Samichlausi | 02.11.2014 14:40 | Hallo, hier die Logs: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 02.11.2014
Scan Time: 12:53:26
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.02.03
Rootkit Database: v2014.11.01.02
License: Trial
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Steinchen
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 322702
Time Elapsed: 18 min, 41 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 13
PUP.Optional.Snapdo.T, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [ed0ee84e7408a4926a51886040c2cb35],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Quarantined, [ed0ee84e7408a4926a51886040c2cb35],
PUP.Optional.SweetPacks.A, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EEE6C360-6118-11DC-9C72-001320C79847}, Quarantined, [8c6f73c3710bd264f6c6c820fe04916f],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, Quarantined, [82791a1c522ab97d7018a63fc240649c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, Quarantined, [708bc76f34480f275c2da93c5da5c937],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, Quarantined, [d02b62d4ee8eb97d3a74a5bdf60dd927],
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\istartsurfSoftware, Quarantined, [21daa195c0bcdb5b975b81b2748fb44c],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, Quarantined, [29d2f6405d1ffe38e09f3e115ca7936d],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM, Quarantined, [f4075adc0973d264d21384f4ab59728e],
PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, Quarantined, [36c58fa7a0dc280e5827490616eddb25],
PUP.Optional.InstallBrain.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT, Quarantined, [0fec7cba2a520c2aad4cc7b7c53f1be5],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, Quarantined, [8d6e3ef8611b22146f405b073cc7f50b],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [6992181e3547da5ce917c190956e60a0],
Registry Values: 9
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, Quarantined, [e21981b5106cee483445228950b27a86],
PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, Quarantined, [e21981b5106cee483445228950b27a86]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, Quarantined, [e21981b5106cee483445228950b27a86]
PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, Quarantined, [6695f0462b51c274b2c70aa1976b48b8],
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [cc2ff73f1d5f092d72692808cb38827e]
PUP.Optional.Incredibar, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\Web Assistant\Firefox, Quarantined, [ce2d46f09ce096a0e17dcab96a9a22de]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\SWEETIM|simapp_id, 92544983462568424, Quarantined, [f4075adc0973d264d21384f4ab59728e]
PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\Web Assistant\Firefox, Quarantined, [2ad144f2601c30068dd10a79a3611ee2]
PUP.Optional.InstallBrain.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT|URL, MYSTART, Quarantined, [0fec7cba2a520c2aad4cc7b7c53f1be5]
Registry Data: 4
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013),Replaced,[38c3f83e225a1b1becabc566877ee818]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013),Replaced,[e11ab581126af145801ccc5f1ce94eb2]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013),Replaced,[e01bca6cacd038fe207d70bb19ec19e7]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-3251651973-3920780798-2598253173-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013, Good: (www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoSoftonicYB&dpid=SnapdoSoftonicYB&co=DE&userid=1dea3003-f1a9-15cb-8a68-98dd91ca1170&searchtype=ds&q={searchTerms}&installDate=24/10/2013),Replaced,[32c9da5c6c10c274f7a108231ce9be42]
Folders: 2
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\LocalLow\Incredibar.com, Quarantined, [db20d95daece53e37bde28eda063c33d],
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\LocalLow\Incredibar.com\incredibar, Quarantined, [db20d95daece53e37bde28eda063c33d],
Files: 55
PUP.Optional.Softonic.A, C:\Users\Steinchen\Downloads\SoftonicDownloader_fuer_free-vimeo-downloader.exe, Quarantined, [3cbf90a6bdbf67cf144a999ec73a8878],
PUP.Optional.Iminent.A, C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage, Quarantined, [c437e74f5b215fd7e5b2c883ae550df3],
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage, Quarantined, [48b3a29423592115afcf113e5ea56c94],
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage-journal, Quarantined, [c53676c0493363d3621cb09f966dad53],
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (user_pref("extensions.incredibar.admin", false);), Replaced,[10eb072f8eee2c0a91634d1f41c414ec]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ferences
/* Do not edit this file.
*
* If ), Replaced,[8d6eac8aa3d9f93d4ba98be172939967]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* If), Replaced,[35c6c175eb911620985c452732d3fa06]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (eferences
/* Do not edit this file.
*
* ), Replaced,[1fdc32047a02a88e27cd591363a28e72]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (eferences
/* Do not edit this file.
*
* If y), Replaced,[21da999d8af2dc5aee063d2f6c99a759]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If yo), Replaced,[19e210268bf13ef833c1d399a461ee12]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ferences
/* Do not edit this file.
*
* If you make), Replaced,[41ba87afabd14ee8c133a2ca84817b85]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you make c), Replaced,[c734b482a9d3f73fc62e4e1e20e501ff]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you make changes to this file w), Replaced,[25d677bf1c6093a3fcf85d0fcf3616ea]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (s file.
