Erst einmal Danke für das schnelle Antworten und danke für deine Mühe.
Nein habe keine Virenscanner Logfiles der letzten 7 Tage mehr.
Hier die FRST-Logfile:
FRST Logfile: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:31-12-2015
durchgeführt von Performance (Administrator) auf KAMIL1-PC (03-01-2016 03:44:56)
Gestartet von C:\Users\Performance\Downloads
Geladene Profile: Performance (Verfügbare Profile: Kamil1 & Reyya & Orhan & Testbenutzer & UpdatusUser & Standart & Host & Performance)
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 9 (Standard-Browser: "C:\Program Files (x86)\SRWare Iron\iron.exe" -- "%1")
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Spotify Ltd) C:\Users\Performance\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Performance\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe
(Spotify Ltd) C:\Users\Performance\AppData\Roaming\Spotify\Spotify.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Giraffic) C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
(Giraffic) C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
() C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\nis.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\SmartSVN 7.5\bin\statuscached.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files\WBC Engine\ExtensionUpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi2\hamachi-2.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi2\LMIGuardianSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi2\hamachi-2-ui.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi2\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\nis.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\chrome.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Frontend.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Service.exe
(BlueStack Systems) C:\Program Files (x86)\BlueStacks\HD-Network.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems) C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe
(BlueStack Systems) C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\nsc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\nsc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Application Automation, LLC) C:\Users\Performance\Desktop\best\ClashBot_7.9.2\ClashBot_exclusive.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [803200 2015-12-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Policies\Explorer\Run: [Policies] => C:\Windows\system32\backup\updatelauncher.exe
HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1
HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1
HKU\S-1-5-19\...\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\...\Run: [Spotify] => C:\Users\Performance\AppData\Roaming\Spotify\Spotify.exe [8387696 2015-12-16] (Spotify Ltd)
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\...\Run: [Spotify Web Helper] => C:\Users\Performance\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-16] (Spotify Ltd)
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [51656 2009-07-06] (EasyBits Software Corp.)
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.5.5.15\buShell.dll [2015-11-05] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.5.5.15\buShell.dll [2015-11-05] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.5.5.15\buShell.dll [2015-11-05] (Symantec Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => Keine Datei
ShellIconOverlayIdentifiers-x32: [SmartSVN1] -> {CC8811D1-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
ShellIconOverlayIdentifiers-x32: [SmartSVN2] -> {CC8811D2-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
ShellIconOverlayIdentifiers-x32: [SmartSVN3] -> {CC8811D3-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
ShellIconOverlayIdentifiers-x32: [SmartSVN4] -> {CC8811D4-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
ShellIconOverlayIdentifiers-x32: [SmartSVN5] -> {CC8811D5-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
ShellIconOverlayIdentifiers-x32: [SmartSVN6] -> {CC8811D6-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
ShellIconOverlayIdentifiers-x32: [SmartSVN7] -> {CC8811D7-1B32-4f3d-A9BF-D21C8F3C0366} => C:\Program Files (x86)\SmartSVN 7.5\lib\shellext32.dll [2012-12-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Status Monitor.lnk [2015-05-03]
ShortcutTarget: Status Monitor.lnk -> C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
Startup: C:\Users\Dr.Bob - Testbenutze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-14]
ShortcutTarget: Dropbox.lnk -> C:\Users\Performance\AppData\Roaming\Dropbox\bin\Dropbox.exe (Keine Datei)
Startup: C:\Users\Dr.Bob - Testbenutze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk [2013-10-29]
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (Keine Datei)
Startup: C:\Users\Dr.Bob - Testbenutze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk [2013-10-28]
ShortcutTarget: net.lnk -> C:\Users\Performance\AppData\Roaming\Windows Net Data\net.exe (Keine Datei)
Startup: C:\Users\Dr.Bob - Testbenutze\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2013-10-13]
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (Keine Datei)
Startup: C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk [2014-10-06]
ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (Keine Datei)
Startup: C:\Users\Kamil1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk [2013-04-19]
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\Performance\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Keine Datei)
BootExecute: PDBoot.exeautocheck autochk *
GroupPolicyUsers\S-1-5-21-269225853-1805347737-3918544349-1012\User: Beschränkung <======= ACHTUNG
CHR HKLM\SOFTWARE\Policies\Google: Beschränkung <======= ACHTUNG
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
ProxyEnable: [.DEFAULT] => Proxy ist aktiviert.
ProxyServer: [.DEFAULT] => http=127.0.0.1:14131;https=127.0.0.1:14131
ProxyServer: [S-1-5-21-269225853-1805347737-3918544349-1018] => 62.204.241.146:8000
Winsock: Catalog5 07 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880 2007-09-04] (AVM Berlin)
Winsock: Catalog9 01 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880 2007-09-04] (AVM Berlin)
Winsock: Catalog9 02 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880 2007-09-04] (AVM Berlin)
Winsock: Catalog9 09 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 10 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 11 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 12 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 13 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 14 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 15 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 16 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 17 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880 2007-09-04] (AVM Berlin)
Winsock: Catalog9 22 C:\Program Files (x86)\FRITZ!DSL\\sarah.dll [24880 2007-09-04] (AVM Berlin)
Winsock: Catalog9 23 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 01 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 02 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 03 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 04 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 05 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 06 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 07 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 08 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9-x64 19 C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll [523344 2014-05-27] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{62632E66-D937-48B8-AC15-74322738F369}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130938308411490000&GUID=00000000-0000-0000-0000-000000000000
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130938308412250000&GUID=00000000-0000-0000-0000-000000000000
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130893510705070000&GUID=1E576981-A090-449D-B80A-B08C50B028CD
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130893510704580000&GUID=1E576981-A090-449D-B80A-B08C50B028CD
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=130893510642500000&GUID=1E576981-A090-449D-B80A-B08C50B028CD
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=5.5&ar=msnhome
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130938308419150000&GUID=00000000-0000-0000-0000-000000000000
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://safesearch.avira.com/#web/result?source=art&q=
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxps://search.avira.net/#web/result?source=art&q=
HKU\S-1-5-21-269225853-1805347737-3918544349-1018\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
URLSearchHook: HKLM-x32 -> Standard = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\1003291816\ICQToolBar.dll (ICQ)
URLSearchHook: HKLM-x32 - Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyng.dll Keine Datei
URLSearchHook: HKLM-x32 - Softonic Deutsch Toolbar - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - C:\Program Files (x86)\Softonic_Deutsch\tbSof1.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - Eazel-DE Toolbar - {69b6939f-c70d-45c5-9bbd-e2e2cc3dd8e5} - C:\Program Files (x86)\Eazel-DE\prxtbEaz2.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\tbDVDV.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - Media Star Toolbar - {dfabc5b5-039b-4865-979a-de31cdf3e351} - C:\Program Files (x86)\Media_Star\tbMedi.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
URLSearchHook: HKLM-x32 - uTorrentBar_DE Toolbar - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - C:\Program Files (x86)\uTorrentBar_DE\tbuTor.dll (Conduit Ltd.)
