Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Werbevirus Oxy (https://www.trojaner-board.de/151756-werbevirus-oxy.html)

Vime 30.03.2014 20:30

Werbevirus Oxy
 
Hallo erstmal,

ich bräuchte eure Hilfe weil ich sehr warscheinlich den Oxy Virus auf meinem PC habe.
Kann die Programme "Oxy" und "Pilefile reminder" von LADY'S WOOD 2013 UNLIMITED nicht unter Programme und Funktionen entfernen obwohl ich der Administrator bin.
Auch wenn ich den PC starte öffnet sich immer ein Programm von Oxy, welches ich schließe doch danach öffnen sich noch 3 weitere und dann ist es vorbei.
Am Anfang war auch so eine Oxy Startseite bei mir in Google Chrome drin, die ich wieder unter Einstellungen entfernt habe und die dazu gehörige Erweiterung auch.
Habe auch einen Malwarebytes Anti-Malware Durchlauf gemacht und dabei sehr viel entdeckt.(im Anhang)

Windows 7 Ultimate 64 bit SP1
AMD Athlon II X2 250
4,0 GB RAM
AMD Radeon HD 6800 Series

sunjojo 30.03.2014 21:25

Hallo Vime, :hallo:

mein Name ist Jonas und ich werde dir bei deiner Bereinigung helfen. Diese kann mit viel Arbeit für dich verbunden sein. Bevor wir anfangen können, lies bitte die Bereinigungsregeln und Hinweise:
Regeln zum Ablauf der Bereinigung
  • Arbeite die Anleitungen und Schritte sorgfältig und nacheinander ab.
  • Wenn du etwas nicht verstehst oder du dir unsicher bist, frage nach und schildere das Problem, so gut es geht. Handle nicht auf eigene Faust.
    • Die Ausführung diverser Bereinigungsprogramme (mit Scripts aus anderen Threads) können dein Betriebssystem zerschießen!
  • Die Bereinigung eines Rechners in verschiedenen Foren zur selben Zeit ist verboten (Crossposting).
  • Installiere oder deinstalliere keine zusätzlichen Programme, lösche keine Dateien und führe nicht selbstständig Systemupdates durch.
  • Die Symptome können verschwunden sein, jedoch bedeutet das Verschwinden von äußeren Merkmalen einer Infektion nicht, dass du wieder clean bist.
    • Ich werde dir ein eindeutiges Clean geben, solange arbeite bitte mit.
Hinweise
  • Ich kann dir nie eine Garantie geben, dass alles entfernt wurde. Die Formatierung der Festplatte und das Neuinstallieren deines Betriebssystems ist immer sicherer und meistens schneller.
  • Die von uns benutzten Programme erstellen meist ein Ergebnisprotokoll (Logfile genannt). Bitte füge alle von mir in einem Schritt geforderten Logfiles in einer Antwort/einem Post ein.
Wenn du alles gelesen hast, kann es losgehen. Bitte speichere alle Programme auf dem Desktop und führe sie von dort aus. :)



Schritt 1
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Poste folgende Logfiles in deiner nächsten Antwort:
  • FRST-Scan

Vime 31.03.2014 13:52

Dankeschön für die schnelle Antwort,
Ich habe schön öfters meine Festplatte formatiert weil ich keine Lust hatte mich schwer mit einem Virus auseinander zu setzen.
Doch ich hab sehr viel gedownloadetes Material da wie z.B World of Warcraft, welches ich dann nur ungerne neu downloaden würde (zeitaufwendig mit einer 2k Leitung).
Hier sind die FRST Files


