sheldon299 | 31.07.2014 09:40 | mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.07.2014
Suchlauf-Zeit: 20:34:25
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.30.06
Rootkit Datenbank: v2014.07.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Christian
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 428527
Verstrichene Zeit: 1 Std, 18 Min, 47 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 17
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [ab037332631879bd507814833ac8ec14],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [ab037332631879bd507814833ac8ec14],
PUP.Optional.Babylon.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [5f4f51541863f1454f06a5b98d75f40c],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, In Quarantäne, [2e8004a126553303edde82581fe3817f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPly, In Quarantäne, [0ea0aff692e93cfa99a593499d653dc3],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\NCH_EN, In Quarantäne, [c3eb51540477c3735224ceff36ccdb25],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje, In Quarantäne, [c2ec327380fbfc3a0deae2fa9c661ce4],
PUP.Optional.DealPly.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje, In Quarantäne, [4767baeb2556152127d12bb107fbee12],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [3e70b2f36219ef47dbcf3bbcf0126799],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [8e20327324570d29d1f728e5c73d3ac6],
PUP.Optional.BProtector.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [19950f962853c86ee016c14f7193bf41],
PUP.Optional.DealPly.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gaiilaahiahdejapggenmdmafpmbipje, In Quarantäne, [5856a8fd98e360d6fff936a624de6997],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{125B7A09-B405-46FB-95FB-96CF6B72992D}, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\CLASSES\Toolbar.CT2801948, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Toolbar.CT2801948, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{125B7A09-B405-46FB-95FB-96CF6B72992D}, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\NCH_EN Toolbar, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
Registrierungswerte: 2
PUP.Optional.InstallCore.A, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0S0TzrtN0V1M1O1H, In Quarantäne, [8e20327324570d29d1f728e5c73d3ac6]
PUP.BProtector, HKU\S-1-5-21-624546122-312161334-520473447-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [6b433174027965d107a0be4fa06423dd]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 10
PUP.OPtional.Dealply.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly, In Quarantäne, [1a94782de09b6fc7ba62e825e51ffe02],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.Babylon.A, C:\Users\Christian\AppData\LocalLow\BabylonToolbar, In Quarantäne, [614d44610c6fce6838ba19a339c98977],
PUP.Optional.Babylon.A, C:\Users\Christian\AppData\LocalLow\BabylonToolbar\BabylonToolbar, In Quarantäne, [614d44610c6fce6838ba19a339c98977],
PUP.Optional.Conduit.A, C:\Users\Christian\AppData\LocalLow\NCH_EN, In Quarantäne, [c4eaa7fe5c1f3600014230987c8613ed],
PUP.Optional.Conduit.A, C:\Users\Christian\AppData\LocalLow\NCH_EN\Logs, In Quarantäne, [c4eaa7fe5c1f3600014230987c8613ed],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
Dateien: 35
PUP.OPtional.Dealply.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly\Uninstall DealPly.lnk, In Quarantäne, [1a94782de09b6fc7ba62e825e51ffe02],
PUP.OPtional.Dealply.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly Help.lnk, In Quarantäne, [1a94782de09b6fc7ba62e825e51ffe02],
PUP.OPtional.Dealply.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly.lnk, In Quarantäne, [1a94782de09b6fc7ba62e825e51ffe02],
PUP.Optional.BProtector.A, C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data, In Quarantäne, [6549f2b3007b092d46b11df3d62e36ca],
PUP.Optional.BProtector.A, C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, In Quarantäne, [b8f675305a211d19995f26eaf80c02fe],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.settings, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\bl, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\dm, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\00, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\01, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\02, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\03, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\10, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\11, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\12, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\13, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\20, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\21, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\22, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.BitGuard.A, C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\traking_settings\23, In Quarantäne, [9717267f16652e08f96cc9e255ad0000],
PUP.Optional.Conduit.A, C:\Users\Christian\AppData\LocalLow\NCH_EN\ldrtbNCH_.dll, In Quarantäne, [c4eaa7fe5c1f3600014230987c8613ed],
PUP.Optional.Conduit.A, C:\Users\Christian\AppData\LocalLow\NCH_EN\tbNCH_.dll, In Quarantäne, [c4eaa7fe5c1f3600014230987c8613ed],
PUP.Optional.Conduit.A, C:\Users\Christian\AppData\LocalLow\NCH_EN\toolbar.cfg, In Quarantäne, [c4eaa7fe5c1f3600014230987c8613ed],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\GottenAppsContextMenu.xml, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\ldrtbNCH_.dll, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\NCH_ENToolbarHelper.exe, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\OtherAppsContextMenu.xml, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\prxtbNCH_.dll, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\SharedAppsContextMenu.xml, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\tbNCH_.dll, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\toolbar.cfg, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\ToolbarContextMenu.xml, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Conduit.A, C:\Program Files (x86)\NCH_EN\uninstall.exe, In Quarantäne, [d9d5b9ecf58692a4192b11b722e0b64a],
PUP.Optional.Delta.A, C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=AC1118F46AAC3BA1&affID=121240&tsp=4983",), Ersetzt,[a905a104b2c953e35132f0fa5fa5ff01]
