Hallo schrauber,
es scheint zu funktionieren, beim Starten meldet sich kein Virenalarm mehr. Wäre super.
(mbam lief übrigens in english)
Hier die files: mbam.txt - AdwCleaner[S0].txt - JRT.txt - FRST.txt
mal schaun, was zusammen rüber kommt. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 16.02.2015
Scan Time: 21:16:52
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.16.08
Rootkit Database: v2015.02.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: ki
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 391318
Time Elapsed: 9 min, 39 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 5
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\hbcennhacfaagdopikcegfcobcadeocj, Quarantined, [6ebaeb340387b87e8949883be1224eb2],
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\icdlfehblmklkikfigmjhbmmpmkmpooj, Quarantined, [6dbb66b9f79320166e65e6dd26dd55ab],
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\mhkaekfpcppmmioggniknbnbdbcigpkk, Quarantined, [34f4fe21dcae60d69f35dde6e023a15f],
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pfndaklgolladniicklehhancnlgocpp, Quarantined, [52d667b87e0c41f5a035b70c7c87fa06],
PUP.Optional.Spigot.A, HKU\S-1-5-21-453296214-1327697751-653560176-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Search Settings, Quarantined, [2bfdbe618efc092d20a920efe91cda26],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 20
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\css, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\Img, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\icons, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\scripts, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_1, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\chrome, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\plugins, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\FromDocToPDF_65, Delete-on-Reboot, [10183fe07e0cb77f93975c036a99e51b],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_1, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\Search Settings, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
Files: 51
PUP.Optional.Downloader, C:\Users\ki\Downloads\344.16-desktop-win8-win7-winvista-32bit-international-whql - CHIP-Installer.exe, Quarantined, [4bddd34c1575e155059073f8be42b947],
PUP.Optional.DownloadSponsor, C:\Users\ki\Downloads\Vollversion Steganos Passwort Manager 15 - CHIP-Installer.exe, Quarantined, [72b64fd0f3973cfa98c2e33f8a780af6],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\yahoo_ff.xml, Quarantined, [cb5db7683c4e5dd94bde2c6af70c0ff1],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\savingsslider@mybrowserbar.com.xpi, Quarantined, [0028e8374149f541ba97bfd94ab9629e],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi, Quarantined, [54d42ef149413bfb0288575b23e038c8],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\background.html, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\background.js, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\config.json, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\dea-128.png, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\dea-48.png, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\empty-favicon.ico, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\jquery.js, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\manifest.json, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\newtab.html, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\newtab.js, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\util.js, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\css\newtab.css, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\Img\no_thumb.png, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.5_0\Img\search-icon.png, Quarantined, [5dcb1708d6b469cdbea7cf8bd52ec53b],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\background.html, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\config.json, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\manifest.json, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\icons\ss-128.png, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\icons\ss-48.png, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\scripts\background.js, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\scripts\loader_1036.js, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.5_0\scripts\utils.js, Quarantined, [b870849b7a102a0c99cd7fdbc14259a7],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_1\amazon-128.png, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_1\amazon-19.png, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_1\amazon-48.png, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_1\background.js, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.SlickSavings.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_1\manifest.json, Quarantined, [94948897d3b7c373cc9ba9b1976c6c94],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\bootstrap.js, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\chrome.manifest, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\install.rdf, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\install_no_bootstrap.rdf, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\chrome\65ffxtbr.jar, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF\manifest.mf, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF\zigbert.rsa, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF\zigbert.sf, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\65ffxtbr@FromDocToPDF_65.com\plugins\NativeMessagingDispatcher.dll, Quarantined, [b96f9b84e7a35ed81bce085633d0da26],
