Micha8888 | 17.06.2015 18:25 | Hallo Schrauber,
hier kommen die gewünschten Dateien:
mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 17.06.2015
Suchlauf-Zeit: 17:58:11
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.17.03
Rootkit Datenbank: v2015.06.15.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Micha
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 483982
Verstrichene Zeit: 37 Min, 33 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 30
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [2c9b4873f8926fc7b762ed838b78e51b],
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32LDR , In Quarantäne, [3493c8f39befcb6b539ec1cd966f8977],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [e1e6ceedcdbd0e28ac72700aff0653ad],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [844354671971fc3a958887f34eb70bf5],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, In Quarantäne, [b21555661a70b185679537eb7391e917],
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, In Quarantäne, [cafdc5f62a60a195a86ddd401aea8f71],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, In Quarantäne, [2e99e4d728621323aaa08d65e71ca858],
PUP.Optional.RadioCanyon.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Radio Canyon, In Quarantäne, [d7f07e3da2e8171f0b43f08ce421ca36],
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, In Quarantäne, [0fb83c7f404ab38345136b1e5aab45bb],
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, In Quarantäne, [ae19a91296f45bdbdb4e7383c142bb45],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{172C6915-8532-42E1-A4F5-41368FDA79D1}, In Quarantäne, [0dba85362c5e6fc7ebc832594bbafa06],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A9B91A7-8EEC-47AA-8679-2DD1FFB7D060}, In Quarantäne, [21a63a814f3ba195a0145437ee17c53b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{38C2D679-77A8-47FF-8EBE-60B83E657F82}, In Quarantäne, [facdfbc0a2e8290dac08dfacce3736ca],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4C003BF5-2E9A-4563-B4DA-7FF3686FA47F}, In Quarantäne, [e5e2e3d82862b38308ab1a71ab5a05fb],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5161BF85-9BC4-4911-9EBC-B71980F32B1E}, In Quarantäne, [b314bffcb3d74ee86a493259fa0bd32d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{580B862B-819A-47BD-9548-BD9DE7BC8FC0}, In Quarantäne, [5f685665ed9d2e08862d88032ed7fd03],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6CF823AB-7595-4939-B497-E1ECDE695118}, In Quarantäne, [f0d7f5c676143600773dd5b69a6ba25e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73816CD2-E777-4D46-A3ED-72EEF7F08160}, In Quarantäne, [eddaeccf305af1450aa91a717a8b9769],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{764574E8-775D-425A-94CC-741CE34FA5C5}, In Quarantäne, [cff82299b7d3a492fdb6d4b71ee707f9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{77D2C499-2FCE-409F-B3E5-74F76F23DEBF}, In Quarantäne, [0eb976454347033305af8a0149bca25e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84C49BBF-AF6B-4B35-A7ED-2D8839FC79DE}, In Quarantäne, [299ebdfe3654a98d852e2863b550d42c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8EA60F5C-ADE3-4E88-962E-BCE0212697CD}, In Quarantäne, [bf08803b6426112520943358c73e04fc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A2EFFDE7-AB88-417C-81F4-4351531FC6B4}, In Quarantäne, [af1816a5b2d83ff7a212682356af11ef],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B02B6954-6589-4AEA-AF2D-524995A06466}, In Quarantäne, [c106615a90fafa3c149f424925e06f91],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B1488EEE-2B0B-4D21-BD31-8055A8E08A37}, In Quarantäne, [ddea8c2fa7e382b44172e6a535d0eb15],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA5424EF-397D-4FE6-A1D4-BBFEEA781665}, In Quarantäne, [6e594e6d2a600531892a1b700302847c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF1245F5-445A-4B7D-94CF-E16A719FB3D7}, In Quarantäne, [e5e2a417a6e4e551e1d2bfccfc0952ae],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DEE2230F-C801-4BC9-B1D4-CBF739C78589}, In Quarantäne, [87407c3fb7d32c0a8f257714b055cb35],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0572417-7058-4E68-9B2C-EA2AF3F5F9C6}, In Quarantäne, [1ea95368acde5bdbd5dfa2e9887d3ec2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F7ECE214-A898-4FF5-924F-4E921436C7D3}, In Quarantäne, [626516a5cdbd4ee86a495437759041bf],
Registrierungswerte: 31