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {017E639E-7655-4B12-BF00-A9D580554CFD} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM -> {D871CB93-D1FF-4B5B-AFAF-88164EA1652C} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM -> {FB9521CF-AA0D-400B-B12F-B15ADBD02725} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {017E639E-7655-4B12-BF00-A9D580554CFD} URL = hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1145&query={searchTerms}&invocationType=tb50hpcndtie7-de-de
SearchScopes: HKLM-x32 -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCYYYYYYYYDE&fl=0&ptb=j7RVg1BN1dpDOleEt.nJSQ&url=hxxp://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchbomb.info/?l=1&q={searchTerms}&pid=233&r=2013/11/24&hid=1690834730156787158&lg=EN&cc=DE&unqvl=42
SearchScopes: HKLM-x32 -> {D871CB93-D1FF-4B5B-AFAF-88164EA1652C} URL = hxxp://de.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913933
SearchScopes: HKLM-x32 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}
SearchScopes: HKLM-x32 -> {FB9521CF-AA0D-400B-B12F-B15ADBD02725} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06&type=ie2008
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\.DEFAULT -> {5070731F-76C1-4644-9B18-42670221168B} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=UT2V5&o=15158&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=UG&apn_dtid=YYYYYYYYDE&apn_uid=1DE8370C-90B1-418C-B55F-138AC351D471&apn_sauid=F644E0E7-13D6-45A6-8610-5FF608235EDE
SearchScopes: HKU\.DEFAULT -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\.DEFAULT -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL =
SearchScopes: HKU\.DEFAULT -> {FB9521CF-AA0D-400B-B12F-B15ADBD02725} URL =
SearchScopes: HKU\S-1-5-19 -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL =
SearchScopes: HKU\S-1-5-20 -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL =
SearchScopes: HKU\S-1-5-21-269225853-1805347737-3918544349-1018 -> {e4a1ece8-ed94-4f93-80ea-75f978ceaf24} URL =
BHO: Complitly -> {0FB6A909-6086-458F-BD92-1F8EE10042A0} -> C:\Users\Kamil1\AppData\Roaming\Complitly\64\Complitly64.dll [2012-05-16] (SimplyGen)
BHO: LyricsMonkey-15 -> {11111111-1111-1111-1111-110411391110} -> C:\Program Files (x86)\LyricsMonkey-15\LyricsMonkey-15-bho64.dll => Keine Datei
BHO: WBC Engine -> {14DD0E04-D4F6-45d2-A958-F361FBD4F64F} -> C:\Program Files\WBC Engine\Extension64.dll => Keine Datei
BHO: RemeoveAdsTiuabee -> {5AAFA94B-B594-7C9D-1485-07DC0A43C822} -> C:\ProgramData\RemeoveAdsTiuabee\G7V8Ew.x64.dll => Keine Datei
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2013-10-20] (Siber Systems Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: HomeTab -> {9fdfb66c-713b-4201-83a6-5b78ae227b41} -> C:\Program Files\HomeTab\IE\HomeTab.dll [2015-02-05] (Simply Tech LTD.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-14] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: DownlOad keeper -> {B5216374-DF4F-4111-CDF5-67012A494F89} -> C:\Program Files (x86)\DownlOad keeper\CWK3F5c.x64.dll => Keine Datei
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll => Keine Datei
BHO: CoolPic - Fun Social Pictures -> {FEFE89E5-A43F-4f4b-8211-B11D91D02135} -> C:\Program Files\CoolPic - Fun Social Pictures\Extension64.dll => Keine Datei
BHO-x32: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2011-04-14] (Orbitdownloader.com)
BHO-x32: Ginyas Browser Companion -> {00cbb66b-1d3b-46d3-9577-323a336acb50} -> C:\Program Files (x86)\BrowserCompanion\jsloader.dll [2013-02-18] ( )
BHO-x32: Browser Guard -> {02a0d829-4393-46fc-a37e-126263035883} -> C:\Program Files (x86)\Browser Guard\browserguard.dll [2013-08-27] (Browser Guard)
BHO-x32: ContributeBHO Class -> {074C1DC5-9320-4A9A-947D-C042949C6216} -> C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27] (Adobe Systems, Inc.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Complitly -> {0FB6A909-6086-458F-BD92-1F8EE10042A0} -> C:\Users\Kamil1\AppData\Roaming\Complitly\Complitly.dll [2012-05-16] (SimplyGen)
BHO-x32: QuickStores-Toolbar -> {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} -> C:\Windows\SysWOW64\mscoree.dll [2009-11-08] (Microsoft Corporation)
BHO-x32: Kein Name -> {140BD8E3-C167-11D4-B4A3-080000180323} -> Keine Datei
BHO-x32: Kein Name -> {1631550F-191D-4826-B069-D9439253D926} -> Keine Datei
BHO-x32: CescrtHlpr Object -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.23.10\bh\BabylonToolbar.dll => Keine Datei
BHO-x32: Kein Name -> {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} -> Keine Datei
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-11-24] (RealPlayer)
BHO-x32: Conduit Engine -> {30F9B915-B755-4826-820B-08FBA6BD249D} -> C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll [2011-01-17] (Conduit Ltd.)
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [2009-01-26] (Safer Networking Limited)
BHO-x32: Search Assistant BHO -> {5848763c-2668-44ca-adbe-2999a6ee2858} -> C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jSrcAs.dll => Keine Datei
BHO-x32: RadioBar Toolbar -> {5B291E6C-9A74-4034-971B-A4B007A0B315} -> C:\Program Files (x86)\RadioBar\toolbar.ni.dll [2010-01-11] (IMEDIX WEB TECHNOLOGIES LTD.)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\coIEPlg.dll [2015-11-05] (Symantec Corporation)
BHO-x32: Eazel-DE Toolbar -> {69b6939f-c70d-45c5-9bbd-e2e2cc3dd8e5} -> C:\Program Files (x86)\Eazel-DE\prxtbEaz2.dll [2011-01-17] (Conduit Ltd.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-27] (Microsoft Corporation)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2013-10-20] (Siber Systems Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll [2013-07-30] (AVG Secure Search)
BHO-x32: Ginyas Browser Companion Verifier -> {963B125B-8B21-49A2-A3A8-E37092276531} -> C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll [2013-02-18] (Blabbers Communications Ltd)
BHO-x32: Babylon IE plugin -> {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} -> C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll => Keine Datei
BHO-x32: HomeTab -> {9fdfb66c-713b-4201-83a6-5b78ae227b41} -> C:\Program Files (x86)\HomeTab\IE\HomeTab.dll [2015-02-05] (Simply Tech LTD.)
BHO-x32: Kein Name -> {A6984C00-C6EB-11D4-B4A4-080000180323} -> C:\PROGRA~2\Rapidown\rapi310.dll => Keine Datei
BHO-x32: Kein Name -> {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} -> Keine Datei
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-14] (Google Inc.)
BHO-x32: DealPly Shopping -> {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} -> C:\Program Files (x86)\DealPly\DealPlyIE.dll => Keine Datei
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Vuze Remote Toolbar -> {ba14329e-9550-4989-b3f2-9732e92d17cc} -> C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll [2011-01-17] (Conduit Ltd.)