PUP.Optional.MindSpark.A, C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\FromDocToPDF_65\3BB0D43E-9BAB-48E6-991C-0D98360E6757.sqlite, Delete-on-Reboot, [10183fe07e0cb77f93975c036a99e51b],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_1\background.js, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_1\ebay-128.png, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_1\ebay-19.png, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_1\ebay-48.png, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_1\manifest.json, Quarantined, [37f135ea5337b0867b1eef74709342be],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\ErrorAssistant_1.3.crx, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.1.crx, Quarantined, [0b1d45dae3a7a98d8cbaafcb08fb6d93],
Physical Sectors: 0
(No malicious items detected)
(end
AdwCleaner Logfile: Code:
# AdwCleaner v4.110 - Bericht erstellt 16/02/2015 um 21:47:54
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-14.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : ki - KI-PCMEDION2012
# Gestarted von : C:\Users\ki\Desktop\AdwCleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\SecTaskMan
Ordner Gelöscht : C:\ProgramData\DownloadManager
Ordner Gelöscht : C:\Users\ki\AppData\Local\iLivid
Ordner Gelöscht : C:\Users\ki\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Users\ki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
Datei Gelöscht : C:\Users\ki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Goodgame Empire.lnk
Datei Gelöscht : C:\Users\ki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Goodgame Empire.lnk
Datei Gelöscht : C:\Users\ki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
Datei Gelöscht : C:\Users\ki\Desktop\Goodgame Empire.lnk
Datei Gelöscht : C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\11-suche.xml
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\iijmpjamifmplbakhgikofogdfackici
Schlüssel Gelöscht : HKCU\Software\Classes\iLivid.torrent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iLivid.torrent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKCU\Software\Ciuvo
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\B696D3C37BD0D6C33A65D38BEC459181
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\B696D3C37BD0D6C33A65D38BEC459181
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B696D3C37BD0D6C33A65D38BEC459181
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v35.0.1 (x86 de)
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.BUTTON_STRUCTURE", "[{\"b\":221359615,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":221359616,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.browser.version.last", "35.0");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.firstKnownVersion", "6.33.3.63617");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=3BB0D43E-9BAB-48E6-991C-0D98360E6757&n=780c0228&p2=^Y6^xdm043^YYA^de&si=swissconverter");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.initialized", true);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installKeysSource", "LocalStorage");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installType", "XPI");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.contextKey", "");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.installDate", "2014052904");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerId", "^Y6^xdm043^YYA^de");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerSubId", "swissconverter");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.pixelUrl", "hxxp://fromdoctopdf.dl.tb.ask.com/install_pixels.jhtml?partner=^Y6^xdm043^YYA^de&coId=e1802acc8c32470b9c5c82a804660fb0&cake[...]
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.success", true);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.toolbarId", "3BB0D43E-9BAB-48E6-991C-0D98360E6757");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.isCompliantUninstallImplementation", true);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.lastActivePing", "1424104910961");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.lastKnownVersion", "6.85.5.64986");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.defaultSearch", false);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.homePageEnabled", false);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.keywordEnabled", false);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.tabEnabled", false);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.partnerPixelFired", true);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.successUrl", "hxxp://swissconverter.com/thankyou.php");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.toolbar.versionChanged", false);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.toolbarCollapsed", true);
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.weather.location", "10001");
[s3j4fal3.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark.lastInstalled", "fromdoctopdf@mindspark.com");
-\\ Google Chrome v40.0.2214.111
*************************
AdwCleaner[R0].txt - [7735 Bytes] - [16/02/2015 21:44:41]
AdwCleaner[S0].txt - [7746 Bytes] - [16/02/2015 21:47:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7805 Bytes] ########## --- --- ---
