So, dann mal los:
MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 12.11.2014
Scan Time: 19:37:33
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.12.08
Rootkit Database: v2014.11.12.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: purzelchen
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 322101
Time Elapsed: 6 min, 32 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 56
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, , [40a8330734489c9a090e48a761a1b34d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, , [40a8330734489c9a090e48a761a1b34d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, , [ca1e8bafc7b547efeb2d10df1ee432ce],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, , [ca1e8bafc7b547efeb2d10df1ee432ce],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, , [33b57bbfb4c858de75593882639f8a76],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, , [33b57bbfb4c858de75593882639f8a76],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamDownloader.1, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamDownloader, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamDownloader, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamDownloader.1, , [80684cee215b082e96835797aa5817e9],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamBHO.1, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamBHO, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamBHO, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamBHO.1, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.Wajam.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, , [d612d4664d2f4fe7386eba01b250e020],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, , [b92ff4469be171c53525289336cc0af6],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, , [b92ff4469be171c53525289336cc0af6],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, , [b92ff4469be171c53525289336cc0af6],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, , [b92ff4469be171c53525289336cc0af6],
PUP.Optional.Babylon.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [b8309e9c186469cdf8dbeec60ff38b75],
PUP.Optional.EazelBar.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EBD839AE-B08C-4fb7-859B-F54AF16C159F}, , [ab3d1f1b4f2d2412c1bb388112f02ed2],
PUP.Optional.MyScrapNook.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, , [a741e6544c30ff378d0a9956fd056e92],
PUP.Optional.MyScrapNook.A, HKLM\SOFTWARE\CLASSES\TypeLib\{03119103-0854-469D-807A-171568457991}, , [94541b1f2458340235628a65a45eb749],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr, , [c72173c7304c71c5cd2b9b55966c2cd4],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr.1, , [1ccce4563a4270c6b642a749cf33936d],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr, , [1ccce4563a4270c6b642a749cf33936d],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr.1, , [1ccce4563a4270c6b642a749cf33936d],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd, , [50981e1c2557f73f83762dc33bc76a96],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd.1, , [48a0b28880fce84e4dac31bfb74be61a],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd, , [48a0b28880fce84e4dac31bfb74be61a],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd.1, , [48a0b28880fce84e4dac31bfb74be61a],
PUP.Optional.AmazonTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Amazon Browser Settings, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, , [ae3a0238c7b5f541e43c96d9c63d28d8],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\priam_bho.DLL, , [67817ac07dff91a538ccd2b5659faa56],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [678136044834d95d65eb3956fe06b34d],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\BonanzaDealsLive, , [fbeda5952755d264cef6a5e664a008f8],
PUP.Optional.qvo6.A, HKLM\SOFTWARE\WOW6432NODE\qvo6Software, , [6781dd5d5f1d78bed42f8cfa59ab21df],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, , [9652d86235477bbb47d96a05ff0450b0],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\priam_bho.DLL, , [45a32416176585b1d133681f5ba9847c],
PUP.Optional.RobinHood.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\iidmoehhpbghchkaogkhmcckhlhebekn, , [c7211525a8d40e280d286cf2a75c8779],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [04e445f5cbb14fe778d8266928dce719],
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, , [975170ca80fcd0664dc48fdc9d667c84],
PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, , [d117b88286f6e94d2cf1d29d46bd24dc],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, , [9058a595126a3204873b800bfd071ee2],
PUP.Optional.AlexaTB.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars, , [33b5bc7e7ffd9b9b60d192f8c93b10f0],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [e4048caec1bbdc5acab79cd116ed1de3],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, , [28c0e65433492511813aadd65aaac838],
PUP.Optional.Qone8, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [b23697a31666f93d49061b74ac58b050],
Registry Values: 5
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, , [33b57bbfb4c858de75593882639f8a76]
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, , [33b57bbfb4c858de75593882639f8a76]
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, , [3cacef4b8def83b3dcf29822fa083bc5],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, , [f0f8e2587ffd7fb77c5268528a78bf41],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0J1B1O1M1N0U1O1N2T, , [28c0e65433492511813aadd65aaac838]
Registry Data: 3
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[5e8a9d9df488072fe5652322e91cef11]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[17d1e258b0cc67cf80ca4cf9df268977]
PUP.Optional.MaxStart.A, HKU\S-1-5-21-432217040-4276816697-2371958446-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.max-start.com/?babsrc=HP_ss_mib2&mntrId=A6F0162F6878B112&affID=127690&tsp=5183, Good: (www.google.com), Bad: (hxxp://www.max-start.com/?babsrc=HP_ss_mib2&mntrId=A6F0162F6878B112&affID=127690&tsp=5183),,[2abece6cc7b5ae8839675bdf32d3f20e]
Folders: 32
PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log, , [eafeaf8b3b41b185a62be7828083ff01],
PUP.Optional.AmazonTB.A, C:\Users\purzelchen\AppData\Local\Amazon Browser Bar, , [d90f26143b415cda62d076141fe5956b],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive, , [598fbe7c225af2443da072900ff4ad53],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive\Update, , [598fbe7c225af2443da072900ff4ad53],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive\Update\Log, , [598fbe7c225af2443da072900ff4ad53],