BHO-x32: uTorrentBar_DE Toolbar -> {c840e246-6b95-475e-9bd7-caa1c7eca9f2} -> C:\Program Files (x86)\uTorrentBar_DE\tbuTor.dll [2010-12-09] (Conduit Ltd.)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll [2010-10-11] (Microsoft Corporation)
BHO-x32: Ask Toolbar -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll => Keine Datei
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {DDA57003-0068-4ed2-9D32-4D1EC707D94D} -> C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19] (Microsoft Corporation)
BHO-x32: Web Check -> {E155F23C-9931-47c6-A619-20E6FCA86D75} -> C:\Program Files (x86)\Web Check\WebCheck.dll [2013-08-12] (Web Check)
BHO-x32: SweetIM Toolbar Helper -> {EEE6C35C-6118-11DC-9C72-001320C79847} -> C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll => Keine Datei
BHO-x32: Yontoo -> {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} -> C:\Program Files (x86)\Yontoo\YontooIEClient.dll => Keine Datei
Toolbar: HKLM - Kein Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - Keine Datei
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2013-10-20] (Siber Systems Inc.)
Toolbar: HKLM - HomeTab - {9fdfb66c-713b-4201-83a6-5b78ae227b41} - C:\Program Files\HomeTab\IE\HomeTab.dll [2015-02-05] (Simply Tech LTD.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2013-12-14] (Google Inc.)
Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll Keine Datei
Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll [2013-07-30] (AVG Secure Search)
Toolbar: HKLM-x32 - HomeTab - {9fdfb66c-713b-4201-83a6-5b78ae227b41} - C:\Program Files (x86)\HomeTab\IE\HomeTab.dll [2015-02-05] (Simply Tech LTD.)
Toolbar: HKLM-x32 - Free PDF Perfect - {EFC2B9BE-AB2B-47F1-A47D-9EB28E58C917} - C:\Program Files (x86)\Freemium\Free PDF Perfect\ieagent32.dll [2013-10-18] (soft Xpansion)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2013-10-20] (Siber Systems Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2013-12-14] (Google Inc.)
Toolbar: HKLM-x32 - RadioRage - {78ba36c9-6036-482b-b48d-ecca6f964b84} - C:\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbar.dll Keine Datei
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\coIEPlg.dll [2015-11-05] (Symantec Corporation)
Toolbar: HKU\.DEFAULT -> Kein Name - {5B291E6C-9A74-4034-971B-A4B007A0B315} - Keine Datei
Toolbar: HKU\.DEFAULT -> Kein Name - {69B6939F-C70D-45C5-9BBD-E2E2CC3DD8E5} - Keine Datei
Toolbar: HKU\.DEFAULT -> Kein Name - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - Keine Datei
Toolbar: HKU\.DEFAULT -> Kein Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - Keine Datei
Handler-x32: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2013-02-18] (Blabbers Communications Ltd)
Handler-x32: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2013-02-18] (Blabbers Communications Ltd)
Handler-x32: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll [2013-02-18] (Blabbers Communications Ltd)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler-x32: toolbarchrome - {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - C:\Program Files (x86)\RadioBar\toolbar.ni.dll [2010-01-11] (IMEDIX WEB TECHNOLOGIES LTD.)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll [2013-07-30] (AVG Secure Search)
FireFox:
========
FF ProfilePath: C:\Users\Performance\AppData\Roaming\Mozilla\Firefox\Profiles\2agsqwjm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-20] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-08-29] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2012-06-28] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-20] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [Keine Datei]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2011-11-14] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2010-08-25] (DivX,Inc.)
FF Plugin-x32: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll [Keine Datei]
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2013-08-29] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\new_plugin\npjp2.dll [Keine Datei]
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-27] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BrowserPlugin\npBrowserPlugin.dll [2012-01-13] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-01-18] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2012-05-22] (Pando Networks)
FF Plugin-x32: @real.com/nppl3260;version=12.0.1.609 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2010-11-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=12.0.1.609 -> c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll [2010-11-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.609 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2010-11-24] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.609 -> c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll [2010-11-24] (RealNetworks, Inc.)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 -> C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll [Keine Datei]
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 -> C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll [Keine Datei]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-05] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll [2010-03-27] (Adobe Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npDivxPlayerPlugin.dll [2009-11-14] (DivX, Inc)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npmieze.dll [2010-03-19] (Synatix GmbH)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2010-11-24] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2014-11-22] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll [2010-11-24] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll [2010-11-24] (RealNetworks, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml [2013-07-30]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012-04-12]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fast.png [2009-12-09]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fast.xml [2009-12-09]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchstonicde.xml [2010-09-28]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\foxsearch.src [2011-07-01]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml [2015-02-20]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\WebSearchober3729983.xml [2011-01-19]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml [2013-07-30]
FF Extension: iMacros for Firefox - C:\Users\Performance\AppData\Roaming\Mozilla\Firefox\Profiles\2agsqwjm.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2015-06-09]
FF Extension: Yahoo! Toolbar - C:\Users\Performance\AppData\Roaming\Mozilla\Firefox\Profiles\2agsqwjm.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2015-06-10] [ist nicht signiert]
FF Extension: Ginyas Browser Companion - C:\Users\Performance\AppData\Roaming\Mozilla\Firefox\Profiles\2agsqwjm.default\extensions\bbrs_002@blabbers.com [2015-06-07] [ist nicht signiert]
FF Extension: Adblock Plus - C:\Users\Performance\AppData\Roaming\Mozilla\Firefox\Profiles\2agsqwjm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-01-02]
FF Extension: Babylon Spelling and Proofreading - C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com [2011-07-01] [ist nicht signiert]
FF Extension: QuickStores-Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de [2010-10-03] [ist nicht signiert]
FF Extension: Eazel-DE Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\{69b6939f-c70d-45c5-9bbd-e2e2cc3dd8e5} [2010-05-08] [ist nicht signiert]
FF Extension: ICQ Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [2009-07-25] [ist nicht signiert]
FF Extension: Skype extension for Firefox - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2010-03-24] [ist nicht signiert]
FF Extension: z - C:\Program Files (x86)\Mozilla Firefox\extensions\{c779117f-ac9b-8a9d-6113-7aa4d076440d} [2012-05-30] [ist nicht signiert]
FF Extension: QuestDns - C:\Program Files (x86)\Mozilla Firefox\extensions\{C91E1C68-B60A-4C9F-B53B-AAAEF0E7EF97} [2010-07-18] [ist nicht signiert]
FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\afproxy@anchorfree.com [2014-03-24] [ist nicht signiert]
FF HKLM\...\Firefox\Extensions: [{FEFE89E5-A43F-4f4b-8211-B11D91D02135}] - C:\Program Files\CoolPic - Fun Social Pictures\Firefox => nicht gefunden
FF HKLM\...\Firefox\Extensions: [{14DD0E04-D4F6-45d2-A958-F361FBD4F64F}] - C:\Program Files\WBC Engine\Firefox
FF Extension: WBC Engine - C:\Program Files\WBC Engine\Firefox [2013-10-18] [ist nicht signiert]
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon
FF Extension: Norton Identity Safe - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon [2015-12-01] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-07-30] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: Adobe Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010-07-16] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [HBLite@HBLite.com] - C:\Program Files (x86)\HBLite\bin\11.0.258.0\firefox\extensions => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-11-24] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [ClickPotatoLite@ClickPotatoLite.com] - C:\Program Files (x86)\ClickPotatoLite\bin\10.0.659.0\firefox\extensions => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-02-01] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-01] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [ShopperReports@ShopperReports.com] - C:\Program Files (x86)\ShopperReports3\bin\3.1.22.0\firefox\firefoxtoolbar\extensions => nicht gefunden
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\15.4.0.5
FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\15.4.0.5 [2013-07-30] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] - C:\Program Files (x86)\Web Check\WebCheck.xpi
FF Extension: Web Check - C:\Program Files (x86)\Web Check\WebCheck.xpi [2013-08-12] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi
FF Extension: Browser Guard - C:\Program Files (x86)\Browser Guard\browserguard.xpi [2013-08-27] [ist nicht signiert]
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon
Chrome:
=======
CHR Profile: C:\Users\Performance\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\Exts\Chrome.crx [2015-12-01]
CHR HKLM\...\Chrome\Extension: [coljhboelhlkbgaaolcngflenaggpeao] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [fcljdicbcnmfhekdcaobgbpjjifniemh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [kmedakdfngfmagjlndeckcbfcmidlbio] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bcjagnifjocnddgeknajocbkkhlgibem] - C:\Program Files (x86)\Chrome\surfcanyon.crx [2011-09-29]
CHR HKLM-x32\...\Chrome\Extension: [bkomkajifikmkfnjgphkjcfeepbnojok] - C:\Program Files (x86)\PriceGong\2.5.3\pricegong.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [bodddioamolcibagionmmobehnbhiakf] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2012-03-27]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cgiaikfpllchefojlnehlmpekeogihnm] - C:\Users\Kamil1\AppData\Local\CRE\cgiaikfpllchefojlnehlmpekeogihnm.crx [2012-04-30]
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\Exts\Chrome.crx [2015-12-01]
CHR HKLM-x32\...\Chrome\Extension: [coljhboelhlkbgaaolcngflenaggpeao] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files (x86)\Web Check\WebCheck.crx [2013-08-12]
CHR HKLM-x32\...\Chrome\Extension: [dghncoeocefmhkhiphdgikkamjeglbfh] - C:\Program Files (x86)\mystarttb\chrome-newtab-search.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonChrome.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [dlfienamagdnkekbbbocojppncdambda] - C:\Program Files (x86)\Complitly\chrome\ComplitlyChrome.crx [2012-05-30]
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Dr.Bob - Testbenutze\AppData\Roaming\BabSolution\CR\Delta.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [fcljdicbcnmfhekdcaobgbpjjifniemh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.1\facemoods.crx <nicht gefunden>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2010-11-24]
CHR HKLM-x32\...\Chrome\Extension: [jlceijfdfeghdhmmbhbcffanmcggoojf] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\Dr.Bob - Testbenutze\AppData\Local\Wajam\Chrome\wajam.crx [2013-07-10]
CHR HKLM-x32\...\Chrome\Extension: [kfepagcelbegkpkcjgfeecmlnmkedjin] - C:\Program Files (x86)\Browser Guard\browserguard.crx [2013-08-27]
CHR HKLM-x32\...\Chrome\Extension: [kmedakdfngfmagjlndeckcbfcmidlbio] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\15.4.0.5\avg.crx [2013-07-30]
CHR HKLM-x32\...\Chrome\Extension: [niapdbllcanepiiimjjndipklodoedlc] - C:\Users\Kamil1\AppData\Local\Temp\YontooLayers.crx <nicht gefunden>
==================== Dienste (Nicht auf der Ausnahmeliste) ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [930944 2015-12-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [466408 2015-12-02] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [466408 2015-12-02] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1222952 2015-12-02] (Avira Operations GmbH & Co. KG)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [162096 2014-10-09] (Avira Operations GmbH & Co. KG)
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [364544 2008-10-28] (AVM Berlin) [Datei ist nicht signiert]
R3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [437880 2015-08-19] (BlueStack Systems, Inc.)
R3 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413304 2015-08-19] (BlueStack Systems, Inc.)
R3 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [839288 2015-08-19] (BlueStack Systems, Inc.)
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
S4 dgdersvc; C:\Windows\system32\dgdersvc.exe [119632 2010-10-25] (Devguru Co., Ltd.)
S4 dgdersvc; C:\Windows\SysWOW64\dgdersvc.exe [95568 2010-10-25] (Devguru Co., Ltd.)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [Datei ist nicht signiert]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [Datei ist nicht signiert]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [Datei ist nicht signiert]
R2 Giraffic; C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe [2245232 2013-05-13] (Giraffic)
S2 gupdate1ca2f02c329b150; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-09-06] (Google Inc.)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi2\hamachi-2.exe [2546184 2015-11-12] (LogMeIn Inc.)
S2 HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [94208 2008-10-09] (Hewlett-Packard) [Datei ist nicht signiert]
S2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [919040 2014-05-17] (AnchorFree Inc.) [Datei ist nicht signiert]
S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [78512 2014-05-17] ()
R2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [430344 2014-05-16] ()
S4 ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [246520 2010-01-03] ()
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [Datei ist nicht signiert]
S4 IGDCTRL; C:\Program Files (x86)\FRITZ!DSL\IGDCTRL.EXE [87344 2007-09-04] (AVM Berlin)
S2 libusbd; C:\Windows\SysWOW64\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) [Datei ist nicht signiert]
S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [Datei ist nicht signiert]
S4 Macromedia Licensing Service; C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [68096 2010-07-18] () [Datei ist nicht signiert]
S4 MAGIX StartUp Analyze Service; C:\Program Files (x86)\MAGIX\PC_Check_Tuning_2012_Download-Version\MXSAS.exe [181248 2011-09-25] (MAGIX AG) [Datei ist nicht signiert]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [43044512 2015-04-03] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\22.5.5.15\NIS.exe [282016 2015-11-20] (Symantec Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4001816 2010-10-04] (INCA Internet Co., Ltd.)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1864480 2014-05-28] (Overwolf LTD)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2011-07-02] ()
S4 RichVideo; C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe [247152 2008-12-31] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S4 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [380064 2015-04-03] (Microsoft Corporation)
R2 statuscached; C:\Program Files (x86)\SmartSVN 7.5\bin\statuscached.exe [216576 2012-12-19] () [Datei ist nicht signiert]
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert]
S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [297984 2014-04-08] () [Datei ist nicht signiert]
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [745368 2012-11-26] (Tunngle.net GmbH) [Datei ist nicht signiert]
S4 VMLiteService; C:\Program Files\VMLite\VMLite Workstation\VMLiteService.exe [426600 2010-08-21] (VMLite, Inc.)
S3 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [14407384 2014-06-12] ()
S4 vToolbarUpdater15.4.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [1616048 2013-07-30] (AVG Secure Search)
R2 WBC Engine Updater; C:\Program Files\WBC Engine\ExtensionUpdaterService.exe [185856 2013-04-28] () [Datei ist nicht signiert]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-21] (Microsoft Corporation)
S4 WinVNC4; C:\Program Files (x86)\RealVNC\VNC4\WinVNC4.exe [439632 2008-10-15] (RealVNC Ltd.)