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by ki on 16.02.2015 at 21:59:01,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{168DEF9F-6815-4E50-A99A-90C7BAFE4D09}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{1E50148C-B2B5-439F-A781-E029997EC917}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{3194A389-7C88-4373-ABAA-61BEE482E2FC}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{31B7228A-242D-46B2-A1AE-0D603B7F73EF}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{3B856D34-A6F0-415A-A089-8F6963399C34}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{42B7B93E-8E43-4302-9CA0-B301427938BD}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{4479ABFD-38DA-434D-A150-8E9D6F074995}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{52F48861-41CD-495F-ACCE-C37DDC33CB37}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{5370A830-A06E-4BB7-B1E1-D9A8E9DAE885}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{69C84944-6A10-4CD3-9C71-7A41ADCF4CD4}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{727D9BEF-0227-4432-BE6A-F364728008ED}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{7FCE1A24-E15A-45B1-BBEC-DEA9E2B53EE2}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{83230355-22E5-49BD-BA7F-84ADC1C2DA07}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{8933B5E3-A9E8-4790-8081-99808A22BDBC}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{AECBC924-1699-47E5-A0B3-CC52D50C9258}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{B28F89EC-0F94-4294-A2C9-A59120253D90}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{B71F2C70-1CA1-4B90-97F3-162295264F9B}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{BA5C85AA-D521-499B-B5D5-B0F36DDE5917}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{BDBFE898-1A7E-492A-B657-6F877C4465F8}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{D169F35A-2D75-42C4-A109-86CEA166A3DA}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{E614A031-80B3-4217-A710-BE4BBBC8C49A}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{E89C72D4-2A47-43F6-BD3F-179456AF1946}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{F5A55C6B-F4D6-456B-B81F-32A06CCF644D}
Successfully deleted: [Empty Folder] C:\Users\ki\appdata\local\{FF68BBA0-4A4E-4E42-AD07-298AF10EBBA9}
~~~ FireFox
Successfully deleted: [Folder] C:\Users\ki\AppData\Roaming\mozilla\firefox\profiles\s3j4fal3.default\extensions\toolbar@web.de
Successfully deleted the following from C:\Users\ki\AppData\Roaming\mozilla\firefox\profiles\s3j4fal3.default\prefs.js
user_pref("extensions.toolbar.mindspark.lastInstalled", "fromdoctopdf@mindspark.com");
Emptied folder: C:\Users\ki\AppData\Roaming\mozilla\firefox\profiles\s3j4fal3.default\minidumps [231 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.02.2015 at 22:02:33,72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015
Ran by ki (administrator) on KI-PCMEDION2012 on 16-02-2015 22:16:25
Running from C:\Users\ki\Desktop
Loaded Profiles: ki (Available profiles: ki)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Memeo) C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(LULU Software) C:\Program Files (x86)\Soda PDF 5\HelperService.exe
(LULU Software) C:\Program Files (x86)\Soda PDF 5\ConversionService.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Drive Manager\SZDrvSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\SystemGuardAlerter.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\ioloGovernor64.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\LiveBoost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intenium) C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe
(Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe
(Audible, Inc.) C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Drive Manager\ABRTMon.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Dropbox, Inc.) C:\Users\ki\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EpmNews.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Steganos Software GmbH) C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe
(NVIDIA Corporation) C:\Users\ki\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database_2ce9b3\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-06-06] (Realtek Semiconductor)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] ()
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [403688 2012-06-28] (Acronis)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-05-20] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-04] (CyberLink)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5993216 2012-06-28] (Acronis)
HKLM-x32\...\Run: [AcronisTimounterMonitor] => C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [1173712 2012-06-28] (Acronis)
HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\EpmNews.exe [2086568 2014-03-06] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [SPM15 Chrome Autofill Relay] => C:\Program Files (x86)\Steganos Password Manager 15\passwordmanagercom.exe [480120 2014-06-25] (Steganos Software GmbH)
HKU\S-1-5-19\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-20\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-453296214-1327697751-653560176-1001\...\Run: [Spiele Post] => C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe [483400 2013-12-06] (Intenium)
HKU\S-1-5-21-453296214-1327697751-653560176-1001\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe [6540200 2015-02-09] (Steganos Software GmbH)
HKU\S-1-5-18\...\Winlogon: [Shell] C:\Windows\explorer.exe [2871808 2011-02-25] (Microsoft Corporation) <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Audible Download Manager.lnk
ShortcutTarget: Audible Download Manager.lnk -> C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe (Audible, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Drive Manager Real-Time.lnk
ShortcutTarget: Samsung Drive Manager Real-Time.lnk -> C:\Program Files (x86)\Clarus\Samsung Drive Manager\ABRTMon.exe (Clarus, Inc.)