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130606280032304460, In Quarantäne, [ae193e7d0c7eea4cf000840adc29bf41]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.xxx|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130606280032304460, In Quarantäne, [fdca8734ed9dd1653bb51d719273ce32]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130606280032304460, In Quarantäne, [08bf4c6f5535ba7ca24ed3bbd5306e92]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\iexplore.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130606280032304460, In Quarantäne, [1aad2794f595c076a54bf09e44c1cf31]
PUP.Optional.Trovi.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32Ldr |{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb, 130606280032304460, In Quarantäne, [3493c8f39befcb6b539ec1cd966f8977]
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, In Quarantäne, [b21555661a70b185679537eb7391e917]
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\Windows\system32\drivers\SPPD.sys, In Quarantäne, [cafdc5f62a60a195a86ddd401aea8f71]
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, Firefox, In Quarantäne, [ae19a91296f45bdbdb4e7383c142bb45]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{172C6915-8532-42E1-A4F5-41368FDA79D1}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [0dba85362c5e6fc7ebc832594bbafa06]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2A9B91A7-8EEC-47AA-8679-2DD1FFB7D060}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [21a63a814f3ba195a0145437ee17c53b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{38C2D679-77A8-47FF-8EBE-60B83E657F82}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [facdfbc0a2e8290dac08dfacce3736ca]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4C003BF5-2E9A-4563-B4DA-7FF3686FA47F}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [e5e2e3d82862b38308ab1a71ab5a05fb]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5161BF85-9BC4-4911-9EBC-B71980F32B1E}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [b314bffcb3d74ee86a493259fa0bd32d]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{580B862B-819A-47BD-9548-BD9DE7BC8FC0}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [5f685665ed9d2e08862d88032ed7fd03]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6CF823AB-7595-4939-B497-E1ECDE695118}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [f0d7f5c676143600773dd5b69a6ba25e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{73816CD2-E777-4D46-A3ED-72EEF7F08160}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [eddaeccf305af1450aa91a717a8b9769]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{764574E8-775D-425A-94CC-741CE34FA5C5}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [cff82299b7d3a492fdb6d4b71ee707f9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{77D2C499-2FCE-409F-B3E5-74F76F23DEBF}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [0eb976454347033305af8a0149bca25e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84C49BBF-AF6B-4B35-A7ED-2D8839FC79DE}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [299ebdfe3654a98d852e2863b550d42c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8EA60F5C-ADE3-4E88-962E-BCE0212697CD}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [bf08803b6426112520943358c73e04fc]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A2EFFDE7-AB88-417C-81F4-4351531FC6B4}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [af1816a5b2d83ff7a212682356af11ef]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B02B6954-6589-4AEA-AF2D-524995A06466}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [c106615a90fafa3c149f424925e06f91]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B1488EEE-2B0B-4D21-BD31-8055A8E08A37}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [ddea8c2fa7e382b44172e6a535d0eb15]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BA5424EF-397D-4FE6-A1D4-BBFEEA781665}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [6e594e6d2a600531892a1b700302847c]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CF1245F5-445A-4B7D-94CF-E16A719FB3D7}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [e5e2a417a6e4e551e1d2bfccfc0952ae]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DEE2230F-C801-4BC9-B1D4-CBF739C78589}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [87407c3fb7d32c0a8f257714b055cb35]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F0572417-7058-4E68-9B2C-EA2AF3F5F9C6}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-codedownloader.exe, In Quarantäne, [1ea95368acde5bdbd5dfa2e9887d3ec2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F7ECE214-A898-4FF5-924F-4E921436C7D3}|AppName, 0f4220e6-e8a1-4b2b-b702-e5e80a2d9f66-2.exe-buttonutil.exe, In Quarantäne, [626516a5cdbd4ee86a495437759041bf]