*
* If you make changes to this fil), Replaced,[df1cd561acd0c3735f95313b35d0e11f]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (eferences
/* Do not edit this file.
*
* If you make changes to this), Replaced,[19e286b05923b581dd17afbd8c796a96]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: ( this file.
*
* If you make changes to this file while t), Replaced,[56a5a492641842f4d3212349bd48d030]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (/* Do not edit this file.
*
* If you make changes), Replaced,[ae4d77bf512b80b612e2f07c0ef72fd1]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you ), Replaced,[1ae160d6443853e31bd9254725e0b050]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ferences
/* Do not edit this file.
*
* If you make changes ), Replaced,[19e2c76fafcd5dd963913a320df801ff]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (not edit this file.
*
* If you make changes to th), Replaced,[65960c2a542810266a8a9ad238cdc33d]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you m), Replaced,[2bd0bf773646a591dd17571533d2b14f]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* If you ), Replaced,[2ecd15214d2fea4c1ed673f9d1342ed2]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (nces
/* Do not edit this file.
*
* I), Replaced,[58a37fb79fddc274cf25036939ccab55]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (r Preferences
/* Do not edit this file.
*
* If y), Replaced,[6c8f2214dba162d4d2225b11e32208f8]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (s
/* Do not edit this file.
*
* If you make ), Replaced,[9c5f79bd522a1224876de78527de1ce4]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If you make ch), Replaced,[df1c85b1fc803ef88e661d4f38cd867a]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you ma), Replaced,[a2595cda9ce06fc712e2f6760afbce32]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (references
/* Do not edit this file.
*
* If ), Replaced,[cd2e280e4636d85e31c3d09cbb4a04fc]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If you ), Replaced,[01faab8bdaa266d07084d6966b9a9d63]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you mak), Replaced,[807b0531a5d73cfa51a30864dd287c84]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (es
/* Do not edit this file.
*
* If you make changes to), Replaced,[3bc0a492e894d85e965e3636010436ca]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: ( Do not edit this file.
*
* If you make changes t), Replaced,[817a84b2a8d44ee837bdcca044c127d9]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you make changes t), Replaced,[bb40e94d2d4f7fb780744923d5303bc5]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: ( Do not edit this file.
*
* If you make changes to), Replaced,[d229ea4c0a721125d024175529dc1fe1]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (es
/* Do not edit this file.
*
* If you make), Replaced,[fefd70c64c3040f66f853a32c3420bf5]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If you), Replaced,[13e8bd792f4d5adc46ae3d2f18ed6c94]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* If yo), Replaced,[4caff64094e8bb7b5e9679f35ea7e917]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you m), Replaced,[5aa1290d007caa8cd91bbbb1b253fc04]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (nces
/* Do not edit this file.
*
* If you make changes to this file w), Replaced,[1edd4de91c60be789c58caa2ce379c64]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (his file.
*
* If you make changes to this file while the a), Replaced,[6d8ea096631964d2767ed5973fc64ab6]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: ( Do not edit this file.
*
* If you make changes to ), Replaced,[95665bdb621ae94d5b997bf10afbd12f]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (s
/* Do not edit this file.
*
* If you make), Replaced,[53a870c687f5c373886c24484eb736ca]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you ), Replaced,[5c9f5bdb374596a06e86bdaf0104bd43]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If you m), Replaced,[6794280e413b48ee9f555e0ea1645ea2]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If), Replaced,[9e5d6acc3a42261038bcd29a62a3c13f]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (Preferences
/* Do not edit this file.
*
* If you m), Replaced,[da21e650dba189ad866e73f918edb947]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you make chan), Replaced,[3bc093a3611bcf6745afa0cc60a5f907]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you make change), Replaced,[e51654e2a5d7ce6829cbf47821e4956b]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you make change), Replaced,[6e8d70c6df9d6acc24d04f1db74e19e7]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you make), Replaced,[d22939fd0874c96df004323a1ee7fd03]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (nces
/* Do not edit this file.
*
* If you make ch), Replaced,[847782b49ae21d199c5897d57f86a759]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you make changes to thi), Replaced,[9368e155d6a653e321d31755cb3a3dc3]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (o not edit this file.
*
* If you make changes to th), Replaced,[e912ce68d4a863d3bc38ce9ef114ba46]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (s
/* Do not edit this file.
*
* If you make changes to th), Replaced,[2dcea88ed4a833039d57472557aebf41]
PUP.Optional.Incredibar.A, C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\prefs.js, Good: (), Bad: (o not edit this file.