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by KomaKuh (administrator) on KOMAKUH-PC on 30-03-2014 22:01:42
Running from C:\Users\KomaKuh\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(SlySoft, Inc.) C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM-x32\...\Run: [CloneCDTray] - C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\.DEFAULT\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\.DEFAULT\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [380928 2009-06-14] (AMD)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\MountPoints2: {0b1400c0-4adb-11e3-9f77-806e6f6e6963} - D:\SETUP.EXE
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFA610428EBDECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396204691&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage: hxxp://www.google.com/de
CHR Extension: (Google Docs) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-11]
CHR Extension: (Google Drive) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-11]
CHR Extension: (YouTube) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-11]
CHR Extension: (Adblock Plus) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-11]
CHR Extension: (Google-Suche) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-11]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2013-11-26]
CHR Extension: (Google Wallet) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-11]
CHR Extension: (Google Mail) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-11]
CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\KomaKuh\AppData\Local\foxtab_speeddial.crx [2013-11-11]
CHR HKCU\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\KomaKuh\AppData\Local\foxtab_speeddial.crx [2013-11-11]
CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\KomaKuh\AppData\Local\foxtab_speeddial.crx [2013-11-11]
CHR StartMenuInternet: Google Chrome - Chrome.exe

==================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [766736 2014-02-18] (BlueStack Systems, Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [98560 2014-02-16] (Overwolf LTD)

==================== Drivers (Whitelisted) ====================

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122128 2014-02-18] (BlueStack Systems)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 SaiK1703; C:\Windows\System32\DRIVERS\SaiK1703.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
R3 SaiU1703; C:\Windows\System32\DRIVERS\SaiU1703.sys [47168 2012-09-20] (Saitek)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
U4 SR;
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-30 22:01 - 2014-03-30 22:01 - 00011434 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-03-30 21:59 - 2014-03-30 22:01 - 00000000 ____D () C:\FRST
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 21:29 - 2014-03-30 21:29 - 00002112 _____ () C:\Users\KomaKuh\Desktop\mbam-log-2014-03-30 (20-40-45).txt - Verknüpfung.lnk
2014-03-30 20:39 - 2014-03-30 20:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-30 20:39 - 2014-03-30 20:45 - 00000000 ____D () C:\ProgramData\WPM
2014-03-30 20:38 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
2014-03-30 20:36 - 2014-03-30 20:36 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:42 - 2014-03-30 12:43 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:45 - 2014-03-30 11:52 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:00 - 2014-03-24 22:03 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 21:01 - 2014-03-21 21:22 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 22:58 - 2014-03-17 23:05 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:04 - 2014-03-17 12:05 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-16 19:17 - 2014-03-16 22:11 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 16:37 - 2014-03-16 17:00 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-10 21:49 - 2014-03-19 23:08 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-03-08 23:07 - 2014-03-09 01:28 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-05 11:23 - 2014-03-05 11:46 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks

==================== One Month Modified Files and Folders =======

2014-03-30 22:01 - 2014-03-30 22:01 - 00011434 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-03-30 22:01 - 2014-03-30 21:59 - 00000000 ____D () C:\FRST
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 21:58 - 2013-11-11 16:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-30 21:33 - 2013-11-11 18:33 - 00000296 _____ () C:\Windows\Tasks\FoxTab.job
2014-03-30 21:29 - 2014-03-30 21:29 - 00002112 _____ () C:\Users\KomaKuh\Desktop\mbam-log-2014-03-30 (20-40-45).txt - Verknüpfung.lnk
2014-03-30 21:10 - 2014-01-16 19:46 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Media Player Classic
2014-03-30 21:04 - 2013-11-11 16:16 - 01528404 ____N () C:\Windows\WindowsUpdate.log
2014-03-30 20:54 - 2014-03-30 20:38 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:54 - 2013-11-11 16:19 - 00001417 _____ () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-30 20:53 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-30 20:53 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-30 20:52 - 2010-11-21 08:50 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-03-30 20:52 - 2010-11-21 08:50 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-03-30 20:52 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-30 20:46 - 2013-11-11 16:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-30 20:46 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-30 20:45 - 2014-03-30 20:39 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-30 20:45 - 2014-03-30 20:39 - 00000000 ____D () C:\ProgramData\WPM
2014-03-30 20:39 - 2011-06-11 02:58 - 00773680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-03-30 20:39 - 2011-06-11 02:58 - 00420912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
2014-03-30 20:36 - 2014-03-30 20:36 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-30 17:47 - 2013-11-11 21:07 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\TS3Client
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:42 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:52 - 2014-03-30 11:45 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-30 08:54 - 2013-11-12 22:13 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\Spotify
2014-03-30 08:40 - 2013-11-24 15:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Overwolf
2014-03-30 03:37 - 2013-11-11 19:09 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\TS3Client
2014-03-30 03:19 - 2013-12-08 21:17 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Battle.net
2014-03-29 23:42 - 2014-01-06 22:30 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-03-29 23:31 - 2013-11-11 19:33 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Skype
2014-03-29 08:09 - 2013-11-11 22:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-03-29 08:00 - 2013-11-12 22:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Spotify
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-25 17:21 - 2013-11-11 18:45 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:03 - 2014-03-24 22:00 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:51 - 2014-02-21 21:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\Users\Receful\AppData\Local\PMB Files
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-23 08:42 - 2013-11-24 15:23 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:23 - 2013-11-11 17:16 - 00000000 ____D () C:\ProgramData\AMD
2014-03-21 22:22 - 2013-11-11 16:31 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 22:18 - 2013-11-11 16:26 - 01592628 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-21 22:15 - 2013-12-08 21:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-21 21:22 - 2014-03-21 21:01 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-19 23:08 - 2014-03-10 21:49 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 17:21 - 2013-11-11 17:20 - 00000000 ____D () C:\Users\KomaKuh\Desktop\hintergrund
2014-03-18 17:19 - 2014-02-12 10:51 - 00000000 ____D () C:\Users\KomaKuh\Documents\SelfMV
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 23:05 - 2014-03-17 22:58 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 22:26 - 2013-12-08 21:21 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:05 - 2014-03-17 12:04 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-17 11:30 - 2014-01-01 18:54 - 00000000 ____D () C:\Gothic II
2014-03-16 22:11 - 2014-03-16 19:17 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 17:00 - 2014-03-16 16:37 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:56 - 2014-01-01 18:54 - 00000000 ____D () C:\Program Files (x86)\JoWooD
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-09 01:28 - 2014-03-08 23:07 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-06 12:34 - 2013-11-11 19:33 - 00000000 ____D () C:\ProgramData\Skype
2014-03-05 12:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-03-05 11:46 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:24 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks

Some content of TEMP:
====================
C:\Users\KomaKuh\AppData\Local\Temp\htmlayout.dll
C:\Users\KomaKuh\AppData\Local\Temp\tmp3534.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmpD8B1.exe
C:\Users\Receful\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Receful\AppData\Local\Temp\WTFastSetupOW.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2010-11-21 05:24] - [2011-03-09 18:01] - 2872320 ____A (Microsoft Corporation) 9FF4D976D1696F114A5738842C1C45FF

C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-30 20:15

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---



Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by KomaKuh at 2014-03-30 22:02:00
Running from C:\Users\KomaKuh\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