PUP.Optional.BonanzaDeals.A, C:\Users\purzelchen\AppData\Local\BonanzaDealsLive, , [5197f446a7d5bc7a1ec01ce605fed32d],
PUP.Optional.BonanzaDeals.A, C:\Users\purzelchen\AppData\Local\BonanzaDealsLive\CrashReports, , [5197f446a7d5bc7a1ec01ce605fed32d],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDealsLive, , [0cdc25154c30f73f07d934ce5fa4d927],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDealsLive\CrashReports, , [0cdc25154c30f73f07d934ce5fa4d927],
PUP.Optional.MindSpark.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\Allin1Convert_8h, , [836575c5522a9f9787be11fade2540c0],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\libraries, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\resources, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Program Files\V-bates, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\content, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\content\libraries, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\content\resources, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\locale, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\locale\en-US, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\skin, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\defaults, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\defaults\preferences, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\libraries, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\resources, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.OnlySearch, C:\Users\purzelchen\AppData\Local\onlysearch, , [eff9360490ec999d15fd5dc9cc37d42c],
PUP.Optional.OnlySearch, C:\Users\purzelchen\AppData\Local\onlysearch\onlysearch, , [eff9360490ec999d15fd5dc9cc37d42c],
PUP.Optional.OnlySearch, C:\Users\purzelchen\AppData\Local\onlysearch\onlysearch\1.3.12.9, , [eff9360490ec999d15fd5dc9cc37d42c],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals, , [757363d7c2ba0b2bb01243e67291f40c],
Files: 81
PUP.Optional.Searchprotect, C:\Program Files (x86)\Amazon Browser Bar\search_protect.exe, , [9c4c47f35626cc6ad0b82c08946dd52b],
PUP.Optional.InstallCore.A, C:\Users\purzelchen\Downloads\FileExtractorSetup.exe, , [10d8b684fc800432b64446be39cc7987],
PUP.Optional.DomaIQ, C:\Users\purzelchen\Downloads\Setup (1).exe, , [16d255e5b4c871c5a83765f60bf503fd],
PUP.Optional.AirAdInstaller, C:\Users\purzelchen\Downloads\setup(1).exe, , [f0f875c58cf07bbb9da21327b050f907],
PUP.Optional.LiveSoftAction.A, C:\Users\purzelchen\Downloads\ARCHOS 70B EREADER user guide provided through pdfretriever.com(1).exe, , [c721fd3d126a52e43d24092b976ac43c],
PUP.Optional.LiveSoftAction.A, C:\Users\purzelchen\Downloads\ARCHOS 70B EREADER user guide provided through pdfretriever.com.exe, , [21c7cd6db0cc181e1b464fe546bbb848],
PUP.Optional.AirAdInstaller, C:\Users\purzelchen\Downloads\setup.exe, , [a8401c1eb2caf5416fd01228fe02bd43],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ljmibnagodajacnnbifpamhggcohblip_0.localstorage, , [ad3bb4863b41af873bd2ba8d4eb534cc],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ljmibnagodajacnnbifpamhggcohblip_0.localstorage-journal, , [c72134066616d85ef01da2a5ee15956b],
PUP.Optional.MindSpark.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\searchplugins\ask-web-search.xml, , [6880a09a92ea9b9b5a8a7dd431d23bc5],
PUP.Optional.Easelbar.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\searchplugins\search-with-eazelbar.xml, , [db0d91a9df9dfa3c0e02223c9b689070],
PUP.Optional.BuenoSearch.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\searchplugins\buenosearch.xml, , [b43426144735ad89f4e40b57927137c9],
PUP.Optional.BuenoSearch.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.buenosearch.com_0.localstorage, , [8a5ed763cfade15593766ff618eb936d],
PUP.Optional.BuenoSearch.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.buenosearch.com_0.localstorage-journal, , [0bdddf5b0a729b9bf317de8748bb2cd4],
PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log\eGdpSvc.LOG, , [eafeaf8b3b41b185a62be7828083ff01],
Stolen.Data, C:\Users\purzelchen\AppData\Roaming\jullli_2012, , [61878eacfa8270c6a6815fed9b6952ae],
PUP.Optional.AmazonTB.A, C:\Users\purzelchen\AppData\Local\Amazon Browser Bar\protect.xml, , [d90f26143b415cda62d076141fe5956b],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.ini, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar\installer.xml, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar\uninstall.ico, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar\uninstall.json, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar\uninstaller.exe, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.AmazonTB.A, C:\Program Files (x86)\Amazon Browser Bar\update.xml, , [d21694a6700c45f1151e96f4857f42be],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive\Update\Log\BonanzaDealsLive.log, , [598fbe7c225af2443da072900ff4ad53],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\background.html, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\logo_128.png, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\main.js, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\main.js.bak, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\manifest.json, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\npbrowserext.dll, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\libraries\ContentScript.js, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\libraries\DataExchangeScript.js, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.436_0\resources\localscript.js, , [24c4f446a1db47ef85b69a816c97f50b],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\unins000.dat, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\icon.png, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\locale\en-US\overlay.dtd, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.Vbates.A, C:\Program Files\V-bates\Firefox\chrome\skin\overlay.css, , [00e8b882c7b537ff3804bf5c669da65a],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\uninst.exe, , [757363d7c2ba0b2bb01243e67291f40c],
PUP.Optional.Eazel.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (user_pref("browser.search.defaulturl", "hxxp://en.eazel.com/results.php?oid=1&id=DAF5A5AA5F624549881415CE11CE2A69&cat=web&co=&lg=en&q={searchTerms}");), ,[2fb9370396e6b086019d3c3d59ac6997]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (user_pref("extensions.buenosearch.admin", false);), ,[50982218cdafa195bbfbd9a324e1ab55]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (ferences
/* Do not edit this file.