PUP.Optional.Delta.A, C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=AC1118F46AAC3BA1&affID=121240&tsp=4983" ],), Ersetzt,[5856277eef8c6fc72d88905ad43026da]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner: Code:
# AdwCleaner v3.302 - Bericht erstellt am 31/07/2014 um 09:40:27
# Aktualisiert 30/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Christian - CHRISTIAN-PC
# Gestartet von : C:\Users\Christian\Desktop\adwcleaner_3.302.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\ProgramData\NCH Software
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Program Files (x86)\NCH Software
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Tobit
Ordner Gelöscht : C:\Users\Christian\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Christian\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Christian\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Christian\AppData\Roaming\NCH Software
Ordner Gelöscht : C:\Users\Christian\AppData\Roaming\Tobit
Ordner Gelöscht : C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Datei Gelöscht : C:\Windows\System32\roboot64.exe
***** [ Tasks ] *****
Task Gelöscht : DealPlyUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Schlüssel Gelöscht : HKCU\Software\a55dfd8b16fe841
Schlüssel Gelöscht : HKLM\SOFTWARE\a55dfd8b16fe841
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Google Chrome v36.0.1985.125
[ Datei : C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=AC1118F46AAC3BA1&affID=121240&tsp=4983
Gelöscht [Extension] : amfclgbdpgndipgoegfpkkgobahigbcl
*************************
AdwCleaner[R0].txt - [5220 octets] - [31/07/2014 09:33:16]
AdwCleaner[S0].txt - [5027 octets] - [31/07/2014 09:40:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5087 octets] ########## JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Christian on 31.07.2014 at 10:05:19,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho15B2.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho1880.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho18F0.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho1A53.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho22AF.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2617.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2667.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho28C6.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2A0D.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2A1C.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2A79.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2D48.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2D95.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2EED.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho2FC8.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho32F2.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3378.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho33AE.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho35B1.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3691.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3726.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho37D.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho3820.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho39B5.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho4960.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho4C31.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho4C7A.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho4CBA.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho4E60.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho4FF3.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho513C.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho59D.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5BE6.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5CA1.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5D3E.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho5DBA.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho6326.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho6410.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho6815.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho704F.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho70CC.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho77CE.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho77FC.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho7CBE.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho7EB1.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho7EC2.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8307.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho845C.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8596.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8660.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho89B.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho89CA.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8B3F.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8B8E.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8F5.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8F53.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho92ED.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho92F0.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9443.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho95E9.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho973.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho977E.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9A8B.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9AC9.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9B1.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho9DAD.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA18C.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA4E6.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA5A1.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA66D.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoA6DB.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoAD17.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB673.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB76E.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB94.