PUP.Optional.Trovi.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M892306FF-698A-4994-934C-486E830F85F7&SearchSource=58&CUI=&UM=5&UP=SPEE5F4955-F7DB-4A98-A6DC-8BD8E5147B5E&q={searchTerms}&SSPV=, In Quarantäne, [c00762599eec979f636d6c18ee179967]
PUP.Optional.Conduit.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|SuggestionsURL_JSON, hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [16b11d9e602a05316f4404f15aa93ec2]
PUP.Optional.Trovi.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|DisplayName, Trovi search, In Quarantäne, [cdfab6054f3b7db9a8287311f510b54b]
Registrierungsdaten: 1
PUP.Optional.Trovi.A, HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M892306FF-698A-4994-934C-486E830F85F7&SearchSource=55&CUI=&UM=5&UP=SPEE5F4955-F7DB-4A98-A6DC-8BD8E5147B5E&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M892306FF-698A-4994-934C-486E830F85F7&SearchSource=55&CUI=&UM=5&UP=SPEE5F4955-F7DB-4A98-A6DC-8BD8E5147B5E&SSPV=),Ersetzt,[f7d003b87218c472f85b69d27a8c5fa1]
Ordner: 12
PUP.Optional.OpenCandy, C:\Users\Micha\AppData\Roaming\OpenCandy, In Quarantäne, [46814e6d61298aac543747775fa4857b],
PUP.Optional.OpenCandy, C:\Users\Micha\AppData\Roaming\OpenCandy\AE59C828F7B64980A018C06EC06243EE, In Quarantäne, [46814e6d61298aac543747775fa4857b],
PUP.Optional.OpenCandy, C:\Users\Micha\AppData\Roaming\OpenCandy\CB20593D9FCD47938771F1EA411777CA, In Quarantäne, [46814e6d61298aac543747775fa4857b],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\UI, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, In Quarantäne, [725512a9305a3402e8fed51082812dd3],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [725512a9305a3402e8fed51082812dd3],
PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, In Quarantäne, [0abda31802881a1cd0f69e5259aa54ac],
Dateien: 10
PUP.Optional.Conduit.A, C:\Users\Micha\AppData\Roaming\OpenCandy\AE59C828F7B64980A018C06EC06243EE\sp-downloader.exe, In Quarantäne, [8b3ca3187e0c3df9ec1920359a671de3],
PUP.Optional.CrossRider.A, C:\Users\Micha\AppData\Roaming\RHEng\38999A80C6E44779B52BDD8C7614207E\setup.exe, In Quarantäne, [f8cf2c8f8109d2641c3c589f45bc3ac6],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [2f980ab1b0dafe38061b9cded13446ba],
PUP.Optional.DVDVideoSoft.A, C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi, In Quarantäne, [10b7aa11acde39fd707ee4a34eb721df],
PUP.Optional.OpenCandy, C:\Users\Micha\AppData\Roaming\OpenCandy\CB20593D9FCD47938771F1EA411777CA\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [46814e6d61298aac543747775fa4857b],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.SearchProtect.A, C:\Users\Micha\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [56712b9098f2f93df300993639ca1de3],
PUP.Optional.Trovi.A, C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M892306FF-698A-4994-934C-486E830F85F7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPEE5F4955-F7DB-4A98-A6DC-8BD8E5147B5E");), Ersetzt,[c60105b62268e84e51bd473fed191ae6]
PUP.Optional.CrossRider.A, C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "149aa582eeacf13a0aa6f4b857994bd4");), Ersetzt,[10b703b8058593a385cf176fd234758b]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) AdwCleaner.txt: Code:
# AdwCleaner v4.206 - Bericht erstellt 17/06/2015 um 18:55:50
# Aktualisiert 01/06/2015 von Xplode
# Datenbank : 2015-05-31.5 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Micha - MICHA-PC
# Gestarted von : C:\Users\Micha\Desktop\AdwCleaner_4.206.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\SearchProtect
Ordner Gelöscht : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Micha\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Micha\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Micha\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Micha\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Micha\AppData\Roaming\YourFileDownloader
Ordner Gelöscht : C:\Users\Micha\AppData\Roaming\RHEng
Datei Gelöscht : C:\Windows\apppatch\apppatch64\vcldr64.dll
Datei Gelöscht : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Datei Gelöscht : C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\user.js
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\SPPDCOM
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17840
-\\ Mozilla Firefox v38.0.5 (x86 de)
[vufb4172.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M892306FF-698A-4994-934C-486E830F85F7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPEE5F4955-F7DB-4A9[...]