S2 StarWindServiceAE; M:\Alcohol 120\StarWind\StarWindServiceAE.exe [X]
===================== Treiber (Nicht auf der Ausnahmeliste) ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [121280 2009-06-11] (SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [121280 2009-06-11] (SlySoft, Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-04-21] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162072 2015-12-02] (Avira Operations GmbH & Co. KG)
S4 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-07-30] (AVG Technologies)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [140448 2015-12-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2008-10-28] (AVM Berlin)
R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\BASHDefs\20150921.003\BHDrvx64.sys [1650936 2015-09-23] (Symantec Corporation)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [146040 2015-08-19] (BlueStack Systems)
S2 BsUDF; C:\Windows\SysWow64\Drivers\BsUDF.sys [449280 2002-09-25] (ahead software) [Datei ist nicht signiert]
R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1605050.00F\ccSetx64.sys [173808 2015-09-23] (Symantec Corporation)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20552 2010-10-25] (Devguru Co., Ltd)
S3 dgderdrv; C:\Windows\SysWOW64\drivers\dgderdrv.sys [18120 2010-10-25] (Devguru Co., Ltd)
S1 DhaHelper; C:\Windows\SysWOW64\drivers\dhahelper.sys [7168 2013-03-31] (MPlayer <hxxp://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) [Datei ist nicht signiert]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-04-02] (DT Soft Ltd)
R1 ElbyCDIO; C:\Windows\SysWOW64\Drivers\ElbyCDIO.sys [9728 2005-01-02] (Elaborate Bytes AG) [Datei ist nicht signiert]
R3 ElbyDelay; C:\Windows\System32\Drivers\ElbyDelay.sys [14032 2007-02-16] (Elaborate Bytes AG)
R3 ElbyDelay; C:\Windows\SysWOW64\Drivers\ElbyDelay.sys [14032 2007-02-16] (Elaborate Bytes AG)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [17480 2013-03-07] () [Datei ist nicht signiert]
S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] () [Datei ist nicht signiert]
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9800 2013-03-07] () [Datei ist nicht signiert]
S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () [Datei ist nicht signiert]
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2008-10-28] (AVM GmbH)
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2014-01-14] (AnchorFree Inc.)
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\IPSDefs\20150930.101\IDSVia64.sys [767224 2015-09-23] (Symantec Corporation)
S3 KORGUMDS; C:\Windows\System32\Drivers\KORGUM64.SYS [34136 2014-05-13] (KORG INC.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-04-21] ()
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
S3 MEMSWEEP2; C:\Windows\system32\5FF2.tmp [6144 2009-06-18] (Sophos Plc) [Datei ist nicht signiert]
S3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\VirusDefs\20151103.001\ENG64.SYS [138488 2015-10-16] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\VirusDefs\20151103.001\EX64.SYS [2148080 2015-10-16] (Symantec Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [Datei ist nicht signiert]
R3 Ps2; C:\Windows\System32\DRIVERS\PS2.sys [21504 2006-09-07] ()
S3 RT73; C:\Windows\System32\DRIVERS\Dr71WU.sys [610816 2008-01-16] (Ralink Technology, Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-05-05] (Duplex Secure Ltd.)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1605050.00F\SRTSP64.SYS [928496 2015-11-12] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1605050.00F\SRTSPX64.SYS [50936 2015-09-23] (Symantec Corporation)
S3 ssudobex; C:\Windows\System32\DRIVERS\ssudobex.sys [201280 2010-09-17] (DEVGURU Co., LTD.(www.devguru.co.kr))
R2 stdmfpam; C:\Program Files (x86)\HomeTab\stdmfpam.dll [67968 2014-12-09] ()
R0 SymEFASI; C:\Windows\System32\drivers\NISx64\1605050.00F\SYMEFASI64.SYS [1621232 2015-11-12] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [111344 2015-11-03] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NISx64\1605050.00F\Ironx64.SYS [297720 2015-09-23] (Symantec Corporation)
R1 SYMTDIv; C:\Windows\System32\Drivers\NISx64\1605050.00F\SYMTDIV.SYS [477400 2015-11-12] (Symantec Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)
S2 TICalc; C:\Windows\SysWow64\Drivers\TICalc.sys [9152 1999-08-30] ()
R1 vmlitedrv; C:\Windows\System32\drivers\vmlitedrv.sys [14952 2010-08-03] (VMLite, Inc.)
R3 vmlitestor; C:\Windows\System32\DRIVERS\vmlitestor.sys [177768 2010-08-11] (VMLite, Inc.)
R1 VMLiteUSBMon; C:\Windows\System32\drivers\vmliteusbmon.sys [135272 2010-08-18] (VMLite, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-10-08] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [33872 2013-02-22] (VMware, Inc.)
R2 {55662437-DA8C-40c0-AADA-2C816A897A49}; c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [27632 2008-09-26] (Cyberlink Corp.)