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBA9A.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBC12.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBDA5.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoBFBB.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoC015.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoC967.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoC9FC.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoCA52.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoCA74.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoCB4C.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD422.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD59F.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoD670.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoDB80.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoDF18.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE2E1.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE502.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE5FE.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE974.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE9B6.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE9D3.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoEA2F.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoED5B.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF131.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF1D.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF24C.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoF5C3.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoFA47.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoFB9E.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoFF8.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoFFC2.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{14AF6E24-D324-450B-903D-1AA0689BBEB0}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{298D4ABB-E53C-4507-AABA-B6BD3D2DA110}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{3222266A-AE08-4F50-813C-FCEE8B53BFCF}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{54CAECCF-56B8-4F75-A08D-82ACB02E856D}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{56DA82D2-65E2-4336-9643-65B382D83DB4}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{78D4A9CC-33B2-4AE0-95CB-B626DA5DDBD2}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{820375D8-219D-4458-BE5B-81C8EBB7EDC1}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{844D8332-E1D9-418C-ADFA-D8BAF37E7308}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{A0366952-4AF1-4275-8B4C-C780CAD73D9F}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{A5C44B10-AFD8-4476-A069-44377C98817F}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{AAC5C4C3-7553-4998-A1F0-8BB22464216B}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{ADFF7955-13A6-4A29-8395-80D50113D98E}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{BC235D62-E9CC-4CDD-807C-0C9EE63377B3}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{C1BAE629-D939-4FBB-895F-022649FACAC5}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{CDC4E08A-BDD6-49BC-945E-4A139D5D092C}
Successfully deleted: [Empty Folder] C:\Users\Christian\appdata\local\{D98D60CD-FBE4-4756-80A3-D64C483BA6D0}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.07.2014 at 10:32:04,11
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-07-2014 01
Ran by Christian (administrator) on CHRISTIAN-PC on 31-07-2014 10:36:44
Running from C:\Users\Christian\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Egis Technology Inc. ) C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(Genie9) C:\Program Files\Genie9\Genie Timeline\GenieTimeLineAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2010-11-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [G Data ASM] => C:\Program Files (x86)\G Data\InternetSecurity\DelayLoader\AutorunDelayLoader.exe [431224 2013-12-19] (G Data Software AG)
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG)
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-624546122-312161334-520473447-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-624546122-312161334-520473447-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled ()
Startup: C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKLM-x32 - (No Name) - {37483b40-c254-4a72-bda4-22ee90182c1e} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {A3648F4B-44FD-4028-A44A-6A63C983B7FB} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKCU - {A3648F4B-44FD-4028-A44A-6A63C983B7FB} URL = https://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.11.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.11.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Christian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-01-22]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-01-22]
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
Chrome:
=======
CHR HomePage:
CHR NewTab: "chrome-extension://eooncjejnppfjjklapaamhcdmjbilmde/redirect.html",
"chrome-extension://amfclgbdpgndipgoegfpkkgobahigbcl/redirect.html"
CHR DefaultSearchKeyword: delta-search.com
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\gcswf32.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Bing Bar) - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Unity Player) - C:\Users\Christian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (YouTube) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-17]
CHR Extension: (Google-Suche) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-17]
CHR Extension: (Google Wallet) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-05]
CHR Extension: (Google Mail) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [354304 2010-11-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [194496 2010-06-17] (Advanced Micro Devices)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2723400 2014-03-25] (G Data Software AG)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed]
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG)
R2 GenieTimelineService; C:\Program Files\Genie9\Genie Timeline\GenieTimelineService.exe [678464 2013-12-08] (Genie9)
S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2010-11-12] (NTI Corporation)