*
* If yo), ,[21c7b981621a2313edc90f6d6c997789]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you make changes to this file while t), ,[6880b3879be14de9e9cda9d37c89718f]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (e.
*
* If you make changes to this file while the ), ,[38b0c575a4d8ac8a8630c2ba7095fe02]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you ma), ,[5b8d40fa7a026ec88a2c007cc83d38c8]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* If you), ,[2abe5dddff7d74c2af07dba16c9947b9]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you mak), ,[3cac3efc74081a1c06b03547d23342be]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you make changes to this file w), ,[a741dd5d89f3290dddd90478e71e3cc4]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: ( this file.
*
* If you make changes to this file w), ,[de0aa397413b37ffb7ff1e5e17ee40c0]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you make), ,[af39ed4db4c83006c8ee58247f867789]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If you ), ,[cc1cba80106cec4a9224087412f34cb4]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* If you make ), ,[b2361f1b9be17abc5066285406ff2ed2]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you make changes t), ,[8a5e1d1dcdaf60d62195126a768fbc44]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (
/* Do not edit this file.
*
* If you make ch), ,[3cac59e16418171f4d69d0ac679e52ae]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* If you ), ,[cb1d54e6b2ca74c2b3032b51838206fa]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten whe), ,[03e5102a9fddd363e4d20379b0557d83]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: ( is running,
* the changes will be overwritten wh), ,[20c84af0e99356e0a70f6517b2532dd3]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when th), ,[f1f799a198e45fd79b1bc7b54db827d9]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (unning,
* the changes will be overwritten when the ), ,[d2166ad06517122405b1710b6b9a5ba5]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: (nces
/* Do not edit this file.
*
* If you make changes t), ,[c325d76326566dc9704689f33cc941bf]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\prefs.js, Good: (), Bad: ( Do not edit this file.
*
* If you make changes to), ,[07e127134d2f71c54c6a681412f350b0]
PUP.Optional.BuenoSearch.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A6F0162F6878B112&affID=127690&tsp=5183");), ,[ecfcb5855f1d13238049e09b0ef704fc]
PUP.Optional.BuenoSearch.A, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (earchTerms}&babsrc=TB_ss&mntrId=A6F0162F6878B112&affID=127690&tsp=5183");
user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q=), ,[28c074c68defa2947653ccafbc49c937]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (78B112&affID=127690&tsp=5183");
user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A6F0162F), ,[d5133cfe90ec072ff2c3631990752ad6]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (62F6878B112&affID=127690&tsp=5183");
user_pref("extensions.buenosearch.tb_), ,[c325eb4fe597a2947e3777054bbad927]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (l", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A6F0162F6878B11), ,[34b4d86228545adc03b23547e223f60a]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&m), ,[3dab74c61666a98dd2e34e2ec2436e92]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (uenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/), ,[cf19dc5e95e77bbbddd836469b6a1de3]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/), ,[6b7d1e1c5c2048eec3f2205cd62f01ff]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (uenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={search), ,[c32561d9f4881b1b50650a72917426da]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (h.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms), ,[b83066d486f669cdd9dc82fa1bea3fc1]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (earch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searc), ,[796f39019be1ef47991c1d5ffa0b867a]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (osearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?), ,[a444be7c81fb9c9a268fd0ac53b2bf41]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (s.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.), ,[20c83bff552753e31e97dba174911fe1]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.), ,[3eaa89b10973b97d7b3a601c6f968e72]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch), ,[f5f39aa0cdafd462862f512b83827d83]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (ns.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearc), ,[84641a20d0acce682491710b3acb5ea2]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (s.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.co), ,[08e0ed4d097380b6496ca5d70cf9a957]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (uenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.), ,[a64286b4f08c65d15461215bd5308878]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (ons.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.), ,[a44454e6d5a781b512a35329fe07a957]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (uenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.c), ,[ad3b1c1ebebe95a111a47705a560d22e]
PUP.Optional.BuenoSearch, C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js, Good: (), Bad: (ns.buenosearch.tlbrSrchUrl", "hxxp://www.buenosear), ,[c226f54583f9f2445b5a86f68a7bcc34]
Physical Sectors: 0
(No malicious items detected)
(end) ADWCleaner Code:
# AdwCleaner v4.101 - Bericht erstellt am 12/11/2014 um 19:51:00
# Aktualisiert 09/11/2014 von Xplode
# Database : 2014-11-12.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : purzelchen - PURZELCHEN-PC
# Gestartet von : C:\Users\purzelchen\Desktop\AdwCleaner_4.101.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : wStLibG64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\eSafe
Ordner Gelöscht : C:\Program Files (x86)\iRobinHood