[vufb4172.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "149aa582eeacf13a0aa6f4b857994bd4");
[vufb4172.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar_ORJ-SPE@apn.ask.com.install-event-fired", true);
*************************
AdwCleaner[R0].txt - [3993 Bytes] - [17/06/2015 18:52:09]
AdwCleaner[S0].txt - [3823 Bytes] - [17/06/2015 18:55:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3882 Bytes] ########## Damit es nicht zu lang wird, der Rest mit dem nächsten Post...
..
die JRT.txt ist zu lang,
Soll ich sie nochmal in 2 Teile aufspalten?
Hier ist noch die frische FRST.txt Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-06-2015
Ran by Micha (administrator) on MICHA-PC on 17-06-2015 19:08:31
Running from C:\Users\Micha\Desktop
Loaded Profiles: Micha (Available Profiles: UpdatusUser & Micha & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
() C:\Users\Micha\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11785832 2011-03-10] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-09] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831528 2011-05-10] (Acer Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-14] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-28] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-18] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-18] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296984 2012-01-05] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-08-26] (CyberLink Corp.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1941911333-1773904818-201126851-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Micha\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-1941911333-1773904818-201126851-1001\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATILFE.EXE [297024 2013-01-24] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1941911333-1773904818-201126851-1001\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-10-02] (Nokia)
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [226920 2011-03-31] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [193128 2011-03-31] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-05-21]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\VR-NetWorld Auftragsprüfung.lnk [2014-12-18]
ShortcutTarget: VR-NetWorld Auftragsprüfung.lnk -> C:\VR-NetWorld\VRToolCheckOrder.exe (VR-NetWorld Software)
Startup: C:\Users\Micha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2015-03-15]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1941911333-1773904818-201126851-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1941911333-1773904818-201126851-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-20] (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-03-01] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-20] (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-03-01] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Perfect PDF 5 - {9DE41FB9-ACA7-4847-982B-D984042588FC} - C:\Program Files (x86)\soft Xpansion\Perfect PDF 5\PDF4ie.dll [2009-10-16] (soft Xpansion)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 83.169.186.161 83.169.186.225
FireFox:
========
FF ProfilePath: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @3ds.com/3dxml -> C:\Program Files\Dassault Systemes\3D XML Player\1\win_b64\code\bin\NP3DXMLPlugin.dll [2014-05-23] ()
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_160.dll [2015-06-14] ()
FF Plugin: @java.com/DTPlugin,version=10.11.2 -> C:\Windows\system32\npDeployJava1.dll [2013-01-29] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @3ds.com/3dxml -> C:\Program Files\Dassault Systemes\3D XML Player\1\win_b64\code\bin32\NP3DXMLPlugin.dll [2013-07-10] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_160.dll [2015-06-14] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-20] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2013-10-02] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1941911333-1773904818-201126851-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Micha\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2011-10-17] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll [2011-07-11] (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\englische-ergebnisse.xml [2014-06-05]
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\gmx-suche.xml [2014-06-05]
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\google-images.xml [2015-02-26]
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\google-maps.xml [2015-02-26]
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\lastminute.xml [2014-04-12]
FF SearchPlugin: C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\searchplugins\webde-suche.xml [2014-06-05]
FF Extension: Cliqz Beta - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\Extensions\cliqz@cliqz.com.xpi [2015-02-26]
FF Extension: Adblock Plus - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-12]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-06-02]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02]
FF HKLM-x32\...\Firefox\Extensions: [{00F0643E-B367-4779-B45D-7046EBA37A88}] - C:\Program Files (x86)\Steganos Password Manager 12\spmplugin3