Startup: C:\Users\ki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\ki\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\ki\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
BootExecute: ?????
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-453296214-1327697751-653560176-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-453296214-1327697751-653560176-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-453296214-1327697751-653560176-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-453296214-1327697751-653560176-1001 -> {0C43FC78-6FD5-4AE7-87F9-F57AC6B459AE} URL = https://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=402027&p={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: CHIP Best Deal BHO -> {7553EA3C-F8DA-4188-B7BC-956894EA54F5} -> C:\Program Files (x86)\chip\Internet Explorer\chip64.dll ()
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: CHIP Best Deal BHO -> {7553EA3C-F8DA-4188-B7BC-956894EA54F5} -> C:\Program Files (x86)\chip\Internet Explorer\chip32.dll ()
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Soda PDF 5 IE Helper -> {C737F472-1193-4281-BF53-A00B67AB3E19} -> C:\Program Files (x86)\Soda PDF 5\PDFIEHelper.dll (LULU Software)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Toolbar: HKLM-x32 - Soda PDF 5 IE Toolbar - {F335ABA2-FDB4-4644-92B2-5CC4B0FC91D6} - C:\Program Files (x86)\Soda PDF 5\PDFIEPlugin.dll (LULU Software)
Toolbar: HKLM-x32 - Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar.dll (Steganos Software GmbH)
Toolbar: HKU\S-1-5-21-453296214-1327697751-653560176-1001 -> Steganos Password Manager Toolbar - {9C65D12D-CF9D-454D-8049-61965D8C6FFF} - C:\Program Files (x86)\Steganos Password Manager 15\SPMIEToolbar64.dll (Steganos Software GmbH)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF SelectedSearchEngine: Yahoo!
FF Homepage: https://www.google.de/
FF Keyword.URL: https://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=402027&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-453296214-1327697751-653560176-1001: @soe.sony.com/installer,version=1.0.3 -> C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF SearchPlugin: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\google-maps.xml
FF SearchPlugin: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\searchplugins\webde-suche.xml
FF Extension: Avira Browser Safety - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\abs@avira.com [2015-02-14]
FF Extension: CHIP Best Deal - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\ciuvo-extension@chip.de [2015-02-05]
FF Extension: Xmarks - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\foxmarks@kei.com [2014-11-22]
FF Extension: No Name - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A} [2012-12-29]
FF Extension: WOT - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-27]
FF Extension: Cliqz Beta - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\cliqz@cliqz.com.xpi [2014-10-03]
FF Extension: OkayFreedom - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2014-12-24]
FF HKLM-x32\...\Firefox\Extensions: [FFSodaPDF5Converter@sodapdf.com] - C:\Program Files (x86)\Soda PDF 5\FFSoda5Ext
FF Extension: Soda PDF 5 Converter For Firefox - C:\Program Files (x86)\Soda PDF 5\FFSoda5Ext [2013-02-24]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2014-01-10]
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3
FF Extension: Steganos Password Manager - C:\Program Files (x86)\Steganos Password Manager 15\spmplugin3 [2014-12-05]
FF HKU\S-1-5-21-453296214-1327697751-653560176-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\ki\AppData\Roaming\Mozilla\Firefox\Profiles\s3j4fal3.default\extensions\cliqz@cliqz.com
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-08]
CHR Extension: (Bing) - C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmkckgpgekmanipelfidlhmkfcjicion [2015-01-01]
CHR Extension: (Google Wallet) - C:\Users\ki\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-08]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKU\S-1-5-21-453296214-1327697751-653560176-1001\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [jhpokclhnekmjlhknfihmghoblfgfeog] - C:\Program Files (x86)\chip\Chrome\chip-1.4.21.crx [2014-11-18]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2723400 2014-03-25] (G Data Software AG)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database_2ce9b3\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database_2ce9b3\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
S4 GSService; C:\Windows\SysWOW64\GSService.exe [444640 2014-07-28] ()
R2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [4700872 2014-09-30] (iolo technologies, LLC)
S4 Macromedia Licensing Service; C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [68096 2012-09-14] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
R2 OkayFreedom VPN Starter Service; C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe [326072 2015-02-09] (Steganos Software GmbH)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2014-12-27] (Electronic Arts)