10,000,000 (HKLM-x32\...\Steam App 227580) (Version:  - EightyEightGames)
123 Free Solitaire v10.0 (HKLM-x32\...\123 Free Solitaire_is1) (Version:  - TreeCardGames)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\{18BBF24A-6D04-4CA4-B6B4-1CF372162EEC}) (Version: 10.2.152.32 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.8 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden
AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.8.6.3059 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{62763BAD-53A8-4C9F-B4CF-7CCABFEFD725}) (Version: 0.8.6.3059 - BlueStack Systems, Inc.)
Call of Duty: Black Ops - Multiplayer (HKLM-x32\...\Steam App 42710) (Version:  - Treyarch)
Call of Duty: Black Ops (HKLM-x32\...\Steam App 42700) (Version:  - Treyarch)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.04 - Piriform)
CloneCD (HKLM-x32\...\CloneCD) (Version:  - SlySoft)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
Cube World version 0.0.1 (HKLM-x32\...\{D692A0E0-1BBB-4E9C-826E-4254EE330830}_is1) (Version: 0.0.1 - Picroma)
Electronic Super Joy (HKLM-x32\...\Steam App 244870) (Version:  - Michael Todd Games)
Final Exam (HKLM-x32\...\Steam App 233190) (Version:  - Mighty Rocket Studio)
Foxtab (HKLM-x32\...\foxtab) (Version:  - FoxTab) <==== ATTENTION
Free YouTube Download version 3.2.30.319 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.30.319 - DVDVideoSoft Ltd.)
Game Booster (HKLM-x32\...\Game Booster_is1) (Version: 2.3.0.0 - IObit)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Gothic II - Die Nacht des Raben (HKLM-x32\...\Gothic II - Die Nacht des Raben) (Version:  - JoWooD Productions Software AG)
Gothic II (HKLM-x32\...\Gothic II) (Version:  - JoWooD Productions Software AG)
Gothic II Addon-Datenbank (HKCU\...\www.mondgesaenge.de - G2ADB) (Version: 3.0 Beta - www.mondgesaenge.de)
Gothic Multiplayer (HKLM-x32\...\Gothic Multiplayer) (Version: 0.1.9 - Gothic Multiplayer Team)
Hammerwatch (HKLM-x32\...\Steam App 239070) (Version:  - )
HashCheck Shell Extension (x86-32) (HKLM-x32\...\HashCheck Shell Extension) (Version: 2.1.11.1 - Kai Liu)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
HydraVision (x32 Version: 4.2.108.0 - ATI Technologies Inc.) Hidden
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
Kingdoms of Amalur: Reckoning™ (HKLM-x32\...\Steam App 102500) (Version:  - Big Huge Games)
K-Lite Codec Pack (64-bit) v4.5.0 (HKLM\...\KLiteCodecPack64_is1) (Version: 4.5.0 - )
K-Lite Codec Pack 7.0.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Launcher omfg.gg (HKCU\...\93bb1775721ec2cc) (Version: 1.0.0.5 - omfg.gg)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Loadout (HKLM-x32\...\Steam App 208090) (Version:  - Edge of Reality)
LOLReplay (HKLM-x32\...\LOLReplay) (Version: 0.8.7 - www.leaguereplays.com)
Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Mark of the Ninja (HKLM-x32\...\Steam App 214560) (Version:  - Klei Entertainment)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MTA:SA v1.3.4 (HKLM-x32\...\MTA:SA 1.3) (Version: v1.3.4 - Multi Theft Auto)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
osu! (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284C}) (Version: 0.0.0.0 - peppy)
Overwolf (HKLM-x32\...\{FE8E927E-8099-4C6B-A337-1CAB00E213C7}) (Version: 0.50.310 - Overwolf)
Oxy (HKCU\...\{9AAF2503-6CD5-414A-B5BA-37639B76C91F}) (Version:  - LADY'S WOOD 2013 LIMITED)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
Path of Exile (HKLM-x32\...\Steam App 238960) (Version:  - Grinding Gear Games)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PileFile reminder (HKCU\...\{56837588-F559-40CF-91D9-D439D405FB28}) (Version:  - LADY'S WOOD 2013 LIMITED)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
puush (HKLM-x32\...\{C3592426-531E-4110-911D-BFECE2CE284B}) (Version: 1.0.0.0 - Dean Herbert)
Realtek 8136 8168 8169 Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0005 - Realtek)
RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version:  - Punk Software)
Rogue Legacy (HKLM-x32\...\Steam App 241600) (Version:  - Cellar Door Games)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.3.13043_14 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.5.3.13043_14 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.34.0 - SAMSUNG Electronics Co., Ltd.)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Smart Technology Programming Software 7.0.27.13 (HKLM\...\{C9193CBB-C31A-412A-A074-AD08F0F2CF3D}) (Version: 7.0.27.13 - Mad Catz)
Spectraball (HKLM-x32\...\Steam App 18300) (Version:  - Shorebound Studios)
Star Wars Battlefront (HKLM-x32\...\{C79CB9C7-10A4-4814-8402-F574672C2192}) (Version: 1.0 - )
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strike Suit Infinity (HKLM-x32\...\Steam App 234160) (Version:  - Born Ready Games Ltd.)
Super Crate Box (HKLM-x32\...\Steam App 212800) (Version:  - Vlambeer)
Super Hexagon (HKLM-x32\...\Super Hexagon_is1) (Version: 1.0 - compiled by testncrash)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
The Binding of Isaac (HKLM-x32\...\Steam App 113200) (Version:  - Edmund McMillen and Florian Himsl)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version:  - Elaborate Bytes)
VLC media player 1.1.7 (HKLM-x32\...\VLC media player) (Version: 1.1.7 - VideoLAN)
WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)