S1 abpiowke; \??\C:\Windows\system32\drivers\abpiowke.sys [X]
S3 CEDRIVER55; \??\C:\Program Files (x86)\Cheat Engine\dbk64.sys [X]
S3 cpuz135; \??\C:\Users\Kamil1\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S3 dump_wmimmc; \??\C:\AeriaGames\WolfTeam-DE\GameGuard\dump_wmimmc.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 IlvMoneyDRIVER53; \??\C:\Users\Kamil1\AppData\Local\Temp\Rar$EX02.499\ME1320.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 PCD5SRVC{8AAF211B-043E02A9-05040000}; \??\C:\PROGRA~1\PC-DOC~1\PCD5SRVC_x64.pkms [X]
S3 X6va005; \??\C:\Users\Kamil1\AppData\Local\Temp\005E2C9.tmp [X]
S3 X6va006; \??\C:\Users\Kamil1\AppData\Local\Temp\0065B53.tmp [X]
S3 X6va008; \??\C:\Users\Kamil1\AppData\Local\Temp\0087147.tmp [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2025-04-04 14:21 - 2025-04-04 14:21 - 00000000 ____D C:\Users\Kamil1\Documents\Symantec
2025-04-04 04:22 - 2025-04-04 04:22 - 00000000 ____D C:\Users\Kamil1\AppData\Local\WindowsUpdate
2016-01-03 03:34 - 2016-01-03 03:37 - 00245108 _____ C:\Users\Performance\Downloads\Addition.txt
2016-01-03 03:31 - 2016-01-03 03:44 - 00066452 _____ C:\Users\Performance\Downloads\FRST.txt
2016-01-03 03:31 - 2016-01-03 03:44 - 00000000 ____D C:\FRST
2016-01-03 03:30 - 2016-01-03 03:30 - 02370560 _____ (Farbar) C:\Users\Performance\Downloads\FRST64.exe
2016-01-03 03:03 - 2016-01-03 03:03 - 00000000 ____D C:\Users\Performance\AppData\LocalLow\uTorrentBar_DE
2016-01-03 02:57 - 2016-01-03 02:57 - 00151885 _____ C:\Users\Performance\Downloads\ListCWall.rar
2016-01-01 20:19 - 2016-01-01 20:19 - 00105706 _____ C:\Users\Performance\Downloads\3dm-door2.zip
2016-01-01 19:59 - 2016-01-01 19:59 - 00090464 _____ C:\Users\Performance\Downloads\3dm-door1.zip
2015-12-28 17:51 - 2015-12-28 17:51 - 00081308 _____ C:\Users\Performance\Downloads\Dire Straits - Sultans Of Swing (Pro) (2).gp3
2015-12-27 17:28 - 2015-12-27 17:28 - 00131028 _____ C:\Users\Performance\Downloads\my48111w7lds-EXTINGUER (1).rar
2015-12-27 16:34 - 2015-12-27 22:09 - 1022711808 _____ C:\Users\Performance\Downloads\TS3UniLf.part1.rar
2015-12-25 11:03 - 2015-12-25 11:03 - 55853025 _____ C:\Users\Performance\Downloads\com.supercell.clashofclans-8.67.3-APK4Fun.com.apk
2015-12-24 23:55 - 2015-12-24 23:55 - 00081308 _____ C:\Users\Performance\Downloads\Dire Straits - Sultans Of Swing (Pro).gp3
2015-12-24 23:55 - 2015-12-24 23:55 - 00081308 _____ C:\Users\Performance\Downloads\Dire Straits - Sultans Of Swing (Pro) (1).gp3
2015-12-24 13:24 - 2015-12-24 13:25 - 04436732 _____ C:\Users\Performance\Downloads\ClashBot_7.9.2.1716.zip
2015-12-23 12:21 - 2015-12-23 12:21 - 10839076 _____ C:\Users\Performance\Downloads\CB_1701_RB_1701_exclusive.zip
2015-12-23 12:17 - 2015-12-23 12:17 - 03591827 _____ C:\Users\Performance\Downloads\ClashBot_7.9.0.1665 (2).zip
2015-12-20 19:54 - 2015-12-20 19:54 - 00131028 _____ C:\Users\Performance\Downloads\my48111w7lds-EXTINGUER.rar
2015-12-19 11:55 - 2015-12-19 11:56 - 13490513 _____ C:\Users\Performance\Downloads\CF-Auto-Root-m0-m0xx-gti9300 (1).zip
2015-12-19 11:49 - 2015-12-19 11:50 - 16596480 _____ C:\Users\Performance\Downloads\CF-Auto-Root-m0-m0xx-gti9300.zip
2015-12-19 11:10 - 2015-12-19 11:10 - 02900123 _____ C:\Users\Performance\Downloads\SamFirm_v0.3.1.zip
2015-12-19 11:08 - 2015-12-19 11:08 - 01110104 _____ C:\Users\Performance\Downloads\Odin3_v3.10.7.zip
2015-12-19 11:08 - 2015-12-19 11:08 - 00000493 _____ C:\Users\Performance\Downloads\Branding Liste.txt
2015-12-19 10:17 - 2015-12-19 10:17 - 03591827 _____ C:\Users\Performance\Downloads\ClashBot_7.9.0.1665 (1).zip
2015-12-19 00:04 - 2015-12-19 00:04 - 00417609 _____ C:\Users\Performance\Downloads\Bertolti.pdf
2015-12-15 01:23 - 2015-12-15 01:23 - 03591827 _____ C:\Users\Performance\Downloads\ClashBot_7.9.0.1665.zip
2015-12-13 23:52 - 2015-12-13 23:52 - 00002292 _____ C:\Users\Performance\Desktop\nld.txt
2015-12-13 23:49 - 2015-12-13 23:49 - 00003147 _____ C:\Users\Performance\Desktop\HHH.8xp
2015-12-13 23:40 - 2015-12-13 23:49 - 00003147 _____ C:\Users\Performance\Desktop\NLD.8xp
2015-12-11 17:59 - 2015-12-11 17:59 - 03515671 _____ C:\Users\Performance\Downloads\ClashBot_7.9.0.1644.zip
2015-12-10 21:01 - 2015-12-10 21:02 - 00101807 _____ C:\Users\Performance\Downloads\E-Online.pdf
2015-12-09 04:22 - 2015-11-05 10:07 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2015-12-09 04:22 - 2015-11-05 09:55 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2015-12-09 04:22 - 2015-11-05 08:54 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-09 04:19 - 2015-11-02 18:04 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2015-12-09 04:19 - 2015-11-02 17:44 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-09 04:16 - 2015-11-06 18:05 - 00648704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-09 04:16 - 2015-11-06 17:43 - 00820224 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-09 04:16 - 2015-11-06 17:36 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-12-09 04:16 - 2015-11-06 17:36 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-12-09 04:16 - 2015-11-06 17:36 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-12-09 04:16 - 2015-11-06 17:36 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-12-09 04:16 - 2015-11-06 17:32 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2015-12-09 04:16 - 2015-11-06 17:32 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2015-12-09 04:16 - 2015-11-06 17:32 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2015-12-09 04:16 - 2015-11-06 17:32 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2015-12-09 04:16 - 2015-11-06 17:00 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-12-09 04:16 - 2015-11-06 16:59 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-12-09 04:16 - 2015-11-06 16:50 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-12-09 04:16 - 2015-11-06 16:47 - 01561600 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-09 04:16 - 2015-11-06 16:47 - 01154560 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-09 04:16 - 2015-11-06 16:37 - 02799104 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-09 04:16 - 2015-11-06 16:27 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-12-09 04:16 - 2015-11-06 16:26 - 00486400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2015-12-09 04:16 - 2015-11-06 16:20 - 01073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-09 04:16 - 2015-11-06 16:20 - 00682496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2015-12-09 03:21 - 2015-11-05 08:42 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-12-09 03:21 - 2015-11-05 08:26 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-12-09 03:18 - 2015-11-10 18:03 - 01208832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-09 03:18 - 2015-11-10 18:03 - 00488448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-09 03:18 - 2015-11-10 17:40 - 01683968 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-09 