S4 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
S4 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
S4 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [229888 2011-06-20] (Samsung Electronics Co., Ltd.) [File not signed]
S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2012.SP4c\RpcAgentSrv.exe [68760 2009-06-13] (SiSoftware) [File not signed]
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 Soda PDF 5 Helper Service; C:\Program Files (x86)\Soda PDF 5\HelperService.exe [1237856 2013-01-25] (LULU Software)
R2 Soda PDF 5 Service; C:\Program Files (x86)\Soda PDF 5\ConversionService.exe [877920 2013-01-25] (LULU Software)
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 SZDrvSvc; C:\Program Files (x86)\Clarus\Samsung Drive Manager\SZDrvSvc.exe [19456 2013-03-06] (Clarus, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [30752 2014-01-02] (EldoS Corporation)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [File not signed]
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [File not signed]
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [File not signed]
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-06-30] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-06-30] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [68608 2014-06-30] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-06-30] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-07-01] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-06-30] (G Data Software AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-16] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] ()
R3 mdf16; C:\Program Files (x86)\Clarus\Samsung Drive Manager\mdf16.sys [20400 2012-06-21] ()
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-04-27] (Intel Corporation)
R3 mvd23; C:\Program Files (x86)\Clarus\Samsung Drive Manager\mvd23.sys [99248 2012-06-21] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32912 2014-09-30] (EldoS Corporation)
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [102664 2013-12-12] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [25992 2013-12-12] ()
R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [700680 2013-12-12] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-16 22:16 - 2015-02-16 22:16 - 00029989 _____ () C:\Users\ki\Desktop\FRST.txt
2015-02-16 22:16 - 2015-02-16 22:16 - 00000000 ____D () C:\Users\ki\Desktop\FRST-OlderVersion
2015-02-16 22:02 - 2015-02-16 22:02 - 00003698 _____ () C:\Users\ki\Desktop\JRT.txt
2015-02-16 21:56 - 2015-02-16 21:56 - 01388274 _____ (Thisisu) C:\Users\ki\Desktop\JRT.exe
2015-02-16 21:52 - 2015-02-16 21:52 - 00007905 _____ () C:\Users\ki\Desktop\AdwCleaner[S0].txt
2015-02-16 21:44 - 2015-02-16 21:48 - 00000000 ____D () C:\AdwCleaner
2015-02-16 21:43 - 2015-02-16 21:43 - 02112512 _____ () C:\Users\ki\Desktop\AdwCleaner_4.110.exe
2015-02-16 21:29 - 2015-02-16 21:29 - 00015411 _____ () C:\Users\ki\Desktop\mbam.txt
2015-02-15 16:36 - 2015-02-15 16:36 - 00033406 _____ () C:\ComboFix.txt
2015-02-15 16:16 - 2015-02-15 16:36 - 00000000 ____D () C:\Qoobox
2015-02-15 16:16 - 2015-02-15 16:36 - 00000000 ____D () C:\ComboFix
2015-02-15 16:16 - 2015-02-15 16:33 - 00000000 ____D () C:\Windows\erdnt
2015-02-15 16:16 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-15 16:16 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-15 16:16 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-15 16:16 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-15 16:16 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-15 16:16 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-15 16:16 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-15 16:16 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-15 16:10 - 2015-02-15 16:10 - 05611771 ____R (Swearware) C:\Users\ki\Desktop\ComboFix.exe
2015-02-14 18:33 - 2015-02-14 18:33 - 00014574 _____ () C:\Users\ki\Desktop\anti-malware.txt
2015-02-14 18:09 - 2015-02-14 18:09 - 00000000 ____D () C:\OETemp
2015-02-14 18:03 - 2015-02-14 18:03 - 00059606 _____ () C:\Users\ki\Desktop\AVSCAN-20150214-141945-34470EF1.LOG
2015-02-14 14:00 - 2015-02-15 16:29 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-14 13:49 - 2015-02-16 22:15 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-14 13:49 - 2015-02-16 21:16 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-14 13:49 - 2015-02-16 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-14 13:49 - 2015-02-16 21:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-14 13:49 - 2015-02-14 13:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-14 13:49 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-14 13:49 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-14 13:49 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-14 13:46 - 2015-02-16 21:14 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\ki\Desktop\mbam-setup-2.0.4.1028.exe
2015-02-14 13:35 - 2015-02-14 13:35 - 00047947 _____ () C:\Users\ki\Desktop\gmer.txt
2015-02-14 13:21 - 2015-02-14 13:21 - 00380416 _____ () C:\Users\ki\Desktop\Gmer-19357.exe