S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [807896 2012-05-21] (Mister Group)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com)
S3 DLPortIO; C:\Windows\SysWOW64\DRIVERS\DLPortIO.SYS [3584 2000-06-29] () [File not signed]
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-07-26] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-07-26] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [68608 2014-07-26] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-05-17] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-07-28] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-07-26] (G Data Software AG)
S2 hwpsgt; C:\Windows\SysWOW64\DRIVERS\hwpsgt.sys [137344 2011-07-13] () [File not signed]
S2 lemsgt; C:\Windows\SysWOW64\DRIVERS\lemsgt.sys [9472 2011-07-13] () [File not signed]
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2013-09-02] (hxxp://libusb-win32.sourceforge.net)
S3 rsvcdwdr; C:\Windows\System32\DRIVERS\rsvcdwdr.sys [45160 2011-11-17] (RapidSolution Software AG)
R1 SLEE_18_DRIVER; C:\Windows\Sleen1864.sys [109144 2014-01-30] (Softwareentwicklung Remus - ArchiCrypt - )
S2 TVicPort; No ImagePath
R1 usedisk; C:\Windows\System32\DRIVERS\usedisk.sys [29208 2014-02-27] (Gili Soft INC.)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [254976 2010-08-31] (Jungo)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 Ser2pl; system32\DRIVERS\ser2pl64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-31 10:36 - 2014-07-31 10:36 - 00017052 _____ () C:\Users\Christian\Desktop\FRST.txt
2014-07-31 10:36 - 2014-07-31 10:36 - 00000000 ____D () C:\Users\Christian\Desktop\FRST-OlderVersion
2014-07-31 10:32 - 2014-07-31 10:32 - 00009329 _____ () C:\Users\Christian\Desktop\JRT.txt
2014-07-31 10:05 - 2014-07-31 10:05 - 00000000 ____D () C:\Windows\ERUNT
2014-07-31 09:58 - 2014-07-31 09:58 - 01016261 _____ (Thisisu) C:\Users\Christian\Desktop\JRT.exe
2014-07-31 09:39 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-31 09:33 - 2014-07-31 09:40 - 00000000 ____D () C:\AdwCleaner
2014-07-31 09:32 - 2014-07-31 09:32 - 01361309 _____ () C:\Users\Christian\Desktop\adwcleaner_3.302.exe
2014-07-30 22:20 - 2014-07-30 22:20 - 00011448 _____ () C:\Users\Christian\Desktop\mbam.txt
2014-07-30 20:33 - 2014-07-30 22:17 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-30 20:32 - 2014-07-30 20:32 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-30 20:32 - 2014-07-30 20:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-30 20:32 - 2014-07-30 20:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-30 20:32 - 2014-07-30 20:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-30 20:32 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-30 20:32 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-30 20:32 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-30 20:29 - 2014-07-30 20:30 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christian\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-29 20:04 - 2014-07-29 20:04 - 00000000 ___SD () C:\ComboFix
2014-07-29 19:58 - 2014-07-29 19:58 - 00028816 _____ () C:\ComboFix.txt
2014-07-29 17:58 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-29 17:58 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-29 17:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-29 17:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-29 17:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-29 17:58 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-29 17:58 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-29 17:58 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-29 17:46 - 2014-07-29 20:04 - 00000000 ____D () C:\Qoobox
2014-07-29 17:43 - 2014-07-29 19:50 - 00000000 ____D () C:\Windows\erdnt
2014-07-29 17:40 - 2014-07-29 17:41 - 05563986 ____R (Swearware) C:\Users\Christian\Desktop\ComboFix.exe
2014-07-29 10:56 - 2014-07-29 10:55 - 00321448 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-29 10:55 - 2014-07-29 10:55 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-29 10:55 - 2014-07-29 10:55 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-29 10:55 - 2014-07-29 10:55 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-29 10:55 - 2014-07-29 10:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-29 10:54 - 2014-07-29 10:54 - 00000000 ____D () C:\Program Files\Java
2014-07-29 10:40 - 2014-07-29 10:40 - 00000000 ____D () C:\Users\Christian\.structorizer
2014-07-28 17:41 - 2014-07-28 17:41 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Acer
2014-07-28 17:38 - 2014-07-28 17:39 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Microsoft Games
2014-07-28 17:38 - 2014-07-28 17:38 - 00000622 _____ () C:\Users\Elisabeth & Franz.Christian-PC\Desktop\Solitär.lnk
2014-07-28 17:37 - 2014-07-28 17:37 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Duden
2014-07-28 17:36 - 2014-07-28 17:36 - 00166880 _____ () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-28 17:36 - 2014-07-28 17:36 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Macromedia
2014-07-28 17:36 - 2014-07-28 17:36 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Adobe
2014-07-28 17:35 - 2014-07-28 17:35 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Google
2014-07-28 17:33 - 2014-07-29 21:55 - 00000680 __RSH () C:\Users\Elisabeth & Franz.Christian-PC\ntuser.pol
2014-07-28 17:33 - 2014-07-28 17:33 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\CyberLink
2014-07-28 17:33 - 2014-07-28 17:33 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\PowerCinema
2014-07-28 17:31 - 2014-07-29 21:55 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC
2014-07-28 17:31 - 2014-07-28 17:31 - 00000020 ___SH () C:\Users\Elisabeth & Franz.Christian-PC\ntuser.ini
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Vorlagen
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Startmenü
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Netzwerkumgebung
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Lokale Einstellungen
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Eigene Dateien
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Druckumgebung
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Documents\Eigene Musik
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Documents\Eigene Bilder
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Verlauf