03:18 - 2015-11-10 17:40 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-08 20:11 - 2015-11-12 22:16 - 17892864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-08 20:11 - 2015-11-12 22:13 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-08 20:11 - 2015-11-12 22:09 - 10937856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-08 20:11 - 2015-11-12 22:08 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-08 20:11 - 2015-11-12 22:08 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-12-08 20:11 - 2015-11-12 22:07 - 02158080 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-08 20:11 - 2015-11-12 22:07 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-12-08 20:11 - 2015-11-12 22:06 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-08 20:11 - 2015-11-12 22:06 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00579072 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-12-08 20:11 - 2015-11-12 22:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-12-08 20:11 - 2015-11-12 22:06 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-12-08 20:11 - 2015-11-12 22:06 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-12-08 20:11 - 2015-11-12 21:39 - 01814528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-08 20:11 - 2015-11-12 21:37 - 12389376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-08 20:11 - 2015-11-12 21:36 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-12-08 20:11 - 2015-11-12 21:34 - 09753088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-08 20:11 - 2015-11-12 21:34 - 01140224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-08 20:11 - 2015-11-12 21:33 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 01804288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-12-08 20:11 - 2015-11-12 21:32 - 00718848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 00424448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-12-08 20:11 - 2015-11-12 21:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-12-08 20:11 - 2015-11-12 21:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-12-08 20:11 - 2015-11-12 21:31 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-12-08 20:11 - 2015-11-12 21:31 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-12-08 20:11 - 2015-11-12 21:31 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-08 20:11 - 2015-11-12 21:31 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-12-08 20:11 - 2015-11-12 21:31 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-08 20:11 - 2015-11-12 21:31 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2016-01-03 03:43 - 2012-05-08 12:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-03 03:40 - 2011-12-31 14:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Profibot
2016-01-03 03:36 - 2013-02-24 09:18 - 00001052 _____ C:\Windows\Tasks\GinyasBrowserCompanion Chrome Watcher.job
2016-01-03 03:36 - 2006-11-02 14:33 - 00000000 ____D C:\Windows
2016-01-03 03:31 - 2013-02-24 09:18 - 00001052 _____ C:\Windows\Tasks\GinyasBrowserCompanion Stats Report.job
2016-01-03 03:28 - 2013-02-24 09:18 - 00001052 _____ C:\Windows\Tasks\GinyasBrowserCompanion FireFox Watcher.job
2016-01-03 03:22 - 2012-09-19 21:58 - 00000000 ____D C:\Program Files (x86)\Giraffic
2016-01-03 03:18 - 2013-02-24 09:18 - 00001004 _____ C:\Windows\Tasks\GinyasBrowserCompanion Runner.job
2016-01-03 03:11 - 2006-11-02 16:22 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-03 03:11 - 2006-11-02 16:22 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-03 03:03 - 2012-09-07 00:57 - 00000000 ____D C:\ProgramData\SecTaskMan
2016-01-03 03:03 - 2011-05-29 21:48 - 00000000 ____D C:\Program Files (x86)\uTorrentBar_DE
2016-01-03 02:56 - 2012-10-15 19:51 - 00000972 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-269225853-1805347737-3918544349-1013UA.job
2016-01-03 02:50 - 2009-09-06 16:15 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-03 02:47 - 2012-06-22 16:17 - 00001142 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-269225853-1805347737-3918544349-1000UA.job
2016-01-03 02:15 - 2010-02-12 07:05 - 00000000 ____D C:\Program Files (x86)\Zynga
2016-01-03 01:59 - 2015-05-22 14:49 - 00000000 ____D C:\Users\Performance\AppData\Roaming\Spotify
2016-01-03 01:41 - 2013-02-24 09:18 - 00000936 _____ C:\Windows\Tasks\GinyasBrowserCompanion Update Checker.job
2016-01-03 01:23 - 2012-09-19 21:58 - 00000000 ____D C:\ProgramData\Giraffic
2016-01-03 01:21 - 2015-05-10 21:42 - 00000000 ____D C:\Users\Performance\AppData\Local\LogMeIn Hamachi
2016-01-03 01:18 - 2010-05-26 21:23 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-01-03 01:16 - 2015-05-22 14:49 - 00000000 ____D C:\Users\Performance\AppData\Local\Spotify
2016-01-03 01:11 - 2013-10-18 23:10 - 00001376 _____ C:\Windows\Tasks\LyricsMonkey-15-updater.job
2016-01-03 01:11 - 2013-10-18 23:09 - 00001282 _____ C:\Windows\Tasks\LyricsMonkey-15-codedownloader.job
2016-01-03 01:11 - 2013-10-18 23:09 - 00001182 _____ C:\Windows\Tasks\LyricsMonkey-15-enabler.job
2016-01-03 01:11 - 2013-10-18 23:08 - 00001996 _____ C:\Windows\Tasks\LyricsMonkey-15-chromeinstaller.job
2016-01-03 01:11 - 2013-10-18 23:08 - 00001922 _____ C:\Windows\Tasks\LyricsMonkey-15-firefoxinstaller.job
2016-01-03 01:11 - 2013-06-03 15:07 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2016-01-03 01:11 - 2012-09-26 21:20 - 00000380 _____ C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Kamil1.job
2016-01-03 01:11 - 2011-10-30 20:20 - 00000280 _____ C:\Windows\Tasks\MxTray.job
2016-01-03 01:11 - 2010-09-05 16:39 - 00000384 _____ C:\Windows\Tasks\Registry Reviver64-Kamil1-Startup.job
2016-01-03 01:11 - 2009-09-06 16:15 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-03 01:11 - 2009-02-13 09:52 - 00000000 ____D C:\ProgramData\NVIDIA
2016-01-03 01:11 - 2006-11-02 16:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-02 20:56 - 2012-10-15 19:51 - 00000950 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-269225853-1805347737-3918544349-1013Core.job
2016-01-02 17:50 - 2006-11-02 16:42 - 00032562 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-01-02 17:47 - 2012-06-22 16:17 - 00001120 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-269225853-1805347737-3918544349-1000Core.job
2016-01-02 17:20 - 2012-09-26 21:20 - 00000374 _____ C:\Windows\Tasks\ReclaimerUpdateFiles_Kamil1.job
2016-01-02 15:43 - 2012-09-26 21:20 - 00000370 _____ C:\Windows\Tasks\ReclaimerUpdateXML_Kamil1.job
2016-01-01 20:02 - 2015-11-13 19:59 - 00000000 ____D C:\Users\Performance\Desktop\C4D
2015-12-28 11:31 - 2015-05-12 20:44 - 00000000 ____D C:\Users\Performance\AppData\Roaming\TS3Client
2015-12-27 12:46 - 2015-11-21 11:52 - 00000000 ____D C:\Users\Performance\Desktop\Informatik
2015-12-27 12:46 - 2015-05-16 15:57 - 00000000 ____D C:\Users\Performance\AppData\Local\CrashDumps
2015-12-27 01:00 - 2009-07-06 18:25 - 00000456 _____ C:\Windows\Tasks\PCDRScheduledMaintenance.job