2015-02-14 13:16 - 2015-02-14 13:18 - 00075416 _____ () C:\Users\ki\Desktop\Addition.txt
2015-02-14 13:16 - 2015-02-14 13:18 - 00054582 _____ () C:\Users\ki\Desktop\FRST-64.txt
2015-02-14 13:11 - 2015-02-16 22:16 - 00000000 ____D () C:\FRST
2015-02-14 13:10 - 2015-02-16 22:16 - 02085888 _____ (Farbar) C:\Users\ki\Desktop\FRST64.exe
2015-02-14 13:06 - 2015-02-14 13:06 - 00000466 _____ () C:\Users\ki\Desktop\defogger_disable.log
2015-02-14 13:06 - 2015-02-14 13:06 - 00000000 _____ () C:\Users\ki\defogger_reenable
2015-02-14 12:47 - 2015-02-14 12:47 - 00050477 _____ () C:\Users\ki\Desktop\Defogger.exe
2015-02-14 12:39 - 2015-02-14 12:39 - 00007018 _____ () C:\Users\ki\Desktop\pw-oben15-02-14.txt
2015-02-13 07:51 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-13 07:51 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-13 07:51 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-02-13 07:51 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-11 07:06 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-02-11 07:06 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-02-11 07:06 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-02-11 07:06 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
2015-02-11 07:05 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 07:05 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 07:05 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 07:05 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 07:05 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 07:05 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 07:05 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 07:05 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 07:05 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 07:05 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-11 07:05 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 07:05 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 07:05 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 07:05 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 07:05 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 07:05 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 07:05 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 07:05 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 07:05 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 07:05 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 07:05 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 07:05 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 07:05 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 07:05 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-11 07:05 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 07:05 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-11 07:05 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 07:05 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 07:05 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-11 07:05 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 07:05 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 07:05 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-02-11 07:05 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-02-11 07:05 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-11 07:05 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 07:05 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-11 07:05 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-11 07:05 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-02-11 07:05 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-11 07:05 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-11 07:05 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 07:05 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 07:05 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 07:05 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 07:05 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-11 07:05 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 07:05 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 07:05 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-02-11 07:05 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-11 07:05 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-11 07:05 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 07:05 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-11 07:05 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-11 07:05 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-02-11 07:05 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-11 07:05 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 07:05 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 07:05 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-11 07:05 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-11 07:05 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 07:05 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-02-11 07:05 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-02-11 