*
* If you make changes to thi), Replaced,[7b80e650a3d90c2a09ebc9a39273cd33]
Physical Sectors: 0
(No malicious items detected)
(end) ADWCleaner: Code:
# AdwCleaner v4.002 - Bericht erstellt am 02/11/2014 um 13:33:17
# DB v2014-10-26.6
# Aktualisiert 27/10/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Steinchen - EDDY
# Gestartet von : C:\Users\Steinchen\Desktop\AdwCleaner_4.002.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : AddonsHelper
[#] Dienst Gelöscht : SearchAnonymizer
[#] Dienst Gelöscht : Web Assistant Updater
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\ProgramData\DNSErrorHelper
Ordner Gelöscht : C:\Program Files\driver-soft
Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\HELPER
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\ICQToolbarData
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\OCS
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Program Files\Common Files\Tobit
Ordner Gelöscht : C:\Windows\system32\config\systemprofile\AppData\Roaming\Tobit
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\Tobit
Ordner Gelöscht : C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\Extensions\firejump@firejump.net
Datei Gelöscht : C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
Datei Gelöscht : C:\Users\Steinchen\AppData\LocalLow\SkwConfig.bin
Datei Gelöscht : C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\user.js
***** [ Tasks ] *****
Task Gelöscht : RunAsStdUser Task
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [dnshelp@dnshelp.com]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Ocs_SM]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_arcsoft-webcam-companion_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_arcsoft-webcam-companion_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_magix-video-deluxe-mx_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_magix-video-deluxe-mx_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\Microsoft\IntelliType Pro\AppSpecific\Iminent.exe
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\SweetIM
Schlüssel Gelöscht : HKCU\Software\WNLT
Schlüssel Gelöscht : HKLM\SOFTWARE\Driver-Soft
Schlüssel Gelöscht : HKLM\SOFTWARE\Speedchecker Limited
Schlüssel Gelöscht : HKLM\SOFTWARE\SweetIM
Schlüssel Gelöscht : HKLM\SOFTWARE\Web Assistant
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Genius Professional Edition_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v33.0.2 (x86 de)
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [9839 octets] - [02/11/2014 13:30:42]
AdwCleaner[S0].txt - [9703 octets] - [02/11/2014 13:33:17]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9763 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.5 (10.31.2014:1)
OS: Windows 7 Professional x86
Ran by Steinchen on 02.11.2014 at 14:30:04,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\drivergenius"
~~~ FireFox
Successfully deleted the following from C:\Users\Steinchen\AppData\Roaming\mozilla\firefox\profiles\2kbceid0.default\prefs.js
user_pref("browser.search.defaultengine", "Ask.com");
user_pref("browser.search.defaulturl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.3&q=");
user_pref("browser.search.order.1", "Ask.com");
user_pref("extensions.incredibar.admin", false);
user_pref("extensions.incredibar.aflt", "orgnl");
user_pref("extensions.incredibar.cntry", "DE");
user_pref("extensions.incredibar.dfltLng", "");
user_pref("extensions.incredibar.dfltSrch", false);
user_pref("extensions.incredibar.did", "10665");
user_pref("extensions.incredibar.envrmnt", "production");
user_pref("extensions.incredibar.excTlbr", false);
user_pref("extensions.incredibar.hdrMd5", "0C8C8BFE905BDBC0F7C80EAA8853A141");
user_pref("extensions.incredibar.hmpg", false);
user_pref("extensions.incredibar.id", "ee62b6e500000000000000221584f73b");
user_pref("extensions.incredibar.installerproductid", "26");
user_pref("extensions.incredibar.instlDay", "15512");
user_pref("extensions.incredibar.instlRef", "");
user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.141:05:56");
user_pref("extensions.incredibar.mntrvrsn", "1.2.0");
user_pref("extensions.incredibar.newTab", false);
user_pref("extensions.incredibar.noFFXTlbr", false);
user_pref("extensions.incredibar.ppd", "");
user_pref("extensions.incredibar.prdct", "incredibar");
user_pref("extensions.incredibar.productid", "26");
user_pref("extensions.incredibar.prtnrId", "Incredibar");
user_pref("extensions.incredibar.sg", "none");
user_pref("extensions.incredibar.smplGrp", "none");
user_pref("extensions.incredibar.tlbrId", "base");
user_pref("extensions.incredibar.upn2", "6OyFFitFpf");
user_pref("extensions.incredibar.upn2n", "92261626097586969");
user_pref("extensions.incredibar.vrsn", "1.5.11.14");
user_pref("extensions.incredibar.vrsnTs", "1.5.11.141:05:56");
user_pref("extensions.incredibar.vrsni", "1.5.11.14");
user_pref("extensions.incredibar_i.aflt", "orgnl");
user_pref("extensions.incredibar_i.dfltLng", "");
user_pref("extensions.incredibar_i.did", "10665");
user_pref("extensions.incredibar_i.excTlbr", false);
user_pref("extensions.incredibar_i.id", "ee62b6e500000000000000221584f73b");