FF HKU\S-1-5-21-1941911333-1773904818-201126851-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF HKU\S-1-5-21-1941911333-1773904818-201126851-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\extensions\cliqz@cliqz.com
FF HKU\S-1-5-21-1941911333-1773904818-201126851-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF Extension: No Name - C:\Users\Micha\AppData\Roaming\Mozilla\Firefox\Profiles\vufb4172.default\extensions\toolbar@gmx.net [not found]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 AAV UpdateService; C:\Program Files (x86)\Lexware\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S4 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
R2 EPSON_PM_RPCV4_06; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE [152640 2013-04-15] (SEIKO EPSON CORPORATION)
S4 GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [29696 2011-05-26] (Acer Incorporated) [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [703984 2014-09-22] (SEIKO EPSON CORPORATION)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
S2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S4 SXDS10; C:\Program Files (x86)\Common Files\soft Xpansion\SXDS10.exe [160768 2009-07-13] (soft Xpansion) [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-17] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S3 STIrUsb; C:\Windows\System32\DRIVERS\irstusb.sys [33792 2008-01-19] (SigmaTel, Inc.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-02-10] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-17 19:08 - 2015-06-17 19:08 - 00021634 _____ C:\Users\Micha\Desktop\FRST.txt
2015-06-17 19:06 - 2015-06-17 19:06 - 00129519 _____ C:\Users\Micha\Desktop\JRT.txt
2015-06-17 19:04 - 2015-06-17 19:04 - 00000207 _____ C:\Windows\tweaking.com-regbackup-MICHA-PC-Windows-7-Home-Premium-(64-bit).dat
2015-06-17 19:04 - 2015-06-17 19:04 - 00000000 ____D C:\RegBackup
2015-06-17 19:02 - 2015-06-17 19:02 - 02949914 _____ (Thisisu) C:\Users\Micha\Desktop\JRT.exe
2015-06-17 18:59 - 2015-06-17 18:59 - 00003978 _____ C:\Users\Micha\Desktop\AdwCleaner[S0].txt
2015-06-17 18:52 - 2015-06-17 18:55 - 00000000 ____D C:\AdwCleaner
2015-06-17 18:51 - 2015-06-17 18:51 - 02231296 _____ C:\Users\Micha\Desktop\AdwCleaner_4.206.exe
2015-06-17 18:48 - 2015-06-17 18:48 - 00020117 _____ C:\Users\Micha\Desktop\mbam.txt
2015-06-17 17:57 - 2015-06-17 18:58 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-17 17:57 - 2015-06-17 17:57 - 00001066 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-17 17:57 - 2015-06-17 17:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-17 17:57 - 2015-06-17 17:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-17 17:57 - 2015-06-17 17:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-17 17:57 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-17 17:57 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-17 17:57 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-17 17:55 - 2015-06-17 17:56 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Micha\Desktop\mbam-setup-2.1.6.1022.exe
2015-06-16 20:28 - 2015-06-16 20:28 - 00034483 _____ C:\ComboFix.txt
2015-06-16 19:44 - 2015-06-16 20:28 - 00000000 ____D C:\Qoobox
2015-06-16 19:44 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-06-16 19:44 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-06-16 19:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-06-16 19:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-06-16 19:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-06-16 19:44 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-06-16 19:44 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-06-16 19:44 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-06-16 19:43 - 2015-06-16 20:25 - 00000000 ____D C:\Windows\erdnt
2015-06-16 19:28 - 2015-06-16 19:28 - 00001228 _____ C:\Users\Micha\Desktop\Revo Uninstaller.lnk
2015-06-16 19:28 - 2015-06-16 19:28 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-06-16 19:26 - 2015-06-16 19:26 - 05628161 ____R (Swearware) C:\Users\Micha\Desktop\ComboFix.exe
2015-06-16 19:25 - 2015-06-16 19:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Micha\Desktop\revosetup95.exe
2015-06-15 19:59 - 2015-06-15 19:59 - 00041967 _____ C:\Users\Micha\Desktop\Gmer.txt
2015-06-15 19:16 - 2015-06-15 19:16 - 00380416 _____ C:\Users\Micha\Desktop\Gmer-19357.exe
2015-06-15 19:14 - 2015-06-15 19:14 - 00050477 _____ C:\Users\Micha\Desktop\Defogger.exe
2015-06-15 19:14 - 2015-06-15 19:14 - 00000472 _____ C:\Users\Micha\Desktop\defogger_disable.log
2015-06-15 19:14 - 2015-06-15 19:14 - 00000000 _____ C:\Users\Micha\defogger_reenable
2015-06-15 18:37 - 2015-06-15 18:37 - 00061893 _____ C:\Users\Micha\Desktop\Addition.txt
2015-06-15 18:35 - 2015-06-17 19:08 - 00000000 ____D C:\FRST
2015-06-15 18:34 - 2015-06-15 18:34 - 02109952 _____ (Farbar) C:\Users\Micha\Desktop\FRST64.exe
2015-06-14 09:49 - 2015-06-14 09:49 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan
2015-06-09 21:02 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-09 21:02 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-09 21:02 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-09 21:02 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-09 21:02 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-09 21:02 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-09 21:02 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-09 21:02 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-09 21:02 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-09 21:02 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-09 21:02 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-06-09 21:02 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-06-09 21:02 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-06-09 21:02 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-06-09 21:02 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-06-09 21:02 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-06-09 21:02 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-06-09 21:02 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-06-09 21:02 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-06-09 21:02 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-09 21:02 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-09 21:02 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-09 21:02 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-09 21:02 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-09 21:02 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-09 21:02 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-09 21:02 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-09 21:02 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-09 21:02 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-09 21:02 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-09 21:02 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-09 21:02 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-09 21:02 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-06-09 21:02 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-06-09 21:02 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-06-09 21:02 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-06-09 21:02 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-06-09 21:01 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-06-09 21:01 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-06-09 21:01 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-09 21:01 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-09 21:01 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-09 21:01 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-09 21:01 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-09 21:01 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-09 21:01 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-09 21:01 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-09 21:01 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-09 21:01 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-06-09 21:01 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-06-09 21:01 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-06-09 21:01 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-06-09 21:01 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-06-09 21:01 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-06-09 21:01 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-06-09 21:01 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-06-09 21:01 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-06-09 21:01 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-06-09 21:01 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-06-09 21:01 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-06-09 21:01 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-09 21:01 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-09 21:01 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-06-09 21:01 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-06-09 21:01 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-09 21:01 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-09 21:01 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-09 21:01 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-06-09 21:01 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-06-09 21:01 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-06-09 21:01 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-06-09 21:01 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-09 21:01 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-09 21:01 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-09 21:01 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-09 21:01 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-09 21:01 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-09 21:01 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-09 21:01 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-09 21:01 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-09 21:00 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-09 21:00 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-09 21:00 