Ordner Gelöscht : C:\Program Files (x86)\PC Cleaner
Ordner Gelöscht : C:\Program Files (x86)\RegClean Pro
Ordner Gelöscht : C:\Users\purzelchen\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\purzelchen\AppData\LocalLow\buenosearch LTD
Ordner Gelöscht : C:\Users\purzelchen\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\purzelchen\AppData\Roaming\UpdaterEX
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\invalidprefs.js
Datei Gelöscht : C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\user.js
Datei Gelöscht : C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\wajam.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gelöscht : HKCU\Software\Classes\keepmysearch
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{53F6A516-3DCC-48F4-835C-6C670CB39CEA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5E58CDA9-3B21-4611-A859-26EE28950E61}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6C5561B6-3DD2-46B5-83BE-EAE744366046}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF}
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\eSafeSecControl
Schlüssel Gelöscht : HKLM\SOFTWARE\SoftwareUpdater
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Vittalia
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}_is1
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v33.0.3 (x86 de)
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.aflt", "babsst");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.autoRvrt", "false");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.dfltLng", "en");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.excTlbr", false);
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.ffxUnstlRst", true);
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.id", "a6f0b0c5000000000000162f6878b112");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.instlDay", "16140");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.instlRef", "sst");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.newTab", false);
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.prdct", "buenosearch");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.rvrt", "false");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.smplGrp", "none");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A6F0162F6878B112&affID=127690&tsp=5183");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.tlbrId", "base");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=A6F0162F6878B112&affID=127690&tsp=5183");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.718:11:25");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.toolbar.mindspark.lastInstalled", "allin1convert@mindspark.com");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("{EBD839AE-B08C-4fb7-859B-F54AF16C159F}.BrowserSearch", "hxxp://en.eazel.com/results.php?oid=1&id=DAF5A5AA5F624549881415CE11CE2A69&cat=web&co=&lg=en&q={searchTerms}");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("{EBD839AE-B08C-4fb7-859B-F54AF16C159F}.Homepage", "hxxp://en.eazel.com?oid=1&id=DAF5A5AA5F624549881415CE11CE2A69");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("{EBD839AE-B08C-4fb7-859B-F54AF16C159F}.ToolbarName", "EazelBar");
[u1lkanrv.default\prefs.js] - Zeile gelöscht : user_pref("{EBD839AE-B08C-4fb7-859B-F54AF16C159F}.UpdateURL", "hxxp://media.eazel.com/xmlbar/EazelBar/LatestVersion.xml");
-\\ Google Chrome v38.0.2125.111
[C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=A6F0162F6878B112&affID=127690&tsp=5183
*************************
AdwCleaner[R0].txt - [9347 octets] - [12/11/2014 19:50:13]
AdwCleaner[S0].txt - [9284 octets] - [12/11/2014 19:51:00]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9344 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.7 (11.08.2014:1)
OS: Windows 7 Home Premium x64
Ran by purzelchen on 12.11.2014 at 19:54:17,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Emptied folder: C:\Users\purzelchen\AppData\Roaming\mozilla\firefox\profiles\u1lkanrv.default\minidumps [178 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.11.2014 at 19:57:32,17
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-11-2014 01
Ran by purzelchen (administrator) on PURZELCHEN-PC on 12-11-2014 19:58:29
Running from C:\Users\purzelchen\Downloads
Loaded Profile: purzelchen (Available profiles: purzelchen)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Sentelic Corporation) C:\Program Files\FSP\FspUip.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe
(Mischel Internet Security) C:\Program Files (x86)\TrojanHunter 5.6\THGuard.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [4285952 2011-06-19] (Sentelic Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2462536 2014-10-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [RoccatKone+] => C:\Program Files (x86)\ROCCAT\Kone[+] Mouse\Kone[+]Monitor.EXE [552960 2011-07-12] (ROCCAT GmbH)
HKLM-x32\...\Run: [FLxHCIm64] => C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [48128 2012-07-19] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [THGuard] => C:\Program Files (x86)\TrojanHunter 5.6\THGuard.exe [1081808 2014-07-30] (Mischel Internet Security)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x35D63A38C2BECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKU\S-1-5-21-432217040-4276816697-2371958446-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL =
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\searchplugins\amazon.xml
FF SearchPlugin: C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\purzelchen\AppData\Roaming\Mozilla\Firefox\Profiles\u1lkanrv.default\searchplugins\google-maps.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.de/
CHR StartupUrls: Default -> "hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_cr_de_display?ie=UTF8&tagbase=bds-p23&tbrId=v1_abb-channel-23_8d4915d1c479416bb8e9f950e100cfd4_39_1006_20140614_DE_cr_sp_adppi15"