07:04 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 07:04 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 07:04 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 07:04 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 07:04 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 07:04 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 07:04 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 07:04 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 07:04 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 07:04 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 07:04 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 07:04 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-02-11 07:04 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-11 07:04 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-02-11 07:04 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-11 07:04 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-02-11 07:04 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-11 07:04 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 07:04 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 07:04 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-11 07:04 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-11 07:04 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-11 07:04 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-11 07:04 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-11 07:04 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-11 07:04 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 07:04 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-11 07:04 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-11 07:04 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 07:04 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-02-11 07:04 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 07:04 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-11 07:04 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 07:04 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-11 07:04 - 2014-10-04 03:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-11 07:04 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-02-11 07:04 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-02-10 23:00 - 2015-02-10 23:00 - 00001077 _____ () C:\Users\Public\Desktop\OkayFreedom.lnk
2015-02-10 23:00 - 2015-02-10 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-02-05 21:50 - 2015-02-05 21:50 - 00003406 _____ () C:\Windows\System32\Tasks\chipSWU
2015-02-05 21:50 - 2015-02-05 21:50 - 00000000 ____D () C:\Users\ki\AppData\Roaming\DesktopIconGoodgame
2015-02-05 21:50 - 2015-02-05 21:50 - 00000000 ____D () C:\Program Files (x86)\chip
2015-02-03 11:05 - 2015-02-03 11:05 - 00006972 _____ () C:\Users\ki\Desktop\pw-oben15-02-03.txt
2015-01-27 20:49 - 2015-01-28 20:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-24 21:01 - 2015-01-24 21:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2015-01-24 20:33 - 2015-01-24 20:33 - 00000000 ____D () C:\Users\ki\AppData\Roaming\DicomViewer 3.0.0.0
2015-01-24 20:33 - 2015-01-24 20:33 - 00000000 ____D () C:\Users\ki\AppData\Local\Spoon
2015-01-23 13:54 - 2015-01-13 05:15 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-01-23 13:54 - 2015-01-13 05:15 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-01-23 13:54 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434725.dll
2015-01-23 13:54 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434725.dll
2015-01-23 13:54 - 2013-10-28 11:53 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-01-23 13:43 - 2014-11-22 11:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-01-23 13:43 - 2014-11-22 11:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-16 22:12 - 2014-12-24 08:52 - 00000000 ____D () C:\Users\ki\AppData\Roaming\Steganos VPN
2015-02-16 22:12 - 2014-09-13 17:50 - 00000000 ___RD () C:\Users\ki\Dropbox
2015-02-16 22:12 - 2013-09-12 19:01 - 00000000 ____D () C:\Users\ki\AppData\Roaming\Dropbox
2015-02-16 22:11 - 2012-07-29 09:27 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-16 22:11 - 2012-01-24 17:36 - 00226863 _____ () C:\Windows\setupact.log
2015-02-16 22:11 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-16 22:09 - 2012-07-29 09:24 - 01979840 _____ () C:\Windows\WindowsUpdate.log
2015-02-16 21:59 - 2013-07-19 08:20 - 00000000 ____D () C:\Users\ki\AppData\Local\CrashDumps
2015-02-16 21:57 - 2009-07-14 05:45 - 00024800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-16 21:57 - 2009-07-14 05:45 - 00024800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-16 21:56 - 2011-05-16 15:04 - 00793780 _____ () C:\Windows\system32\perfh007.dat
2015-02-16 21:56 - 2011-05-16 15:04 - 00178776 _____ () C:\Windows\system32\perfc007.dat
2015-02-16 21:56 - 2009-07-14 06:13 - 01806092 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-16 21:53 - 2012-08-13 08:01 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-16 21:49 - 2010-11-21 04:47 - 01917322 _____ () C:\Windows\PFRO.log