user_pref("extensions.incredibar_i.installerproductid", "26");
user_pref("extensions.incredibar_i.instlDay", "15512");
user_pref("extensions.incredibar_i.instlRef", "");
user_pref("extensions.incredibar_i.ms_url_id", "");
user_pref("extensions.incredibar_i.newTab", false);
user_pref("extensions.incredibar_i.ppd", "");
user_pref("extensions.incredibar_i.prdct", "incredibar");
user_pref("extensions.incredibar_i.productid", "26");
user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
user_pref("extensions.incredibar_i.smplGrp", "none");
user_pref("extensions.incredibar_i.tlbrId", "base");
user_pref("extensions.incredibar_i.upn2", "6OyFFitFpf");
user_pref("extensions.incredibar_i.upn2n", "92261626097586969");
user_pref("extensions.incredibar_i.vrsn", "1.5.11.14");
user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.141:05:56");
user_pref("extensions.incredibar_i.vrsni", "1.5.11.14");
user_pref("extensions.qipu.exceptions", "{\"conrad.de\":\"/\",\"zalando.de\":\"/\",\"vodafone.de\":\"/\",\"audible.de\":\"/\",\"baur.de\":\"/\",\"ebrosia.de\":\"/\",\"myprinti
user_pref("extensions.searchya.admin", false);
user_pref("extensions.searchya.aflt", "foxtab");
user_pref("extensions.searchya.autoRvrt", "false");
user_pref("extensions.searchya.cntry", "DE");
user_pref("extensions.searchya.dfltLng", "EN");
user_pref("extensions.searchya.dfltSrch", true);
user_pref("extensions.searchya.excTlbr", false);
user_pref("extensions.searchya.hdrMd5", "9B9F489E48E6581989A2901274106F6A");
user_pref("extensions.searchya.hmpg", true);
user_pref("extensions.searchya.id", "f64ccc4600000000000000ff4535c581");
user_pref("extensions.searchya.instlDay", "15436");
user_pref("extensions.searchya.instlRef", "tst-215");
user_pref("extensions.searchya.isDcmntCmplt", true);
user_pref("extensions.searchya.lastVrsnTs", "1.5.20.215:56:11");
user_pref("extensions.searchya.mntrvrsn", "1.2.0");
user_pref("extensions.searchya.newTab", true);
user_pref("extensions.searchya.newTabUrl", "hxxp://searchya.com/?chnl=tst-215&s=2&cr=1875887416&cd=2XzutAtN2Y1L1QzutDtD0F0FyEyDtAyD0CyDzztC0C0CyEyCtN0D0TzutBtDtCtBtDyEtDyC");
user_pref("extensions.searchya.prdct", "searchya");
user_pref("extensions.searchya.propectorlck", 78880743);
user_pref("extensions.searchya.prtkHmpg", 1);
user_pref("extensions.searchya.prtnrId", "ironsrc");
user_pref("extensions.searchya.sg", "none");
user_pref("extensions.searchya.smplGrp", "none");
user_pref("extensions.searchya.srchPrvdr", "SearchYa!");
user_pref("extensions.searchya.tlbrId", "base");
user_pref("extensions.searchya.tlbrSrchUrl", "hxxp://searchya.com/?chnl=tst-215&s=3&cr=1875887416&cd=2XzutAtN2Y1L1QzutDtD0F0FyEyDtAyD0CyDzztC0C0CyEyCtN0D0TzutBtDtCtBtDyEtDyC&q
user_pref("extensions.searchya.vrsn", "1.5.20.2");
user_pref("extensions.searchya.vrsnTs", "1.5.20.215:56:11");
user_pref("extensions.searchya.vrsni", "1.5.20.2");
user_pref("extensions.searchya_i.dfltSrch", true);
user_pref("extensions.searchya_i.dnsErr", true);
user_pref("extensions.searchya_i.hmpg", true);
user_pref("extensions.searchya_i.hmpgUrl", "hxxp://searchya.com/?chnl=tst-215&s=0&cr=1875887416&cd=2XzutAtN2Y1L1QzutDtD0F0FyEyDtAyD0CyDzztC0C0CyEyCtN0D0TzutBtDtCtBtDyEtDyC");
user_pref("extensions.searchya_i.newTab", true);
user_pref("extensions.searchya_i.smplGrp", "none");
user_pref("extensions.searchya_i.vrsnTs", "1.5.20.215:56:11");
user_pref("icqtoolbar.numberOfSearches", 0);
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent101", "1361024312734");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent109", "1361029153359");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent111", "1361029153364");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent112", "1361029169072");
user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent122", "1361029153369");
user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb165/?a=6Oz93zLJv4&i=26&loc=skw&search=");
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_referrer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://us.yhs4.search.yahoo.com
user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_temp_referer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://us.yhs4.search.yahoo
user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=toolbar|babsrc=tb_ss|invocationType=tb50-ie-aolsoftonic-tbsbox-en-us|invocatio
user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_referrer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://hukd.mydealz.de/profile/
user_pref("{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}.ScriptData_WSG_temp_referer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://hukd.mydealz.de/prof
Emptied folder: C:\Users\Steinchen\AppData\Roaming\mozilla\firefox\profiles\2kbceid0.default\minidumps [1067 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.11.2014 at 14:31:52,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-11-2014
Ran by Steinchen (administrator) on EDDY on 02-11-2014 14:33:39
Running from C:\Users\Steinchen\Downloads
Loaded Profile: Steinchen (Available profiles: Steinchen)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [TrayServer] => C:\Program Files\MAGIX\Video_deluxe_MX_Download-Version\TrayServer_de.exe [90112 2008-08-07] (MAGIX AG)