CHR DefaultSearchURL: Default -> hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p23_serp_cr_de_display?ie=UTF8&tagbase=bds-p23&tag=bds-p23-serp-de-cr-21&tbrId=v1_abb-channel-23_8d4915d1c479416bb8e9f950e100cfd4_39_1006_20140614_DE_cr_ds_adppi15&query={searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://suggestqueries.google.com/complete/search?q={searchTerms}&output=chrome
CHR Profile: C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-20]
CHR Extension: (Google Wallet) - C:\Users\purzelchen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [105120 2011-09-30] (Atheros Commnucations) [File not signed]
S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-09-19] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-09-19] (BlueStack Systems, Inc.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-10-16] (NVIDIA Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-10-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19439944 2014-10-16] (NVIDIA Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-09-30] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-09-19] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-15] (Disc Soft Ltd)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [132608 2009-06-29] (Huawei Technologies Co., Ltd.)
S3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [117248 2014-05-18] (Huawei Technologies Co., Ltd.) [File not signed]
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [76584 2012-07-19] (Fresco Logic)
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [53760 2011-06-19] (Windows (R) Win 7 DDK provider)
S3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [121600 2014-05-18] (Huawei Technologies Co., Ltd.) [File not signed]
S3 KoneFltr; C:\Windows\System32\drivers\Kone.sys [15488 2008-12-11] (ROCCAT Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-12] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-10-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-10-16] (NVIDIA Corporation)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 ALSysIO; \??\C:\Users\PURZEL~1\AppData\Local\Temp\ALSysIO64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 19:57 - 2014-11-12 19:57 - 00000838 _____ () C:\Users\purzelchen\Documents\JRT.txt
2014-11-12 19:57 - 2014-11-12 19:57 - 00000838 _____ () C:\Users\purzelchen\Desktop\JRT.txt
2014-11-12 19:54 - 2014-11-12 19:54 - 00000000 ____D () C:\Windows\ERUNT
2014-11-12 19:53 - 2014-11-12 19:36 - 01706808 _____ (Thisisu) C:\Users\purzelchen\Desktop\JRT.exe
2014-11-12 19:52 - 2014-11-12 19:52 - 00009504 _____ () C:\Users\purzelchen\Documents\AdwCleaner[S0].txt
2014-11-12 19:50 - 2014-11-12 19:51 - 00000000 ___DC () C:\AdwCleaner
2014-11-12 19:44 - 2014-11-12 19:44 - 00030927 ____C () C:\mbam.txt
2014-11-12 19:37 - 2014-11-12 19:52 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-12 19:36 - 2014-11-12 19:36 - 01706808 _____ (Thisisu) C:\Users\purzelchen\Downloads\JRT.exe
2014-11-12 19:36 - 2014-11-12 19:36 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-12 19:36 - 2014-11-12 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-12 19:36 - 2014-11-12 19:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-12 19:36 - 2014-11-12 19:36 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-12 19:36 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-12 19:36 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-12 19:36 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-12 19:35 - 2014-11-12 19:35 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\purzelchen\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-12 19:35 - 2014-11-12 19:35 - 02140160 _____ () C:\Users\purzelchen\Desktop\AdwCleaner_4.101.exe
2014-11-11 17:09 - 2014-11-11 17:09 - 00017133 ____C () C:\ComboFix.txt
2014-11-11 17:00 - 2014-11-11 17:09 - 00000000 ___DC () C:\Qoobox
2014-11-11 17:00 - 2014-11-11 17:09 - 00000000 ____D () C:\Windows\erdnt
2014-11-11 17:00 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-11 17:00 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-11 17:00 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-11 17:00 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-11 17:00 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-11 17:00 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-11 17:00 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-11 17:00 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-11 16:54 - 2014-11-11 16:54 - 00000000 ___DC () C:\TDSSKiller_Quarantine
2014-11-11 16:51 - 2014-11-11 16:51 - 05598118 ____R (Swearware) C:\Users\purzelchen\Desktop\ComboFix.exe
2014-11-10 15:06 - 2014-11-10 15:06 - 04184008 _____ (Kaspersky Lab ZAO) C:\Users\purzelchen\Downloads\tdsskiller.exe
2014-11-10 14:59 - 2014-11-10 14:59 - 00001226 _____ () C:\Users\purzelchen\Desktop\Revo Uninstaller.lnk
2014-11-10 14:59 - 2014-11-10 14:59 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-11-10 14:58 - 2014-11-10 14:58 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\purzelchen\Downloads\revosetup95.exe
2014-11-10 14:30 - 2014-11-10 14:30 - 00039525 _____ () C:\Users\purzelchen\Downloads\deadfly-GMER.log
2014-11-10 14:23 - 2014-11-10 14:54 - 00028924 _____ () C:\Users\purzelchen\Downloads\Addition.txt
2014-11-10 14:22 - 2014-11-12 19:58 - 00012054 _____ () C:\Users\purzelchen\Downloads\FRST.txt
2014-11-10 14:22 - 2014-11-12 19:58 - 00000000 ___DC () C:\FRST
2014-11-10 14:21 - 2014-11-10 14:21 - 00000482 _____ () C:\Users\purzelchen\Downloads\defogger_disable.log
2014-11-10 14:21 - 2014-11-10 14:21 - 00000000 _____ () C:\Users\purzelchen\defogger_reenable
2014-11-10 14:15 - 2014-11-10 14:15 - 00380416 _____ () C:\Users\purzelchen\Downloads\rv3wvh5j.exe
2014-11-10 14:15 - 2014-11-10 14:15 - 00050477 _____ () C:\Users\purzelchen\Downloads\Defogger.exe
2014-11-10 14:14 - 2014-11-10 14:14 - 02116096 _____ (Farbar) C:\Users\purzelchen\Downloads\FRST64.exe
2014-11-09 15:07 - 2011-06-21 05:09 - 00200976 _____ (Trend Micro Inc.) C:\Windows\SysWOW64\Drivers\tmcomm.sys
2014-11-09 15:06 - 2014-11-09 15:06 - 03437368 _____ (tuneuppro.com ) C:\Users\purzelchen\Downloads\setup (2).exe
