36 - 00000000 ____D () C:\Users\Sven\AppData\Local\ArmA 2 OA
2014-05-27 05:00 - 2012-08-21 07:08 - 00000000 ____D () C:\Users\Sven\AppData\Local\Trainer
2014-05-27 03:58 - 2014-05-16 18:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-27 02:29 - 2014-05-13 16:44 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-27 02:27 - 2014-05-12 11:48 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos
2014-05-22 18:43 - 2011-09-22 15:23 - 00000000 ____D () C:\Fraps
2014-05-22 07:10 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 07:05 - 2011-12-29 22:25 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-22 05:55 - 2013-09-05 05:41 - 00000000 ____D () C:\Users\Sven\Downloads\4ZuDer9
2014-05-22 03:21 - 2014-05-22 03:02 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-22 03:21 - 2012-05-07 06:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastChaosGER
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:13 - 2014-05-22 03:10 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:13 - 2014-05-22 03:10 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:12 - 2014-05-22 03:11 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:09 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr
2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com
2014-05-20 02:05 - 2014-03-09 11:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2010-05-02 14:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-20 01:49 - 2012-08-19 02:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-20 01:49 - 2012-08-19 02:55 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Wippien
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Program Files\Wippien
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-18 11:29 - 2013-06-07 06:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-18 11:29 - 2011-07-16 21:42 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft
2014-05-18 11:29 - 2010-05-02 01:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-17 03:21 - 2012-07-12 11:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-17 03:21 - 2012-07-12 11:08 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-17 03:21 - 2011-10-10 11:10 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-17 03:20 - 2010-05-02 01:24 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe
2014-05-15 14:14 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 13:31 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 12:48 - 2013-08-14 04:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 12:37 - 2010-05-02 11:19 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 20:30 - 2014-05-08 18:29 - 00000000 ____D () C:\Users\Sven\Downloads\RapidLC
2014-05-12 20:46 - 2010-11-07 21:40 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-05-12 10:29 - 2013-09-30 15:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-12 10:29 - 2010-10-03 14:41 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TS3Client
2014-05-12 10:29 - 2010-05-02 01:37 - 00000000 ____D () C:\Users\Sven\Tracing
2014-05-12 10:29 - 2010-05-02 01:34 - 00000000 ____D () C:\Windows\Panther
2014-05-12 07:26 - 2014-06-10 11:28 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-10 11:28 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2012-03-08 00:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

Some content of TEMP:
====================
C:\Users\Sven\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfaj_ny.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-08 00:01

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---

Soo.. fehlen noch irgendwelche Logs ?

M-K-D-B 11.06.2014 10:55

Zitat:

Zitat von Goodfell (Beitrag 1313841)
Soo.. fehlen noch irgendwelche Logs ?

Nein, das genügt mir. :)





Reste entfernen
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:

start
C:\Users\Gast\Downloads\spring_breakers.exe
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Sicherungsstandart\Extensions\aaipilfmheplbcghignccoiiebekkdhe
C:\Users\Sven\Desktop\Datein\lc next trailer\thc-ssl-dos-1.4-win-bin.zip
Reboot:
end


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.









Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. :daumenhoc
Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.




Schritt 1
Du verwendest veraltete Software auf deinem Rechner, was ein Sicherheitsrisiko darstellt. Daher solltest du veraltete Software deinstallieren und anschließend die aktuellste Version installieren.
Folge dem Pfad Start > Systemsteuerung > Sofware / Programme deinstallieren.
Deinstalliere die folgenden Programme von deinem Rechner:
  • Java(TM) 6 Update 27
  • Java 7 Update 55
  • Adobe Reader 9
Starte deinen Rechner nach der Deinstallation neu auf.
Downloade und installiere dir bitte nun:Starte deinen Rechner nach der Installation neu auf.





Schritt 2
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.







Schritt 3
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems.


Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti-Viren-Programm und zusätzlicher Schutz
  • Gehe sicher, dass du immer nur eine Anti-Viren Software installiert hast und dass diese auch up to date ist! Ein kostenloses Anti-Viren Programm, das wir empfehlen, wäre z. B. Avast! Free Antivirus oder Microsoft Security Essentials.
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt. Du kannst es zusätzlich zu deinem Anti-Viren Programm verwenden.
    Update das Tool und lasse es einmal in der Woche laufen. Die Kaufversion bietet zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • AdwCleaner
    Dieses Tool erkennt eine Vielzahl von Werbeprogrammen (Adware) und unerwümschten Programmen (PUPs).
    Starte das Tool einmal die Woche und lass es laufen. Sollte eine neue Version verfügbar sein, so wird dies angezeigt und du kannst dir die neueste Version direkt von der Herstellerseite auf den Desktop herunterladen. Auch dieses Programm kann parallel zu deinem Anti-Viren Programm verwendet werden.
  • SpywareBlaster
    Eine kurze Einführung findest du Hier


Alternative Browser
Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Mozilla Firefox
  • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
  • NoScript
    Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt, wenn Du es bestätigst.
  • AdblockPlus
    Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzuzufügen reicht und dieser wird nicht mehr geladen.
    Es spart außerdem Downloadkapazität.


Performance
  • Halte dich fern von Registry Cleanern.
    Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link:
    Miekemoes Blogspot ( MVP )


Was du vermeiden solltest:
  • Klicke nicht auf alles, nur weil es dich dazu auffordert und schön bunt ist.
  • Verwende keine P2P oder Filesharing Software (Emule, uTorrent,..).
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie z.B. deinFoto.jpg.exe.
  • Lade keine Software von Softonic oder Chip herunter, da diese Installer oft mit Adware oder unerünschter Software versehen sind!



Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen?

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

Goodfell 11.06.2014 14:00

Super, danke dir, schätze es wirklich sehr!



Zitat:

Zitat von M-K-D-B (Beitrag 1314040)

Schritt 2
Die Reihenfolge ist hier entscheidend.
Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
Windowstaste + R > Combofix /Uninstall (eingeben) > OK

Ich hab weder Defogger oder Combofix benutzt, wie soll ich vorgehen ?

Code:


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-06-2014 01
Ran by Sven at 2014-06-11 14:56:41 Run:2
Running from C:\Users\Sven\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
C:\Users\Gast\Downloads\spring_breakers.exe
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Sicherungsstandart\Extensions\aaipilfmheplbcghignccoiiebekkdhe
C:\Users\Sven\Desktop\Datein\lc next trailer\thc-ssl-dos-1.4-win-bin.zip
Reboot:
end
*****************

C:\Users\Gast\Downloads\spring_breakers.exe => Moved successfully.
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Sicherungsstandart\Extensions\aaipilfmheplbcghignccoiiebekkdhe => Moved successfully.
C:\Users\Sven\Desktop\Datein\lc next trailer\thc-ssl-dos-1.4-win-bin.zip => Moved successfully.


The system needed a reboot.

==== End of Fixlog ====


M-K-D-B 12.06.2014 09:06

Zitat:

Zitat von Goodfell (Beitrag 1314111)
Ich hab weder Defogger oder Combofix benutzt, wie soll ich vorgehen ?

Naja, diese zwei Schritte einfach weglassen und gleich mit DelFix weiter... steht doch dort "Falls du ... benutzt hast" ;)





Ich bin froh, dass wir helfen konnten :abklatsch:

In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest:
Lob, Kritik und Wünsche
Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! :)

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:20 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131