HKLM\...\Run: [vspdfprsrv.exe] => C:\Program Files\Avanquest\PDF Experte 8 Ultimate\vspdfprsrv.exe [6082560 2012-04-23] (Visagesoft)
HKLM\...\Run: [AmIcoSinglun] => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [233472 2009-07-31] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1549608 2009-08-17] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10996368 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-09] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1093232 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [1668720 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058880 2013-03-28] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXRCV] => C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [642664 2014-05-26] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXSTM] => C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863848 2014-05-26] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [5643176 2014-10-22] (Box, Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [124720 2014-10-09] (Avira Operations GmbH & Co. KG)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-10-01] (Malwarebytes Corporation)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [rfxsrvtray] => D:\Tobit Radio.fx\Client\rfx-tray.exe [1838872 2013-02-07] (Tobit.Software)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [Netdrive] => C:\Program Files\NetDrive\netdrive.exe [2789888 2014-08-06] (Bdrive Inc.)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [Steam] => C:\Program Files\Steam\Steam.exe [1938624 2014-10-21] (Valve Corporation)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Steinchen\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIKBE.EXE [261696 2013-09-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIKBE.EXE [261696 2013-09-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22057568 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\RunOnce: [Report] => C:\AdwCleaner\AdwCleaner[S0].txt [9843 2014-11-02] ()
HKU\S-1-5-21-3251651973-3920780798-2598253173-1000\...\Policies\Explorer: []
HKU\S-1-5-18\...\Run: [RfxSrvTray] => D:\Tobit Radio.fx\Client\rfx-tray.exe [1838872 2013-02-07] (Tobit.Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Radio.fx.LNK
ShortcutTarget: Radio.fx.LNK -> D:\Tobit Radio.fx\Client\rfx-client.exe (Tobit.Software)
ShellIconOverlayIdentifiers: [0000BoxSyncFileLocked] -> {578f4da4-f7b0-391f-96de-5b169c14928a} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [0000BoxSyncNotSynced] -> {e01ad165-79b5-3179-bc48-3c4773323416} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [0000BoxSyncProblem] -> {91b6e11c-f714-309f-a400-6023318dced7} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [0000BoxSyncSynced] -> {f573f8b6-e94b-38c3-b89f-39eb5091043d} => C:\Windows\system32\mscoree.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @graphisoft.com/GDL Web Plug-in -> C:\Program Files\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin -> C:\Users\Steinchen\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012-05-17]
FF Extension: Add Google Search To New Tab Page - C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\Extensions\newtabgoogle@graememcc.co.uk.xpi [2013-02-17]
FF Extension: Qipu Cashbackmelder open beta - C:\Users\Steinchen\AppData\Roaming\Mozilla\Firefox\Profiles\2kbceid0.default\Extensions\toolbar@qipu.de.xpi [2012-09-25]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-05-19]
FF HKLM\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-03-18]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.istartsurf.com/?type=hp&ts=1408176844&from=smt&uid=HitachiXHTS543232L9A300_080725FB0400LEC2868BX"
CHR DefaultSearchKeyword: Default -> mystart.incredibar.com/
CHR DefaultSearchURL: Default -> hxxp://mystart.incredibar.com/mb165/?a=6Oz93zLJv4&i=26&loc=skw&search={searchTerms}
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-14]
CHR Extension: (YouTube) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-18]
CHR Extension: (Google-Suche) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-18]
CHR Extension: (WEB.DE MailCheck) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2013-01-21]
CHR Extension: (Google Wallet) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-10-18]
CHR Extension: (Google Mail) - C:\Users\Steinchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-18]
CHR HKLM\...\Chrome\Extension: [jaogepninmlbinccpbiakcgiolijlllo] - C:\Program Files\1&1 Mail & Media\WEB.DE MailCheck\GC\webde_mailcheck.1.0.crx [2013-01-14]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 ABBYY.Licensing.FineReader.ScreenshotReader.9.0; C:\Program Files\ABBYY Screenshot Reader\NetworkLicenseServer.exe [759048 2009-05-15] (ABBYY)
S2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-09] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-09] (Avira Operations GmbH & Co. KG)
S2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [162096 2014-10-09] (Avira Operations GmbH & Co. KG)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [28184 2014-10-13] (Box, Inc.)