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Anwendungsdaten
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Anwendungsdaten
2014-07-28 17:31 - 2014-02-17 15:30 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Genie9
2014-07-28 17:31 - 2013-09-23 16:19 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\Documents\Visual Studio 2010
2014-07-28 17:31 - 2011-11-16 10:30 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Microsoft Help
2014-07-28 17:31 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-28 17:31 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-28 17:22 - 2014-07-31 09:43 - 00000616 _____ () C:\Windows\setupact.log
2014-07-28 17:22 - 2014-07-28 17:22 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-28 17:21 - 2014-07-31 09:42 - 00015494 _____ () C:\Windows\PFRO.log
2014-07-28 17:09 - 2014-07-29 11:13 - 00002782 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-28 17:09 - 2014-07-28 17:09 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-28 17:07 - 2014-07-28 17:07 - 04813544 _____ (Piriform Ltd) C:\Users\Christian\Downloads\ccsetup416.exe
2014-07-28 13:56 - 2014-07-28 13:56 - 00000573 _____ () C:\Users\Christian\Desktop\Programmers Notepad [WinAVR].lnk
2014-07-28 12:44 - 2014-07-28 12:44 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-07-28 12:44 - 2014-07-28 12:44 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-07-28 11:57 - 2014-07-28 11:57 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-28 11:55 - 2014-07-28 11:56 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Christian\Downloads\revosetup95.exe
2014-07-27 16:13 - 2014-07-31 10:37 - 00000000 ____D () C:\FRST
2014-07-27 16:13 - 2014-07-31 10:36 - 02094080 _____ (Farbar) C:\Users\Christian\Desktop\FRST64.exe
2014-07-27 15:54 - 2014-07-27 16:00 - 251170997 _____ () C:\Users\Christian\Downloads\Windows6.1-KB958830-x64-RefreshPkg.msu
2014-07-27 15:44 - 2014-07-27 15:50 - 241162581 _____ () C:\Users\Christian\Downloads\Windows6.1-KB958830-x86-RefreshPkg.msu
2014-07-27 15:02 - 2014-07-27 15:02 - 00003132 _____ () C:\Windows\System32\Tasks\{921BBC8D-8938-456B-B469-E310D9DA4059}
2014-07-27 10:46 - 2014-07-27 10:49 - 05125829 _____ () C:\Users\Christian\Downloads\ccsetup416.zip
2014-07-27 09:51 - 2014-07-27 09:51 - 00000017 _____ () C:\Users\Christian\AppData\Local\resmon.resmoncfg
2014-07-26 22:30 - 2014-07-26 22:30 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Local\Acer
2014-07-26 22:29 - 2014-07-26 22:29 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Roaming\CyberLink
2014-07-26 22:29 - 2014-07-26 22:29 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Local\PowerCinema
2014-07-26 22:28 - 2014-07-26 22:28 - 00000680 __RSH () C:\Users\Elisabeth_Franz\ntuser.pol
2014-07-26 22:27 - 2014-07-26 22:28 - 00000000 ____D () C:\Users\Elisabeth_Franz
2014-07-26 22:27 - 2014-07-26 22:27 - 00000020 ___SH () C:\Users\Elisabeth_Franz\ntuser.ini
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Vorlagen
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Startmenü
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Netzwerkumgebung
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Lokale Einstellungen
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Eigene Dateien
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Druckumgebung
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Documents\Eigene Musik
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Documents\Eigene Bilder
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\AppData\Local\Verlauf
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\AppData\Local\Anwendungsdaten
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Anwendungsdaten
2014-07-26 22:27 - 2014-02-17 15:30 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Roaming\Genie9
2014-07-26 22:27 - 2013-09-23 16:19 - 00000000 ____D () C:\Users\Elisabeth_Franz\Documents\Visual Studio 2010
2014-07-26 22:27 - 2011-11-16 10:30 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Local\Microsoft Help
2014-07-26 22:27 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Elisabeth_Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-26 22:27 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Elisabeth_Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-26 13:51 - 2014-07-26 13:51 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-07-26 13:51 - 2014-07-26 13:51 - 00068608 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-07-26 13:51 - 2014-07-26 13:51 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-07-26 13:51 - 2014-07-26 13:51 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-07-26 13:48 - 2014-07-26 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data InternetSecurity CBE
2014-07-25 12:16 - 2014-07-25 12:16 - 00000017 _____ () C:\Windows\SysWOW64\shortcut_ex.dat
2014-07-25 00:54 - 2014-07-25 00:54 - 00007120 ____N () C:\bootsqm.dat
2014-07-23 16:01 - 2014-07-23 16:12 - 00000000 ____D () C:\ProgramData\UcusIkcic
2014-07-14 15:04 - 2014-07-14 15:04 - 00000000 ____D () C:\Users\Christian\AppData\Local\G DATA
2014-07-11 20:13 - 2014-07-11 20:13 - 00000000 ____D () C:\Users\Christian\AppData\Local\National Instruments
2014-07-11 19:48 - 2014-07-13 13:04 - 00000000 ____D () C:\Program Files\National Instruments
2014-07-11 19:40 - 2014-07-13 14:57 - 00000000 ____D () C:\Program Files (x86)\National Instruments
2014-07-11 19:38 - 2014-07-13 14:55 - 00000000 ____D () C:\ProgramData\National Instruments
2014-07-11 18:57 - 2014-07-29 15:14 - 00000000 ____D () C:\Users\Christian\Downloads\Programmierung