2014-11-09 15:06 - 2014-11-09 15:06 - 02002376 _____ (Trend Micro Inc.) C:\Users\purzelchen\Downloads\HousecallLauncher.exe
2014-11-02 12:16 - 2014-11-02 12:16 - 00000000 ____D () C:\Users\purzelchen\AppData\Roaming\TrojanHunter
2014-11-02 10:23 - 2014-11-02 12:26 - 00000000 ____D () C:\Program Files (x86)\TrojanHunter 5.6
2014-11-02 10:23 - 2014-11-02 10:23 - 00059392 ____R () C:\Windows\SysWOW64\streamhlp.dll
2014-11-02 10:23 - 2014-11-02 10:23 - 00001047 _____ () C:\Users\purzelchen\Desktop\TrojanHunter.lnk
2014-11-02 10:23 - 2014-11-02 10:23 - 00000000 ____D () C:\ProgramData\TrojanHunter
2014-11-02 10:23 - 2014-11-02 10:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
2014-11-01 13:47 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-11-01 13:47 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2014-11-01 13:47 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-11-01 13:47 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2014-11-01 13:47 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-11-01 13:47 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2014-11-01 13:46 - 2014-11-01 13:47 - 00000000 ____D () C:\Users\purzelchen\AppData\Local\NVIDIA Corporation
2014-11-01 13:46 - 2014-11-01 13:46 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-11-01 13:46 - 2014-10-16 17:54 - 02800296 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-11-01 13:46 - 2014-10-16 17:54 - 02197680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-11-01 13:46 - 2014-10-16 17:54 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-11-01 13:46 - 2014-10-16 17:54 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-11-01 13:46 - 2014-10-16 13:27 - 00614544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-11-01 13:45 - 2014-10-16 15:11 - 06883136 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-11-01 13:45 - 2014-10-16 15:11 - 03533632 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-11-01 13:45 - 2014-10-16 15:11 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-11-01 13:45 - 2014-10-16 15:11 - 00933064 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-11-01 13:45 - 2014-10-16 15:11 - 00384200 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-11-01 13:45 - 2014-10-16 15:11 - 00061640 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-11-01 13:45 - 2014-10-15 01:48 - 04047877 _____ () C:\Windows\system32\nvcoproc.bin
2014-11-01 13:44 - 2014-10-16 17:54 - 31890064 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 24555840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 20968040 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 20922696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 19966856 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 18499648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 17260864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 16886168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 14029400 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 13942368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 13190288 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-11-01 13:44 - 2014-10-16 17:54 - 11395672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 11333848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 04289856 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 04009672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 03237528 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 02849224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 01876296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434448.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 01539272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434448.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 01538880 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00962376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00931984 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00921928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00895176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-11-01 13:44 - 2014-10-16 17:54 - 00038048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-11-01 13:44 - 2014-10-16 17:54 - 00034976 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00032416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-11-01 13:44 - 2014-10-16 17:54 - 00027024 _____ () C:\Windows\system32\nvinfo.pb
2014-11-01 13:42 - 2014-11-01 13:43 - 306270552 _____ (NVIDIA Corporation) C:\Users\purzelchen\Downloads\344.48-notebook-win8-win7-64bit-international-whql.exe
2014-10-30 20:40 - 2014-10-30 20:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-10-30 20:40 - 2014-10-30 20:40 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-10-30 15:17 - 2014-11-12 19:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-30 15:17 - 2014-11-01 13:55 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-30 15:17 - 2014-11-01 13:55 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-30 15:17 - 2014-11-01 13:55 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-30 15:17 - 2014-10-30 15:17 - 00000000 ____D () C:\Windows\system32\Macromed