S2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [126128 2012-05-16] (Seiko Epson Corporation)
S2 EPSON_EB_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [156160 2011-01-11] (SEIKO EPSON CORPORATION)
S2 EPSON_PM_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [125440 2011-01-11] (SEIKO EPSON CORPORATION)
S2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 FlexNet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1064312 2013-10-02] (Flexera Software LLC)
S2 HTCMonitorService; C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-10] (Nero AG)
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
S2 ndsvc; C:\Program Files\NetDrive\ndsvc.exe [2088960 2013-02-25] (Bdrive Inc.) [File not signed]
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [36352 2010-11-08] () [File not signed]
S2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
S2 Radio.fx; D:\Tobit Radio.fx\Server\rfx-server.exe [3999512 2013-06-03] ()
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-09] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-09] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-05-19] (DT Soft Ltd)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [56320 2009-03-09] (ITE Tech. Inc. )
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-02] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2007-07-31] (ATK0100)
S3 ndfs; C:\Program Files\NetDrive\ndfs.sys [48352 2013-02-01] (Bdrive Inc.)
R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [45968 2011-11-03] (Rovi Corporation)
S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26112 2010-11-08] (The OpenVPN Project)
S2 adfs; No ImagePath
S3 catchme; \??\C:\Users\STEINC~1\AppData\Local\Temp\catchme.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-02 14:33 - 2014-11-02 14:33 - 00000000 ____D () C:\Users\Steinchen\Downloads\FRST-OlderVersion
2014-11-02 14:31 - 2014-11-02 14:31 - 00008026 _____ () C:\Users\Steinchen\Desktop\JRT.txt
2014-11-02 14:30 - 2014-11-02 14:30 - 00000000 ____D () C:\Windows\ERUNT
2014-11-02 14:29 - 2014-11-02 13:33 - 00009843 _____ () C:\Users\Steinchen\Desktop\AdwCleaner[S0].txt
2014-11-02 13:30 - 2014-11-02 13:33 - 00000000 ____D () C:\AdwCleaner
2014-11-02 13:29 - 2014-11-02 13:29 - 00020001 _____ () C:\Users\Steinchen\Desktop\mbam.txt
2014-11-02 12:52 - 2014-11-02 13:25 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-02 12:52 - 2014-11-02 12:52 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-02 12:52 - 2014-11-02 12:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-02 12:52 - 2014-11-02 12:52 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-02 12:52 - 2014-11-02 12:52 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-02 12:52 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-02 12:52 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-02 12:52 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-02 12:51 - 2014-11-02 12:50 - 01706359 _____ (Thisisu) C:\Users\Steinchen\Desktop\JRT.exe
2014-11-02 12:51 - 2014-11-02 12:49 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Steinchen\Desktop\mbam-setup-2.0.3.1025.exe
2014-11-02 12:51 - 2014-11-02 12:49 - 01998336 _____ () C:\Users\Steinchen\Desktop\AdwCleaner_4.002.exe
2014-11-02 12:49 - 2014-11-02 12:50 - 01706359 _____ (Thisisu) C:\Users\Steinchen\Downloads\JRT.exe
2014-11-02 12:49 - 2014-11-02 12:49 - 01998336 _____ () C:\Users\Steinchen\Downloads\AdwCleaner_4.002.exe
2014-11-02 12:48 - 2014-11-02 12:49 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Steinchen\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-01 16:33 - 2014-11-01 16:33 - 00017872 _____ () C:\ComboFix.txt
2014-11-01 16:17 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-01 16:17 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-01 16:17 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-01 16:17 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-01 16:17 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-01 16:17 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-01 16:17 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-01 16:17 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-01 16:09 - 2014-11-01 16:33 - 00000000 ____D () C:\Qoobox
2014-11-01 16:08 - 2014-11-01 16:31 - 00000000 ____D () C:\Windows\erdnt
2014-11-01 16:05 - 2014-11-01 16:06 - 05591672 ____R (Swearware) C:\Users\Steinchen\Desktop\ComboFix.exe
2014-10-31 18:26 - 2014-10-31 18:26 - 00001278 _____ () C:\Users\Steinchen\Downloads\Gmer.log
2014-10-31 17:49 - 2014-10-31 17:49 - 00036126 _____ () C:\Users\Steinchen\Downloads\Ereignisse Avira Antivir.txt
2014-10-31 17:18 - 2014-10-31 17:18 - 00380416 _____ () C:\Users\Steinchen\Downloads\Gmer-19357.exe
2014-10-31 17:16 - 2014-10-31 17:16 - 00037619 _____ () C:\Users\Steinchen\Downloads\Addition.txt
2014-10-31 17:15 - 2014-11-02 14:33 - 00000906 _____ () C:\Users\Steinchen\Downloads\FRST.txt
2014-10-31 17:14 - 2014-11-02 14:33 - 01105920 _____ (Farbar) C:\Users\Steinchen\Downloads\FRST.exe
2014-10-31 17:14 - 2014-11-02 14:33 - 00000000 ____D () C:\FRST