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-09 21:00 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-06-09 21:00 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-06-09 21:00 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-09 21:00 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-09 21:00 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-06-09 21:00 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-06-09 21:00 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-09 21:00 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-06-09 21:00 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-09 21:00 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-06-09 21:00 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-06-09 21:00 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-09 21:00 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-09 21:00 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-09 21:00 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-09 21:00 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-06-09 21:00 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-09 21:00 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-09 21:00 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-09 21:00 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-09 21:00 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-09 21:00 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-09 21:00 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-09 21:00 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-09 21:00 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-09 21:00 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-09 21:00 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-09 21:00 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-09 21:00 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-09 21:00 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-09 21:00 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-09 21:00 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-09 21:00 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-09 21:00 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-09 21:00 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-09 21:00 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-09 21:00 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-09 21:00 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-09 21:00 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-09 21:00 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-09 21:00 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-09 21:00 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-09 21:00 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-09 21:00 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-09 21:00 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-02 19:57 - 2015-06-05 07:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-01 19:25 - 2015-06-01 19:25 - 00000000 ____D C:\Users\Micha\AppData\Local\GWX
2015-05-27 19:12 - 2015-06-14 16:14 - 00000000 ____D C:\xxx_Spacekace
2015-05-27 19:07 - 2015-05-27 19:07 - 00002926 _____ C:\Windows\System32\Tasks\{A70B4894-488E-4F7D-9658-CE05DE187C17}
2015-05-27 19:06 - 2015-05-27 19:06 - 00002926 _____ C:\Windows\System32\Tasks\{EF861F98-8ECE-467A-9900-A30661150D52}
2015-05-27 19:06 - 2015-05-27 19:06 - 00002926 _____ C:\Windows\System32\Tasks\{8A12EAC0-FB5E-4799-93A2-7485A7108190}
2015-05-27 19:06 - 2015-05-27 19:06 - 00002926 _____ C:\Windows\System32\Tasks\{7B3E6852-505A-4620-8AAC-CE8A529F980D}
2015-05-27 19:05 - 2015-05-27 19:05 - 00002926 _____ C:\Windows\System32\Tasks\{55D7EEB0-D740-4C3C-B894-C7627531F9BD}
2015-05-22 08:06 - 2015-05-22 08:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-05-22 08:06 - 2015-05-22 08:06 - 00000000 ____D C:\Program Files\McAfee Security Scan
2015-05-21 19:39 - 2015-06-14 09:49 - 00002130 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-05-21 19:39 - 2015-05-22 08:06 - 00000000 ____D C:\ProgramData\McAfee Security Scan
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-17 19:04 - 2011-07-15 20:08 - 01903510 _____ C:\Windows\WindowsUpdate.log
2015-06-17 19:04 - 2009-07-14 06:45 - 00024400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-17 19:04 - 2009-07-14 06:45 - 00024400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-17 18:58 - 2011-08-07 13:23 - 00000434 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-06-17 18:58 - 2011-08-04 18:08 - 00000000 ____D C:\ProgramData\clear.fi
2015-06-17 18:57 - 2012-05-07 19:41 - 00930388 _____ C:\Windows\PFRO.log
2015-06-17 18:57 - 2012-03-07 20:51 - 00124832 _____ C:\Windows\setupact.log
2015-06-17 18:57 - 2011-11-23 21:31 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-17 18:57 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-17 18:48 - 2012-04-03 20:01 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-17 18:41 - 2012-04-19 20:35 - 00000000 ____D C:\Windows\sv
2015-06-17 18:37 - 2014-05-11 20:37 - 00000911 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {21FD95D8-1422-45E8-BE1A-C68D8E69A811}.job