2014-07-10 20:11 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 20:11 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 20:11 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 20:11 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 20:10 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 20:10 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 20:10 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 20:10 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 20:09 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 20:09 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 20:09 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 20:09 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 20:09 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 20:09 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 20:09 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 20:09 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 20:09 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 20:09 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 20:09 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 20:09 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 20:09 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 20:09 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 20:09 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 20:09 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 20:09 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 20:09 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 20:09 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 20:09 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 20:09 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 20:09 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 20:09 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 20:09 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 20:09 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 20:09 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 20:09 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 20:09 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 20:09 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 20:09 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 20:09 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 20:09 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 20:09 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 20:09 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 20:09 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 20:09 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 20:09 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 20:09 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 20:09 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 20:09 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 20:09 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 20:09 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 20:09 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 20:09 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 20:09 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 20:09 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 20:09 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 20:09 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 20:09 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 20:09 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 20:09 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 20:09 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 20:09 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 20:09 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 20:09 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 20:09 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 20:08 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 20:08 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 20:08 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-02 20:17 - 2014-07-16 20:40 - 00000000 ____D () C:\Users\Christian\Documents\Steganos Safe
2014-07-02 19:53 - 2014-07-04 22:11 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Steganos
2014-07-02 19:52 - 2014-07-02 19:54 - 00000000 ____D () C:\Program Files (x86)\Steganos Safe 14
2014-07-02 19:52 - 2014-07-02 19:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Safe 14
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-07-31 10:38 - 2014-07-31 10:36 - 00017052 _____ () C:\Users\Christian\Desktop\FRST.txt
2014-07-31 10:37 - 2014-07-27 16:13 - 00000000 ____D () C:\FRST
2014-07-31 10:36 - 2014-07-31 10:36 - 00000000 ____D () C:\Users\Christian\Desktop\FRST-OlderVersion
2014-07-31 10:36 - 2014-07-27 16:13 - 02094080 _____ (Farbar) C:\Users\Christian\Desktop\FRST64.exe
2014-07-31 10:32 - 2014-07-31 10:32 - 00009329 _____ () C:\Users\Christian\Desktop\JRT.txt
2014-07-31 10:05 - 2014-07-31 10:05 - 00000000 ____D () C:\Windows\ERUNT
2014-07-31 09:58 - 2014-07-31 09:58 - 01016261 _____ (Thisisu) C:\Users\Christian\Desktop\JRT.exe
2014-07-31 09:56 - 2011-06-05 01:18 - 00000000 ____D () C:\ProgramData\clear.fi
2014-07-31 09:50 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-31 09:50 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-31 09:43 - 2014-07-28 17:22 - 00000616 _____ () C:\Windows\setupact.log
2014-07-31 09:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-31 09:42 - 2014-07-28 17:21 - 00015494 _____ () C:\Windows\PFRO.log
2014-07-31 09:41 - 2011-01-22 14:54 - 01235655 _____ () C:\Windows\WindowsUpdate.log
2014-07-31 09:40 - 2014-07-31 09:33 - 00000000 ____D () C:\AdwCleaner
2014-07-31 09:33 - 2013-11-11 18:05 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0752838C-B6C1-4564-9B69-B9E251C01A13}
2014-07-31 09:32 - 2014-07-31 09:32 - 01361309 _____ () C:\Users\Christian\Desktop\adwcleaner_3.302.exe
2014-07-30 22:22 - 2011-01-22 23:41 - 00708520 _____ () C:\Windows\system32\perfh007.dat
2014-07-30 22:22 - 2011-01-22 23:41 - 00153568 _____ () C:\Windows\system32\perfc007.dat
2014-07-30 22:22 - 2009-07-14 07:13 - 01644736 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-30 22:20 - 2014-07-30 22:20 - 00011448 _____ () C:\Users\Christian\Desktop\mbam.txt
2014-07-30 22:17 - 2014-07-30 20:33 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-30 21:35 - 2014-05-18 11:50 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\CodeBlocks
2014-07-30 21:27 - 2014-06-01 15:43 - 00001196 _____ () C:\Users\Christian\Desktop\Ablage.txt
2014-07-30 21:21 - 2013-09-15 10:14 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\VisualAssist
2014-07-30 21:20 - 2013-09-15 10:13 - 00000000 ____D () C:\Users\Christian\AppData\Local\VisualAssist
2014-07-30 21:17 - 2013-09-15 10:07 - 00000000 ____D () C:\Users\Christian\Documents\Atmel
2014-07-30 20:32 - 2014-07-30 20:32 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-30 20:32 - 2014-07-30 20:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-30 20:32 - 2014-07-30 20:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-30 20:32 - 2014-07-30 20:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-30 20:30 - 2014-07-30 20:29 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christian\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-29 21:55 - 2014-07-28 17:33 - 00000680 __RSH () C:\Users\Elisabeth & Franz.Christian-PC\ntuser.pol