2014-10-31 17:12 - 2014-10-31 17:13 - 00000550 _____ () C:\Users\Steinchen\Downloads\defogger_disable.log
2014-10-31 17:12 - 2014-10-31 17:12 - 00000156 _____ () C:\Users\Steinchen\defogger_reenable
2014-10-31 17:11 - 2014-10-31 17:11 - 00050477 _____ () C:\Users\Steinchen\Downloads\Defogger.exe
2014-10-31 16:08 - 2014-10-31 13:24 - 194045080 _____ (Kaspersky Lab) C:\Users\Steinchen\Downloads\pure13.0.2.558abcdDE_5372.exe
2014-10-31 15:59 - 2014-10-31 15:59 - 00014146 _____ () C:\Users\Steinchen\Downloads\hijackthis.log
2014-10-31 15:59 - 2014-10-31 13:22 - 00388608 _____ (Trend Micro Inc.) C:\Users\Steinchen\Downloads\HiJackThis204.exe
2014-10-30 17:44 - 2014-10-30 17:45 - 123385433 _____ () C:\Users\Steinchen\Downloads\Ontop-ready%20for%20competition-HD.mp4
2014-10-30 17:22 - 2014-10-30 17:23 - 82796069 _____ () C:\Users\Steinchen\Downloads\OnTop%20-%20Retrospektive-SD.mp4
2014-10-30 15:21 - 2014-10-30 17:04 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-10-28 19:13 - 2014-10-29 22:31 - 00000000 ____D () C:\Users\Steinchen\Neuer Ordner
2014-10-28 17:53 - 2014-10-28 19:10 - 00000000 ____D () C:\Users\Steinchen\Documents\Adobe
2014-10-23 12:24 - 2014-10-23 12:24 - 00001367 _____ () C:\Users\Steinchen\Desktop\Box Sync.lnk
2014-10-23 11:54 - 2014-10-31 12:53 - 00000000 ____D () C:\Users\Steinchen\AppData\Local\Box Sync
2014-10-23 11:53 - 2014-10-30 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync
2014-10-23 11:53 - 2014-10-23 11:53 - 00000000 ____D () C:\Program Files\Box
2014-10-19 21:11 - 2014-10-20 12:31 - 00000000 ____D () C:\Users\Steinchen\Documents\Bewerbung
2014-10-16 15:40 - 2014-10-10 02:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-16 15:40 - 2014-10-10 02:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-16 15:40 - 2014-10-10 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-16 15:40 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-16 15:40 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-16 15:40 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-16 15:40 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-16 15:40 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-16 15:40 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-16 15:40 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-16 15:40 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-16 15:40 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-16 15:40 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-16 15:40 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-16 15:40 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-16 15:40 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-16 15:40 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-16 15:40 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-16 15:40 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-16 15:40 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-16 15:40 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-16 15:40 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-16 15:40 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-16 15:40 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-16 15:40 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-16 15:40 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-16 15:40 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 15:40 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-16 15:40 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-16 15:40 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-16 15:40 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-16 15:40 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-16 15:40 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-16 15:40 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-16 15:40 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-16 15:40 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-16 15:40 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-16 15:40 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-16 15:40 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-16 15:40 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-16 15:40 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-10-16 15:40 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-16 15:40 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-16 15:40 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-16 15:40 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-16 15:40 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-16 15:40 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-16 15:40 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-16 15:40 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-16 15:39 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-16 15:39 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-12 15:05 - 2014-10-12 15:13 - 00000000 ____D () C:\Users\Steinchen\Desktop\Neuer Ordner
2014-10-07 15:51 - 2014-10-07 15:56 - 00000000 ____D () C:\Program Files\PixelNet Software