==================== Restore Points  =========================

17-03-2014 12:41:20 Geplanter Prüfpunkt
21-03-2014 20:16:33 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
21-03-2014 20:20:06 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {03BFB27F-3E9D-45DD-A900-065081B91E88} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe <==== ATTENTION
Task: {1946DDF7-9952-4115-B24B-124D9A1D8AF7} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-21] (Microsoft Corporation)
Task: {2555299A-F3E4-4ACD-85BB-9D87DB096EA9} - System32\Tasks\PileFile logon => C:\Users\KomaKuh\AppData\Local\Temp\Goat SimulatorDownload_D1BD\Goat_Simulator_Downloader.exe [2014-03-30] () <==== ATTENTION
Task: {3369FF24-689C-4E71-AE83-81756113BEC1} - System32\Tasks\ASUS\i-Setup153131 => C:\Windows\AMD_Chipset_V307320_Windows7\AsusSetup.exe [2008-08-01] (ASUSTek)
Task: {412E6711-57A1-47A1-BB04-5E52DBE534D7} - System32\Tasks\PileFile reminder => C:\Users\KomaKuh\AppData\Local\Temp\Goat SimulatorDownload_D1BD\Goat_Simulator_Downloader.exe [2014-03-30] () <==== ATTENTION
Task: {733A5972-9BBA-4AFB-AA36-34AE5D37118F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-11] (Google Inc.)
Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe
Task: {A4C75C85-C9DF-41A5-9630-45E29744BC9F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-11] (Google Inc.)
Task: {BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} - System32\Tasks\Oxy => C:\Users\KomaKuh\AppData\Roaming\Oxy\Updater.exe [2014-03-30] () <==== ATTENTION
Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe
Task: {E1CF9038-4982-432F-B54D-C5031EC75380} - System32\Tasks\FoxTab => C:\Users\KomaKuh\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\KomaKuh\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-12-06 17:06 - 2013-12-06 17:06 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
2014-03-15 17:00 - 2014-03-15 02:50 - 13637448 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData:NT
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT
AlternateDataStreams: C:\Users\KomaKuh\Anwendungsdaten:NT
AlternateDataStreams: C:\Users\KomaKuh\AppData\Roaming:NT

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
MSCONFIG\startupreg: KiesAirMessage => C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => "C:\Users\Receful\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Receful\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/30/2014 08:47:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/30/2014 08:46:06 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/30/2014 08:40:46 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/30/2014 08:39:03 AM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/29/2014 02:57:47 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/29/2014 02:56:04 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/28/2014 04:33:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/28/2014 04:31:29 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/27/2014 06:42:24 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/27/2014 06:40:40 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)


System errors:
=============
Error: (03/30/2014 08:46:06 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/30/2014 08:39:03 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/29/2014 02:56:04 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/28/2014 04:31:29 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/27/2014 06:40:40 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/26/2014 07:57:48 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/25/2014 04:12:40 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/24/2014 05:47:13 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/23/2014 08:41:37 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064

Error: (03/22/2014 03:39:18 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064


Microsoft Office Sessions:
=========================
Error: (03/30/2014 08:47:50 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/30/2014 08:46:06 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/30/2014 08:40:46 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/30/2014 08:39:03 AM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/29/2014 02:57:47 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/29/2014 02:56:04 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/28/2014 04:33:12 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/28/2014 04:31:29 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (03/27/2014 06:42:24 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/27/2014 06:40:40 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service.  Service did not stop gracefully the last time it was run.
  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
  bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)


==================== Memory info ===========================

Percentage of memory in use: 38%
Total physical RAM: 4095.11 MB
Available physical RAM: 2498.95 MB
Total Pagefile: 8188.41 MB
Available Pagefile: 6230.27 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:714.74 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 1B163557)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Ich hätte noch eine Frage, bin ich jetzt durch den Virus gefährdet, also das er mir E-Mail Daten oder auch Account Daten von diversen Spielen entnehmen kann ?