2015-12-24 06:18 - 2015-06-04 17:46 - 00000000 ____D C:\Users\Performance\Desktop\Klara
2015-12-23 12:41 - 2015-05-16 14:46 - 00000000 ____D C:\Users\Performance\Desktop\best
2015-12-19 03:12 - 2009-09-06 15:26 - 01882574 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-12-19 03:12 - 2009-02-13 17:40 - 00796488 _____ C:\Windows\system32\perfh007.dat
2015-12-19 03:12 - 2009-02-13 17:40 - 00195770 _____ C:\Windows\system32\perfc007.dat
2015-12-19 03:12 - 2006-11-02 14:33 - 00000000 ____D C:\Windows\inf
2015-12-19 03:12 - 2006-11-02 13:46 - 01882574 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-16 13:48 - 2012-05-08 12:02 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-16 13:48 - 2012-05-08 12:02 - 00003736 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-16 13:48 - 2011-05-30 19:43 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-16 13:44 - 2015-11-08 16:37 - 18362048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-12-16 01:13 - 2015-06-03 18:14 - 00000000 ____D C:\Users\Performance\AppData\Roaming\Media Player Classic
2015-12-14 00:36 - 2015-11-26 00:35 - 00001623 _____ C:\Users\Performance\tilp.ini
2015-12-14 00:36 - 2015-07-01 17:21 - 00000000 ____D C:\Users\Performance\.ticables
2015-12-13 21:07 - 2015-07-01 16:19 - 00000000 ____D C:\Users\Performance\AppData\Local\ApplicationHistory
2015-12-09 05:22 - 2006-11-02 14:33 - 00000000 ____D C:\Windows\rescache
2015-12-09 04:49 - 2006-11-02 16:21 - 05266552 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-09 04:43 - 2014-01-15 22:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-12-09 04:23 - 2010-03-25 00:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-09 04:21 - 2014-01-15 22:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-09 04:16 - 2013-08-18 02:09 - 00000000 ____D C:\Windows\system32\MRT
2015-12-09 03:29 - 2006-11-02 13:35 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-12-07 00:58 - 2015-12-02 22:21 - 00000000 ____D C:\Users\Performance\Desktop\Gabi Bewerb
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2010-12-28 22:11 - 2010-12-28 22:11 - 0008287 _____ () C:\Program Files (x86)\INSTALL.LOG
2012-05-22 14:53 - 2012-05-22 15:27 - 962530584 _____ () C:\Program Files (x86)\ShotOnline_GER_Install.exe
2010-12-28 22:11 - 2010-12-01 11:27 - 2735200 _____ (Conduit Ltd.) C:\Program Files (x86)\tbZyng.dll
2010-12-28 22:11 - 2002-07-26 17:02 - 0153088 _____ () C:\Program Files (x86)\UNWISE.EXE
2015-06-02 20:05 - 2015-10-27 08:29 - 0000132 _____ () C:\Users\Performance\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
2015-05-16 11:28 - 2015-07-19 20:40 - 0001116 _____ () C:\Users\Performance\AppData\Roaming\wklnhst.dat
2015-06-02 15:36 - 2015-11-08 08:58 - 0011776 _____ () C:\Users\Performance\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-01 16:19 - 2015-07-01 16:19 - 0000099 _____ () C:\Users\Performance\AppData\Local\fusioncache.dat
2009-07-13 14:28 - 2011-04-17 19:12 - 0000085 ___SH () C:\ProgramData\.zreglib
2012-06-14 17:18 - 2012-06-14 17:18 - 0000088 __RSH () C:\ProgramData\AF94F39FB3.sys
2012-06-14 17:18 - 2012-10-14 13:03 - 0001890 ___SH () C:\ProgramData\KGyGaAvL.sys
2009-10-05 14:46 - 2012-02-06 16:12 - 0071630 _____ () C:\ProgramData\nvModes.001
2009-10-05 14:45 - 2012-02-06 16:12 - 0071630 _____ () C:\ProgramData\nvModes.dat
Dateien, die verschoben oder gelöscht werden sollten:
====================
C:\ProgramData\C__Users_Kamil1_Desktop_PlatinumHideIP.exe
C:\Users\Kamil1\1.dat
C:\Users\Kamil1\artpclnt.dll
C:\Users\Kamil1\config.exe
C:\Users\Kamil1\devil.dll
C:\Users\Kamil1\DSETUP.dll
C:\Users\Kamil1\errorlog.exe
C:\Users\Kamil1\Erste Ball Bewegung1.exe
C:\Users\Kamil1\granny2.dll
C:\Users\Kamil1\ijl15.dll
C:\Users\Kamil1\ilu.dll
C:\Users\Kamil1\jagex_runescape_preferences.dat
C:\Users\Kamil1\jagex_runescape_preferences2.dat
C:\Users\Kamil1\metin2.exe
C:\Users\Kamil1\metin2client.dat
C:\Users\Kamil1\mscoree.dll
C:\Users\Kamil1\MSS32.DLL
C:\Users\Kamil1\msvcp60.dll
C:\Users\Kamil1\MSVCRTD.DLL
C:\Users\Kamil1\PatchUpdater.exe
C:\Users\Kamil1\patchw32.dll
C:\Users\Kamil1\python22.dll
C:\Users\Kamil1\SpeedTreeRT.dll
C:\Users\Kamil1\unicows.dll
C:\Users\Public\LazyBot.exe
C:\Users\Public\wyUpdate.exe
Einige Dateien in TEMP:
====================
C:\Users\Dr.Bob - Testbenutze\AppData\Local\Temp\avgnt.exe
C:\Users\Dr.Bob - Testbenutze\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpexscei.dll
C:\Users\Dr.Bob - Testbenutze\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Host\AppData\Local\Temp\32B8.exe
C:\Users\Host\AppData\Local\Temp\avgnt.exe
C:\Users\Host\AppData\Local\Temp\i4jdel0.exe
C:\Users\Host\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Host\AppData\Local\Temp\Update Fonts.EXE
C:\Users\Kamil1\AppData\Local\Temp\avgnt.exe
C:\Users\Orhan\AppData\Local\Temp\avgnt.exe
C:\Users\Orhan\AppData\Local\Temp\i4jdel0.exe
C:\Users\Orhan\AppData\Local\Temp\msg564A.exe
C:\Users\Performance\AppData\Local\Temp\avgnt.exe
C:\Users\Performance\AppData\Local\Temp\GLB1A2B.EXE
C:\Users\Performance\AppData\Local\Temp\w2vxu5k4.dll
C:\Users\Standart\AppData\Local\Temp\6291.exe
C:\Users\Standart\AppData\Local\Temp\avgnt.exe
C:\Users\Standart\AppData\Local\Temp\htmlayout.dll
C:\Users\Standart\AppData\Local\Temp\i4jdel0.exe
C:\Users\Standart\AppData\Local\Temp\SkypeSetup.exe
Einige mit null Byte Größe Dateien/Ordner:
==========================
C:\Windows\mstwain32.exe
==================== Bamital & volsnap =================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\Windows\system32\winlogon.exe => Datei ist digital signiert
C:\Windows\system32\wininit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\Windows\explorer.exe => Datei ist digital signiert
C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\Windows\system32\svchost.exe => Datei ist digital signiert
C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\Windows\system32\services.exe => Datei ist digital signiert
C:\Windows\system32\User32.dll => Datei ist digital signiert
C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\Windows\system32\userinit.exe => Datei ist digital signiert
C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\Windows\system32\rpcss.dll => Datei ist digital signiert
C:\Windows\system32\dnsapi.dll => Datei ist digital signiert
C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
testsigning: ==> 'testsigning' ist aktiviert. Prüfung auf eventuelle nicht-signierte Treiber durchführen <===== ACHTUNG
LastRegBack: 2016-01-03 01:27
==================== Ende von FRST.txt ============================ --- --- ---
Leider ist meine Addition.txt Logfile zu lang um sie in den Thread zu posten, und Doppelposting will ich vermeiden. :)
Edit: Was ich vergessen habe noch zu sagen ist, dass bei jedem Start der Testmodus ausgeführt wird, also es steht Testmodus in jeder Ecke und oben die Microsoft Version. Hat das evtl. auch mit dem Virus zu tun? (Dies ist schon etwas länger und hat mich bisher nicht gestört. :)
Gruß Kamil |