2014-10-29 19:23 - 2014-11-12 16:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-29 19:23 - 2014-10-30 20:40 - 00001933 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-10-29 19:23 - 2014-10-30 20:40 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-10-29 19:23 - 2014-10-29 19:23 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-28 19:41 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-28 19:41 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-28 19:41 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-28 19:41 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-28 19:41 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-28 19:41 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-28 19:41 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-28 19:41 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-28 19:41 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-28 19:41 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-28 19:41 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-28 19:41 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-28 19:41 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-28 19:41 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-28 19:41 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-28 19:41 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-28 19:41 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-28 19:41 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-28 19:41 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-28 19:41 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-28 19:41 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-28 19:41 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-28 19:41 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-28 19:41 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-28 19:41 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-28 19:41 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-28 19:41 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-28 19:41 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-28 19:41 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-28 19:41 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-28 19:41 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-28 19:41 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-28 19:41 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-28 19:41 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-28 19:41 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-28 19:41 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-28 19:41 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-28 19:41 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-28 19:41 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-28 19:41 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-28 19:41 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-28 19:41 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-28 19:41 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-28 19:41 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-28 19:41 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-28 19:41 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-28 19:40 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-28 19:40 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-28 19:40 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-28 19:40 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-28 19:40 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-28 19:40 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-28 19:40 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-28 19:40 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-28 19:40 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-28 19:40 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-28 19:40 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-28 19:40 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-28 19:40 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-28 19:40 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-28 19:40 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-28 19:40 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-28 19:40 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-28 19:40 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-28 19:40 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-28 19:40 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-28 19:40 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-28 19:40 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-28 19:40 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-28 19:40 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-28 19:40 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-28 19:40 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-28 19:40 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-28 19:40 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-28 19:40 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-28 19:40 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-28 19:40 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-28 19:40 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-28 19:40 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-10-28 19:40 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-10-28 19:40 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-10-28 19:40 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-10-28 19:40 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-10-28 19:40 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-10-28 19:40 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-10-28 19:40 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-10-28 19:40 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-10-28 19:40 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-10-28 19:40 - 2014-07-08 23:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-10-28 19:40 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-10-28 19:40 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-28 19:40 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-28 19:40 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-28 19:40 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-28 19:40 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-28 19:40 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-28 19:38 - 2014-09-25 03:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-28 19:38 - 2014-09-25 02:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-10-28 19:38 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-28 19:38 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-28 16:22 - 2014-10-30 15:08 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-10-28 16:21 - 2014-11-01 13:56 - 00000000 ____D () C:\Users\purzelchen\AppData\Local\Adobe