sunjojo 31.03.2014 18:00

Hi,

Zitat:

Ich habe schön öfters meine Festplatte formatiert weil ich keine Lust hatte mich schwer mit einem Virus auseinander zu setzen.
Zitat:

Ich hätte noch eine Frage, bin ich jetzt durch den Virus gefährdet, also das er mir E-Mail Daten oder auch Account Daten von diversen Spielen entnehmen kann ?
Ich kann dich erstmal beruhigen. Es sieht danach aus, als ob du nur Adware auf dem Rechner hättest. Deswegen musst du deine Festplatte nicht formatieren und deine Daten sind soweit auch nicht gefährdet, aber neue Passwörter schaden keinem :).



Schritt 1
Bitte deinstalliere folgende Programme:
  • Foxtab
Gehe dafür auf:
Windows XP: Start -> Systemsteuerung -> Kategorieansicht auswählen (falls nicht voreingestellt) -> Software
Windows Vista/7: Start -> Systemsteuerung -> Anzeige (oben-rechts) auf Kategorie stellen (falls nicht voreingestellt) -> Programme deinstallieren (Unterpunkt von Programme)
Windows 8: Suchen --> "Systemsteuerung" in das Suchfeld eingeben --> Systemsteuerung auswählen --> Programme deinstallieren (Unterpunkt von Programme)
und wähle die angegeben Programme aus. Drücke Entfernen (Windows XP) oder Deinstallieren (Windows Vista/7/8).

Schritt 2
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).
Schritt 3
Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop.
SystemLook (64 bit)
  • Doppelklicke auf die SystemLook_x64.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:
    Code:

    :regfind
    PileFile reminder
    Oxy

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich Dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auf dem Desktop als SystemLook.txt gespeichert.

Schritt 4
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.



Poste folgende Logfiles in deiner nächsten Antwort:
  • AdwCleaner-Scan
  • SystemLook-Scan
  • FRST-Scan

Vime 31.03.2014 19:14

Als ich die Systemlookdatei posten wollte hing mehrmals mein Browser und er sendete meinen Post einfach nicht ab weil dort soviel Text vorhanden ist.
Soll ich dann die Systemlookdatei einfach in den Anhang packen?

Und danke dir nochmal Jonas, hast mich echt beruhigt :)

sunjojo 31.03.2014 19:16

Zitat:

Soll ich dann die Systemlookdatei einfach in den Anhang packen?
Kannst du machen, aber bitte wenns geht als Textdatei :).

Vime 31.03.2014 19:38

Hey,

danke dir, die Files kommen sofort :D

Code:

# AdwCleaner v3.022 - Bericht erstellt am 31/03/2014 um 19:13:50
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : KomaKuh - KOMAKUH-PC
# Gestartet von : C:\Users\KomaKuh\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****

Dienst Gelöscht : desksvc
Dienst Gelöscht : IePluginService
Dienst Gelöscht : Wpm

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\IePluginService
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365
Ordner Gelöscht : C:\Program Files (x86)\Desk 365
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Users\KomaKuh\AppData\Local\Temp\Desk365
Ordner Gelöscht : C:\Users\KomaKuh\AppData\Roaming\Desk 365
Ordner Gelöscht : C:\Users\KomaKuh\AppData\Roaming\Oxy
Ordner Gelöscht : C:\Users\KomaKuh\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
Ordner Gelöscht : C:\Users\Receful\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Receful\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchmpbaclbiioedakpcldenooikekokm
Datei Gelöscht : C:\Windows\System32\Tasks\Desk 365 RunAsStdUser
Datei Gelöscht : C:\Windows\Tasks\FoxTab.job
Datei Gelöscht : C:\Windows\System32\Tasks\FoxTab

***** [ Verknüpfungen ] *****

Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk

***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Desk 365]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\Escolade
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\Desksvc
Schlüssel Gelöscht : HKLM\Software\hdcode
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\qone8Software
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\V9
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Desk 365
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wpm