2014-07-29 21:55 - 2014-07-28 17:31 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC
2014-07-29 20:14 - 2011-07-15 18:00 - 00000000 ___RD () C:\Users\Christian\Desktop\Mein_Zimmer
2014-07-29 20:04 - 2014-07-29 20:04 - 00000000 ___SD () C:\ComboFix
2014-07-29 20:04 - 2014-07-29 17:46 - 00000000 ____D () C:\Qoobox
2014-07-29 19:58 - 2014-07-29 19:58 - 00028816 _____ () C:\ComboFix.txt
2014-07-29 19:58 - 2014-04-23 15:42 - 00000000 ____D () C:\Users\dub_cm_auto
2014-07-29 19:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-29 19:50 - 2014-07-29 17:43 - 00000000 ____D () C:\Windows\erdnt
2014-07-29 19:41 - 2011-11-06 18:24 - 00000680 __RSH () C:\Users\Christian\ntuser.pol
2014-07-29 19:41 - 2011-06-04 21:45 - 00000000 ____D () C:\Users\Christian
2014-07-29 19:41 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-29 17:41 - 2014-07-29 17:40 - 05563986 ____R (Swearware) C:\Users\Christian\Desktop\ComboFix.exe
2014-07-29 15:14 - 2014-07-11 18:57 - 00000000 ____D () C:\Users\Christian\Downloads\Programmierung
2014-07-29 11:13 - 2014-07-28 17:09 - 00002782 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-07-29 10:55 - 2014-07-29 10:56 - 00321448 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-29 10:55 - 2014-07-29 10:55 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-29 10:55 - 2014-07-29 10:55 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-29 10:55 - 2014-07-29 10:55 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-29 10:55 - 2014-07-29 10:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-29 10:54 - 2014-07-29 10:54 - 00000000 ____D () C:\Program Files\Java
2014-07-29 10:46 - 2014-03-20 15:49 - 00014265 _____ () C:\Users\Christian\Desktop\Zeugnisse.xlsx
2014-07-29 10:40 - 2014-07-29 10:40 - 00000000 ____D () C:\Users\Christian\.structorizer
2014-07-28 17:41 - 2014-07-28 17:41 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Acer
2014-07-28 17:39 - 2014-07-28 17:38 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Microsoft Games
2014-07-28 17:38 - 2014-07-28 17:38 - 00000622 _____ () C:\Users\Elisabeth & Franz.Christian-PC\Desktop\Solitär.lnk
2014-07-28 17:37 - 2014-07-28 17:37 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Duden
2014-07-28 17:36 - 2014-07-28 17:36 - 00166880 _____ () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-28 17:36 - 2014-07-28 17:36 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Macromedia
2014-07-28 17:36 - 2014-07-28 17:36 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Adobe
2014-07-28 17:35 - 2014-07-28 17:35 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Google
2014-07-28 17:33 - 2014-07-28 17:33 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\CyberLink
2014-07-28 17:33 - 2014-07-28 17:33 - 00000000 ____D () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\PowerCinema
2014-07-28 17:31 - 2014-07-28 17:31 - 00000020 ___SH () C:\Users\Elisabeth & Franz.Christian-PC\ntuser.ini
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Vorlagen
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Startmenü
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Netzwerkumgebung
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Lokale Einstellungen
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Eigene Dateien
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Druckumgebung
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Documents\Eigene Musik
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Documents\Eigene Bilder
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Verlauf
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\AppData\Local\Anwendungsdaten
2014-07-28 17:31 - 2014-07-28 17:31 - 00000000 _SHDL () C:\Users\Elisabeth & Franz.Christian-PC\Anwendungsdaten
2014-07-28 17:22 - 2014-07-28 17:22 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-28 17:15 - 2013-08-17 14:19 - 00000000 ____D () C:\Users\Christian\Documents\CCleaner_Registry
2014-07-28 17:09 - 2014-07-28 17:09 - 00000000 ____D () C:\Program Files\CCleaner
2014-07-28 17:09 - 2011-12-14 15:47 - 00000000 ___RD () C:\Users\Christian\Desktop\Programme
2014-07-28 17:07 - 2014-07-28 17:07 - 04813544 _____ (Piriform Ltd) C:\Users\Christian\Downloads\ccsetup416.exe
2014-07-28 16:59 - 2011-07-02 12:55 - 00000000 ___HD () C:\Program Files (x86)\InstallJammer Registry
2014-07-28 16:54 - 2011-07-02 13:03 - 00000000 ___RD () C:\Users\Christian\Desktop\Spiele
2014-07-28 15:30 - 2011-07-16 11:18 - 00000000 ____D () C:\ProgramData\Spreng- und Abriss-Simulator
2014-07-28 15:15 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-07-28 15:01 - 2010-12-02 10:24 - 00000000 ____D () C:\Program Files (x86)\Acer GameZone
2014-07-28 14:56 - 2010-12-02 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone
2014-07-28 14:21 - 2010-12-02 10:13 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-28 13:56 - 2014-07-28 13:56 - 00000573 _____ () C:\Users\Christian\Desktop\Programmers Notepad [WinAVR].lnk
2014-07-28 13:06 - 2011-06-05 13:25 - 00000000 ___RD () C:\Users\Christian\Desktop\Sonstiges
2014-07-28 12:44 - 2014-07-28 12:44 - 00106272 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys
2014-07-28 12:44 - 2014-07-28 12:44 - 00018160 _____ (G Data Software) C:\Windows\system32\Drivers\GdPhyMem.sys
2014-07-28 11:57 - 2014-07-28 11:57 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-28 11:56 - 2014-07-28 11:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Christian\Downloads\revosetup95.exe
2014-07-28 11:45 - 2013-03-14 22:38 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-28 11:45 - 2013-03-14 22:38 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-27 18:26 - 2013-03-14 22:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-27 16:00 - 2014-07-27 15:54 - 251170997 _____ () C:\Users\Christian\Downloads\Windows6.1-KB958830-x64-RefreshPkg.msu
2014-07-27 15:50 - 2014-07-27 15:44 - 241162581 _____ () C:\Users\Christian\Downloads\Windows6.1-KB958830-x86-RefreshPkg.msu