2014-10-06 16:01 - 2014-10-06 21:41 - 00000000 ____D () C:\Users\Steinchen\Desktop\foro mama
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-02 13:35 - 2013-02-16 15:33 - 00182226 _____ () C:\Windows\PFRO.log
2014-11-02 13:34 - 2013-02-16 15:33 - 00158673 _____ () C:\Windows\setupact.log
2014-11-02 13:13 - 2013-11-12 22:24 - 00000000 ____D () C:\Windows\220FB0354744483A9A0B41DF77061583.TMP
2014-11-02 11:25 - 2013-05-02 10:35 - 03480547 _____ () C:\ndsvc.log
2014-11-02 11:25 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-01 16:33 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-11-01 16:31 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2014-11-01 12:51 - 2010-11-20 22:01 - 00006656 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-31 13:00 - 2012-05-17 13:54 - 01965916 _____ () C:\Windows\WindowsUpdate.log
2014-10-31 12:56 - 2012-05-19 22:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-31 12:53 - 2013-10-02 22:27 - 00000000 ____D () C:\Users\Steinchen\AppData\Local\Akamai
2014-10-31 12:53 - 2013-07-28 11:15 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-10-31 12:53 - 2012-05-17 15:21 - 00000000 ____D () C:\Users\Steinchen\AppData\Roaming\Skype
2014-10-31 12:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\wfp
2014-10-31 12:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\registration
2014-10-31 11:51 - 2009-07-14 05:34 - 00032208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-31 11:51 - 2009-07-14 05:34 - 00032208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-31 11:00 - 2014-09-11 17:00 - 00000917 _____ () C:\Windows\Tasks\EPSON WF-7610 Series Update {0F3E16B0-7BD4-41F6-95F4-F8851B079459}.job
2014-10-31 11:00 - 2014-09-11 17:00 - 00000731 _____ () C:\Windows\Tasks\EPSON WF-7610 Series Invitation {0F3E16B0-7BD4-41F6-95F4-F8851B079459}.job
2014-10-31 10:57 - 2012-10-18 14:21 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-31 10:52 - 2014-09-11 16:52 - 00000917 _____ () C:\Windows\Tasks\EPSON WF-7610 Series Update {D6921944-E3EC-4FB2-94FE-B01E6D22EF38}.job
2014-10-31 10:52 - 2014-09-11 16:52 - 00000731 _____ () C:\Windows\Tasks\EPSON WF-7610 Series Invitation {D6921944-E3EC-4FB2-94FE-B01E6D22EF38}.job
2014-10-30 23:44 - 2009-07-14 03:04 - 00000519 _____ () C:\Windows\win.ini
2014-10-30 23:43 - 2013-06-27 20:27 - 00000000 ____D () C:\Program Files\Steam
2014-10-30 23:42 - 2013-12-09 20:56 - 00000000 ____D () C:\Users\Steinchen\AppData\Local\HTC MediaHub
2014-10-30 23:42 - 2012-10-18 14:21 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-30 13:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-30 13:41 - 2013-02-16 16:18 - 00000000 ____D () C:\Users\Steinchen\AppData\Local\Adobe
2014-10-29 22:00 - 2012-10-31 15:18 - 00000000 ____D () C:\Users\Steinchen\Documents\Gutscheine
2014-10-29 18:06 - 2014-08-04 11:17 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-29 18:06 - 2014-08-04 11:16 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-29 18:06 - 2012-11-15 16:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-29 18:06 - 2012-11-15 16:39 - 00000000 ____D () C:\Program Files\Avira
2014-10-29 14:23 - 2013-05-22 17:05 - 00000002 _____ () C:\studentspace.log
2014-10-28 19:10 - 2013-02-16 15:07 - 00000000 ____D () C:\Users\Steinchen\AppData\Roaming\Adobe
2014-10-28 06:35 - 2012-11-16 10:52 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-23 11:33 - 2014-09-17 19:59 - 00000000 ___RD () C:\Program Files\Skype
2014-10-23 11:33 - 2012-05-17 15:21 - 00000000 ____D () C:\ProgramData\Skype
2014-10-21 20:42 - 2013-04-03 18:08 - 00000000 ____D () C:\Users\Steinchen\Documents\Elster Steuererklärung
2014-10-21 18:37 - 2012-05-28 21:59 - 00000000 ____D () C:\Users\Steinchen\Documents\Arbeit
2014-10-20 13:40 - 2012-05-19 13:33 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-20 13:39 - 2013-05-05 19:29 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-10-20 12:25 - 2012-05-19 19:01 - 00000000 ____D () C:\Users\Steinchen\Documents\AA Studium
2014-10-17 22:59 - 2012-08-13 13:36 - 00000000 ____D () C:\Program Files\Heroes of Newerth
2014-10-17 08:42 - 2014-09-12 09:39 - 00000000 ____D () C:\Windows\rescache
2014-10-17 07:27 - 2012-05-17 14:13 - 00168480 _____ () C:\Users\Steinchen\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-17 07:25 - 2009-07-14 05:33 - 03981864 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-17 07:22 - 2014-05-06 17:23 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-17 07:21 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-10-09 09:32 - 2013-05-02 10:35 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-09 09:32 - 2012-11-15 16:39 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-09 09:32 - 2012-11-15 16:39 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
Some content of TEMP:
====================
C:\Users\Steinchen\AppData\Local\temp\Quarantine.exe
C:\Users\Steinchen\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-26 14:01
==================== End Of Log ============================ --- --- ---
kannst du mir auch sagen was sich da so tut und ob du schon eine Ahnung hast? |