2014-10-28 14:50 - 2014-10-28 14:50 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-10-28 14:50 - 2014-10-28 14:50 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-28 14:50 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\SysWOW64\dhRichClient3.dll
2014-10-28 14:50 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\SysWOW64\sqlite36_engine.dll
2014-10-28 14:39 - 2014-11-11 16:55 - 00000000 __SHD () C:\ProgramData\Windows Update Service0
2014-10-16 16:01 - 2014-10-16 16:00 - 00608737 _____ () C:\Users\purzelchen\Desktop\shadowrunchartab.jpeg
2014-10-16 09:59 - 2014-10-16 10:06 - 00000000 ____D () C:\Users\purzelchen\Desktop\adn
2014-10-16 09:59 - 2014-10-16 09:59 - 00000000 ____D () C:\Users\purzelchen\Desktop\Neuer Ordner
2014-10-15 23:44 - 2014-10-15 23:44 - 00001608 _____ () C:\Windows\DCEBOOT.RST
2014-10-15 23:44 - 2014-10-15 23:44 - 00000000 _____ () C:\Windows\DCEBOOT.LOG
2014-10-15 23:40 - 2014-10-15 23:41 - 00236080 _____ (Trend Micro Inc.) C:\Windows\RegBootClean64.exe
2014-10-15 23:40 - 2014-10-15 23:41 - 00025136 _____ (Trend Micro Inc.) C:\Windows\DCEBoot64.exe
2014-10-15 18:08 - 2014-11-10 00:46 - 00232154 _____ () C:\Users\purzelchen\AppData\Local\census.cache
2014-10-15 18:08 - 2014-11-10 00:46 - 00095598 _____ () C:\Users\purzelchen\AppData\Local\ars.cache
2014-10-15 17:55 - 2014-10-15 17:55 - 00000036 _____ () C:\Users\purzelchen\AppData\Local\housecall.guid.cache
2014-10-15 11:12 - 2014-10-15 11:12 - 00000000 ____D () C:\Users\purzelchen\AppData\Roaming\dvdcss
2014-10-13 22:07 - 2014-10-13 22:07 - 00292848 _____ () C:\Windows\Minidump\101314-27190-01.dmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 19:52 - 2013-10-29 21:13 - 00000443 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-11-12 19:51 - 2013-11-19 10:08 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-12 19:51 - 2013-10-01 22:48 - 00209020 _____ () C:\Windows\PFRO.log
2014-11-12 19:51 - 2013-10-01 17:35 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-11-12 19:51 - 2013-10-01 14:02 - 01078696 _____ () C:\Windows\WindowsUpdate.log
2014-11-12 19:51 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-12 19:51 - 2009-07-14 05:51 - 00156885 _____ () C:\Windows\setupact.log
2014-11-12 19:51 - 2009-07-14 05:45 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-12 19:51 - 2009-07-14 05:45 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-12 19:37 - 2014-08-21 18:01 - 00000000 ____D () C:\Users\purzelchen\Desktop\kitty
2014-11-12 19:22 - 2013-11-19 10:08 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-12 16:10 - 2009-07-14 18:58 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-11-12 16:10 - 2009-07-14 18:58 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-11-12 16:10 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-11 17:09 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-11-11 17:08 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-11 17:07 - 2009-07-14 03:34 - 00000215 ____C () C:\Windows\system.ini
2014-11-11 12:40 - 2013-10-29 21:04 - 00000000 ____D () C:\Users\purzelchen\AppData\Local\CrashDumps
2014-11-10 14:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-10 14:21 - 2013-10-01 14:20 - 00000000 ____D () C:\Users\purzelchen
2014-11-09 14:52 - 2014-09-09 14:54 - 00000000 ____D () C:\Users\purzelchen\Documents\UseNeXT
2014-11-09 14:48 - 2013-10-01 18:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-09 14:45 - 2014-09-09 14:54 - 00000000 ____D () C:\Users\purzelchen\AppData\Roaming\UseNeXT
2014-11-09 14:22 - 2014-08-23 10:41 - 00000000 ____D () C:\Users\purzelchen\Downloads\Musik
2014-11-02 12:19 - 2014-08-25 12:01 - 00000000 ____D () C:\Users\purzelchen\Desktop\whg
2014-11-02 12:14 - 2014-09-09 15:34 - 00000000 ____D () C:\Program Files\WinRAR
2014-11-01 13:47 - 2013-10-01 18:03 - 00001309 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2014-11-01 13:47 - 2013-10-01 17:33 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-11-01 13:47 - 2013-10-01 17:32 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-11-01 13:46 - 2013-10-25 15:23 - 00000000 ____D () C:\Users\purzelchen\AppData\Local\NVIDIA
2014-11-01 13:46 - 2013-10-01 17:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-11-01 13:46 - 2013-10-01 17:34 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-11-01 13:46 - 2011-11-20 15:48 - 00000000 ____D () C:\temp
2014-11-01 13:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-10-28 22:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-10-28 20:17 - 2009-07-14 05:45 - 00297624 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-28 20:16 - 2014-06-24 16:40 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-28 19:44 - 2013-10-01 22:32 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-28 19:42 - 2013-10-01 22:32 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-27 22:23 - 2013-11-19 10:09 - 00002137 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-22 16:49 - 2014-08-19 13:06 - 00000000 ____D () C:\Users\purzelchen\Desktop\Paul
2014-10-21 20:17 - 2013-11-19 10:08 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-21 20:17 - 2013-11-19 10:08 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-19 09:49 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-16 17:54 - 2013-10-01 17:33 - 00072904 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-10-16 17:54 - 2013-10-01 17:33 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-10-15 11:13 - 2014-09-09 19:14 - 00000000 ____D () C:\Users\purzelchen\AppData\Roaming\vlc
2014-10-14 22:23 - 2014-09-11 09:53 - 00000000 ____D () C:\Users\purzelchen\AppData\Local\QuickPar
2014-10-13 22:07 - 2013-10-14 14:05 - 00000000 ____D () C:\Windows\Minidump
Some content of TEMP:
====================
C:\Users\purzelchen\AppData\Local\Temp\Quarantine.exe
C:\Users\purzelchen\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-25 23:59
==================== End Of Log ============================ --- --- --- |