2014-07-27 15:37 - 2011-06-04 21:45 - 00166880 _____ () C:\Users\Christian\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-27 15:33 - 2012-04-05 12:06 - 00000000 ____D () C:\Program Files (x86)\K-3D 0.8.0.1
2014-07-27 15:14 - 2014-06-10 18:00 - 00000000 ____D () C:\Program Files (x86)\Drakensang - Am Fluss der Zeit
2014-07-27 15:14 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-07-27 15:13 - 2014-06-12 19:23 - 00000000 ____D () C:\Users\Christian\Documents\Drakensang_TRoT
2014-07-27 15:06 - 2009-07-14 06:45 - 00567864 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-27 15:02 - 2014-07-27 15:02 - 00003132 _____ () C:\Windows\System32\Tasks\{921BBC8D-8938-456B-B469-E310D9DA4059}
2014-07-27 14:24 - 2013-09-29 18:58 - 00000000 ____D () C:\Program Files (x86)\RapidSolution
2014-07-27 14:24 - 2011-12-10 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 9
2014-07-27 11:01 - 2013-05-16 18:01 - 00000000 ____D () C:\Users\Christian\AppData\Local\CrashDumps
2014-07-27 10:49 - 2014-07-27 10:46 - 05125829 _____ () C:\Users\Christian\Downloads\ccsetup416.zip
2014-07-27 09:51 - 2014-07-27 09:51 - 00000017 _____ () C:\Users\Christian\AppData\Local\resmon.resmoncfg
2014-07-27 09:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-07-27 09:47 - 2012-06-04 09:20 - 00000000 ____D () C:\Users\Christian\Documents\Outlook-Dateien
2014-07-26 22:30 - 2014-07-26 22:30 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Local\Acer
2014-07-26 22:29 - 2014-07-26 22:29 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Roaming\CyberLink
2014-07-26 22:29 - 2014-07-26 22:29 - 00000000 ____D () C:\Users\Elisabeth_Franz\AppData\Local\PowerCinema
2014-07-26 22:28 - 2014-07-26 22:28 - 00000680 __RSH () C:\Users\Elisabeth_Franz\ntuser.pol
2014-07-26 22:28 - 2014-07-26 22:27 - 00000000 ____D () C:\Users\Elisabeth_Franz
2014-07-26 22:27 - 2014-07-26 22:27 - 00000020 ___SH () C:\Users\Elisabeth_Franz\ntuser.ini
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Vorlagen
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Startmenü
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Netzwerkumgebung
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Lokale Einstellungen
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Eigene Dateien
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Druckumgebung
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Documents\Eigene Musik
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Documents\Eigene Bilder
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\AppData\Local\Verlauf
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\AppData\Local\Anwendungsdaten
2014-07-26 22:27 - 2014-07-26 22:27 - 00000000 _SHDL () C:\Users\Elisabeth_Franz\Anwendungsdaten
2014-07-26 13:51 - 2014-07-26 13:51 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys
2014-07-26 13:51 - 2014-07-26 13:51 - 00068608 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys
2014-07-26 13:51 - 2014-07-26 13:51 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys
2014-07-26 13:51 - 2014-07-26 13:51 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys
2014-07-26 13:50 - 2014-05-17 15:17 - 00000000 ____D () C:\ProgramData\G Data
2014-07-26 13:48 - 2014-07-26 13:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\G Data InternetSecurity CBE
2014-07-26 13:41 - 2014-05-17 15:18 - 00000000 ____D () C:\Program Files (x86)\G Data
2014-07-26 13:35 - 2011-11-01 13:55 - 00000000 ____D () C:\Users\Elisabeth & Franz
2014-07-26 13:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup
2014-07-26 13:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2014-07-26 13:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\com
2014-07-25 12:16 - 2014-07-25 12:16 - 00000017 _____ () C:\Windows\SysWOW64\shortcut_ex.dat
2014-07-25 03:22 - 2011-06-04 21:44 - 00000000 ____D () C:\Recovery
2014-07-25 00:54 - 2014-07-25 00:54 - 00007120 ____N () C:\bootsqm.dat
2014-07-24 17:29 - 2014-02-20 17:05 - 00000866 _____ () C:\Windows\system32\ServiceRunSettings.xml
2014-07-24 17:00 - 2009-07-14 06:45 - 00024576 _____ () C:\Windows\system32\umstartup.etl
2014-07-24 06:36 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-23 16:12 - 2014-07-23 16:01 - 00000000 ____D () C:\ProgramData\UcusIkcic
2014-07-16 20:40 - 2014-07-02 20:17 - 00000000 ____D () C:\Users\Christian\Documents\Steganos Safe
2014-07-15 19:12 - 2011-06-05 13:25 - 00000000 ___RD () C:\Users\Christian\Desktop\Französisch
2014-07-14 15:04 - 2014-07-14 15:04 - 00000000 ____D () C:\Users\Christian\AppData\Local\G DATA
2014-07-14 14:54 - 2014-03-20 15:48 - 00028368 _____ () C:\Users\Christian\Desktop\Noten.xlsx
2014-07-14 14:44 - 2012-05-23 16:42 - 00004282 _____ () C:\Users\Christian\AppData\Roaming\LTspiceIV.ini
2014-07-13 14:57 - 2014-07-11 19:40 - 00000000 ____D () C:\Program Files (x86)\National Instruments
2014-07-13 14:55 - 2014-07-11 19:38 - 00000000 ____D () C:\ProgramData\National Instruments
2014-07-13 13:06 - 2014-04-09 19:43 - 00000000 ____D () C:\Users\Christian\Desktop\Wirtschaft und Recht
2014-07-13 13:04 - 2014-07-11 19:48 - 00000000 ____D () C:\Program Files\National Instruments
2014-07-11 20:13 - 2014-07-11 20:13 - 00000000 ____D () C:\Users\Christian\AppData\Local\National Instruments
2014-07-11 18:50 - 2013-07-18 14:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-11 18:36 - 2009-07-14 09:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 18:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-11 18:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-11 15:11 - 2011-06-04 21:41 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-11 14:54 - 2011-07-17 09:15 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-04 22:11 - 2014-07-02 19:53 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Steganos
2014-07-04 13:45 - 2014-06-10 17:14 - 00000000 ____D () C:\Windows\system32\{F4298088-7F22-4808-98AC-50A36B17C7A9}
2014-07-02 19:54 - 2014-07-02 19:52 - 00000000 ____D () C:\Program Files (x86)\Steganos Safe 14
2014-07-02 19:53 - 2014-07-02 19:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steganos Safe 14
2014-07-02 16:18 - 2012-12-14 18:45 - 00000000 ___RD () C:\Users\Christian\Desktop\Ministranten
Some content of TEMP:
====================
C:\Users\Christian\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-26 22:17
==================== End Of Log ============================ --- --- ---
--- --- --- |