2015-02-16 21:30 - 2012-07-29 09:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-16 21:27 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-02-16 21:10 - 2013-11-23 09:46 - 00000099 _____ () C:\Users\Public\LMDebug.log
2015-02-16 18:22 - 2014-12-05 09:12 - 00000000 ____D () C:\Users\ki\AppData\Roaming\Steganos
2015-02-15 16:36 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-15 16:30 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-15 16:28 - 2009-07-14 03:34 - 27525120 _____ () C:\Windows\system32\config\system.bak
2015-02-15 16:28 - 2009-07-14 03:34 - 101711872 _____ () C:\Windows\system32\config\software.bak
2015-02-15 16:28 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\default.bak
2015-02-15 16:28 - 2009-07-14 03:34 - 00028672 _____ () C:\Windows\system32\config\sam.bak
2015-02-15 16:28 - 2009-07-14 03:34 - 00024576 _____ () C:\Windows\system32\config\security.bak
2015-02-14 21:03 - 2014-07-03 16:58 - 00000000 ____D () C:\Windows\Minidump
2015-02-14 18:09 - 2014-06-28 15:44 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-14 17:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-02-14 13:06 - 2012-07-29 09:33 - 00000000 ____D () C:\Users\ki
2015-02-14 10:46 - 2013-04-14 14:52 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0
2015-02-12 09:54 - 2012-10-29 09:25 - 00000000 ____D () C:\winsv
2015-02-12 09:45 - 2013-09-12 19:02 - 00000000 ____D () C:\Users\ki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-11 09:53 - 2009-07-14 05:45 - 00664240 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-11 09:52 - 2014-12-12 09:53 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-11 09:52 - 2014-05-07 07:16 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-11 09:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-02-11 07:48 - 2012-08-12 13:07 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-11 07:47 - 2013-08-15 02:01 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 07:42 - 2011-07-18 21:31 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-10 23:00 - 2014-12-24 08:51 - 00000000 ____D () C:\Program Files (x86)\OkayFreedom
2015-02-05 19:26 - 2013-03-24 09:21 - 00449024 ___SH () C:\Users\ki\Documents\Thumbs.db
2015-02-05 12:53 - 2012-08-13 08:01 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 12:53 - 2012-08-13 08:01 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-05 12:53 - 2011-12-01 22:26 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-04 22:25 - 2012-07-29 09:27 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-04 22:25 - 2012-07-29 09:27 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-03 10:47 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-28 18:35 - 2012-07-29 18:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-25 10:59 - 2012-01-24 00:22 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-25 10:17 - 2014-11-29 16:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-01-25 10:17 - 2012-01-24 00:22 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-01-24 20:46 - 2014-12-09 22:22 - 00000000 ____D () C:\Users\ki\AppData\Local\Incomedia
2015-01-24 20:45 - 2014-12-09 22:21 - 00000000 ____D () C:\Program Files (x86)\WebSite X5 v11 - Home
2015-01-24 20:44 - 2012-07-29 09:34 - 00209056 _____ () C:\Users\ki\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-23 17:20 - 2014-09-08 20:51 - 00000083 _____ () C:\Windows\SysWOW64\gpupdate.bin
2015-01-23 17:20 - 2014-09-07 20:56 - 00000000 ____D () C:\Users\ki\AppData\Local\RipTiger
2015-01-18 22:31 - 2014-03-01 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster
2015-01-18 22:27 - 2014-12-08 20:43 - 00000000 ____D () C:\Users\ki\Downloads\_chip
2015-01-18 18:33 - 2014-04-28 12:20 - 00000000 ____D () C:\Users\ki\AppData\Roaming\.minecraft
2015-01-18 14:33 - 2014-01-25 17:34 - 00000000 ____D () C:\Users\ki\Documents\BotaniculaSaves
==================== Files in the root of some directories =======
2013-10-27 10:35 - 2013-10-27 10:35 - 0000432 _____ () C:\Users\ki\AppData\Roaming\.backup.dm
2014-06-30 23:20 - 2014-06-30 23:20 - 0000000 _____ () C:\Users\ki\AppData\Roaming\gdfw.log
2014-06-30 23:20 - 2014-06-30 23:20 - 0000779 _____ () C:\Users\ki\AppData\Roaming\gdscan.log
2014-01-10 10:51 - 2014-01-10 10:51 - 0000000 _____ () C:\Users\ki\AppData\Roaming\pdfconverter
2012-07-31 09:27 - 2014-07-24 20:26 - 11804672 _____ () C:\Users\ki\AppData\Roaming\Sandra.mdb
2013-07-07 19:23 - 2013-07-07 19:23 - 0007619 _____ () C:\Users\ki\AppData\Local\Resmon.ResmonCfg
2012-07-29 18:31 - 2012-07-29 18:31 - 0017408 _____ () C:\Users\ki\AppData\Local\WebpageIcons.db
2014-03-25 19:17 - 2014-03-25 19:17 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\ki\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdv7lzr.dll
C:\Users\ki\AppData\Local\Temp\Quarantine.exe
C:\Users\ki\AppData\Local\Temp\sqlite3.dll
Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\IR41_QCX.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-13 08:25
==================== End Of Log ============================ --- --- --- |