2015-06-17 18:37 - 2014-05-11 20:37 - 00000725 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {21FD95D8-1422-45E8-BE1A-C68D8E69A811}.job
2015-06-17 18:14 - 2014-05-11 20:14 - 00000911 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Update {36A6A64B-FE55-4D86-8B55-219DD8C4831F}.job
2015-06-17 18:14 - 2014-05-11 20:14 - 00000725 _____ C:\Windows\Tasks\EPSON XP-312 313 315 Series Invitation {36A6A64B-FE55-4D86-8B55-219DD8C4831F}.job
2015-06-17 18:14 - 2011-11-23 21:31 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-17 17:54 - 2011-07-16 06:01 - 00699682 _____ C:\Windows\system32\perfh007.dat
2015-06-17 17:54 - 2011-07-16 06:01 - 00149790 _____ C:\Windows\system32\perfc007.dat
2015-06-17 17:54 - 2009-07-14 07:13 - 01620684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-16 20:28 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2015-06-16 20:14 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2015-06-16 20:13 - 2009-07-14 04:34 - 25952256 _____ C:\Windows\system32\config\SYSTEM.bak
2015-06-16 20:13 - 2009-07-14 04:34 - 109051904 _____ C:\Windows\system32\config\SOFTWARE.bak
2015-06-16 20:13 - 2009-07-14 04:34 - 00786432 _____ C:\Windows\system32\config\DEFAULT.bak
2015-06-16 20:13 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2015-06-16 20:13 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2015-06-16 19:41 - 2014-09-23 20:58 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E3AACEAF-6370-40FC-92C8-4DD90B33A3A3}
2015-06-15 21:17 - 2011-08-16 20:32 - 02035712 _____ C:\Users\Micha\Documents\Mögeliner SC.wbf
2015-06-15 20:50 - 2011-08-04 15:06 - 00000000 ____D C:\Users\Micha\AppData\Local\VirtualStore
2015-06-15 19:14 - 2011-08-04 15:06 - 00000000 ____D C:\Users\Micha
2015-06-15 18:28 - 2011-08-07 15:13 - 00000000 ____D C:\Treiber
2015-06-14 09:49 - 2014-08-15 09:41 - 00000000 ____D C:\Users\Micha\AppData\Local\Adobe
2015-06-14 09:49 - 2012-04-03 20:01 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-14 09:49 - 2012-04-03 20:01 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-06-14 09:49 - 2011-08-07 14:30 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-14 09:42 - 2009-07-14 06:45 - 00455200 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-13 13:49 - 2011-08-04 15:06 - 00123848 _____ C:\Users\Micha\AppData\Local\GDIPFONTCACHEV1.DAT
2015-06-11 21:01 - 2015-03-24 21:26 - 00000000 ____D C:\Users\Micha\AppData\Roaming\vlc
2015-06-11 20:34 - 2015-03-15 20:00 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-10 21:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2015-06-10 03:33 - 2014-12-10 20:01 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 03:33 - 2014-05-08 19:32 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 03:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 03:13 - 2013-08-13 21:46 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 03:03 - 2011-08-07 22:03 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 03:02 - 2009-07-14 04:34 - 00000510 _____ C:\Windows\win.ini
2015-06-05 07:30 - 2012-04-30 19:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-02 19:48 - 2015-03-15 20:00 - 00000000 ____D C:\Users\Micha\AppData\Local\Microsoft Help
2015-06-01 20:05 - 2012-01-31 21:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lexware
2015-06-01 18:26 - 2011-08-16 17:47 - 00000000 ____D C:\Users\Public\Documents\VR-NetWorld
2015-05-31 11:06 - 2014-01-16 19:44 - 06162944 ___SH C:\Users\Micha\Documents\Thumbs.db
2015-05-29 07:54 - 2015-03-15 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-05-29 07:36 - 2010-11-21 09:16 - 00000000 ____D C:\Windows\ShellNew
2015-05-29 07:35 - 2011-08-08 21:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-05-27 19:54 - 2015-03-24 21:19 - 00000000 ____D C:\Users\Micha\.mediathek3
2015-05-26 18:20 - 2011-08-07 21:22 - 00000000 ____D C:\VR-NetWorld
2015-05-20 21:57 - 2015-04-09 19:51 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-20 21:57 - 2015-04-09 19:51 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-19 19:09 - 2011-11-23 21:31 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-19 19:09 - 2011-11-23 21:31 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories =======
2012-05-17 20:30 - 2012-05-17 20:30 - 0003584 _____ () C:\Users\Micha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-08-07 20:06 - 2013-08-07 20:06 - 0000001 _____ () C:\Users\Micha\AppData\Local\llftool.4.30.agreement
2012-01-26 20:56 - 2012-05-07 22:07 - 0007605 _____ () C:\Users\Micha\AppData\Local\Resmon.ResmonCfg
2011-07-15 20:32 - 2013-08-14 22:15 - 0012914 _____ () C:\ProgramData\ArcadeDeluxe5.log
2011-06-08 08:57 - 2010-03-02 23:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe
Files to move or delete:
====================
C:\Users\Micha\CDBIDXL.DAT
C:\Users\Micha\NECDB.DAT
C:\Users\Micha\NETRKDB.DAT
C:\Users\Micha\TDBIDXL.DAT
Some files in TEMP:
====================
C:\Users\Micha\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Micha\AppData\Local\Temp\Quarantine.exe
C:\Users\Micha\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-13 14:34
==================== End of log ============================ Gruß
Micha |