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16736

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v33.0.1750.154

[ Datei : C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ Datei : C:\Users\Receful\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [8664 octets] - [31/03/2014 19:11:44]
AdwCleaner[R1].txt - [8724 octets] - [31/03/2014 19:12:59]
AdwCleaner[S0].txt - [6791 octets] - [31/03/2014 19:13:50]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6851 octets] ##########


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by KomaKuh (administrator) on KOMAKUH-PC on 31-03-2014 19:55:13
Running from C:\Users\KomaKuh\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(SlySoft, Inc.) C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginService\PluginService.exe
(337 Technology Limited.) C:\Program Files (x86)\Desk 365\deskSvc.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM-x32\...\Run: [CloneCDTray] - C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\.DEFAULT\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\.DEFAULT\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [380928 2009-06-14] (AMD)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [Desk 365] - C:\Program Files (x86)\Desk 365\desk365.exe [1017904 2014-03-31] (337 Technology Limited.)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\MountPoints2: {0b1400c0-4adb-11e3-9f77-806e6f6e6963} - D:\SETUP.EXE
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFA610428EBDECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage: hxxp://www.google.com/de
CHR Extension: (Google Docs) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-11]
CHR Extension: (Google Drive) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-11]
CHR Extension: (YouTube) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-11]
CHR Extension: (Adblock Plus) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-11]
CHR Extension: (Google-Suche) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-11]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2013-11-26]
CHR Extension: (Google Wallet) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-11]
CHR Extension: (Google Mail) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-11]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-31]
CHR StartMenuInternet: Google Chrome - Chrome.exe

==================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [766736 2014-02-18] (BlueStack Systems, Inc.)
R2 desksvc; C:\Program Files (x86)\Desk 365\deskSvc.exe [425008 2014-03-31] (337 Technology Limited.)
R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [515584 2014-03-17] (Cherished Technololgy LIMITED)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [98560 2014-02-16] (Overwolf LTD)
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [496640 2014-03-31] (Cherished Technololgy LIMITED)

==================== Drivers (Whitelisted) ====================

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122128 2014-02-18] (BlueStack Systems)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 SaiK1703; C:\Windows\System32\DRIVERS\SaiK1703.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
R3 SaiU1703; C:\Windows\System32\DRIVERS\SaiU1703.sys [47168 2012-09-20] (Saitek)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
U4 SR;
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-31 19:55 - 2014-03-31 19:55 - 00013548 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-03-31 19:30 - 2014-03-31 19:30 - 00018048 _____ () C:\Users\KomaKuh\Downloads\Benotungsschema Praktikumsmappe 9.odt
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Desk 365
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\WPM
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\Desk 365
2014-03-31 19:16 - 2014-03-31 19:53 - 07376130 _____ () C:\Users\KomaKuh\Desktop\SystemLook.txt
2014-03-31 19:16 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-31 19:15 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-31 19:15 - 2014-03-31 19:15 - 00165376 _____ () C:\Users\KomaKuh\Desktop\SystemLook_x64.exe
2014-03-31 19:11 - 2014-03-31 19:14 - 00000000 ____D () C:\AdwCleaner
2014-03-31 19:09 - 2014-03-31 19:12 - 00000475 _____ () C:\Users\KomaKuh\Desktop\Neues Textdokument (4).txt
2014-03-31 19:09 - 2014-03-31 19:09 - 01950720 _____ () C:\Users\KomaKuh\Desktop\adwcleaner.exe
2014-03-31 15:48 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
2014-03-31 15:47 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\Downloads\mausi 3
2014-03-31 15:47 - 2014-03-31 15:47 - 00270615 _____ () C:\Users\KomaKuh\Downloads\Mausi3.zip
2014-03-31 15:27 - 2014-03-31 15:28 - 00000000 ____D () C:\Users\KomaKuh\Desktop\saves FRST
2014-03-31 14:40 - 2014-03-31 19:14 - 00000224 _____ () C:\Windows\setupact.log
2014-03-31 14:40 - 2014-03-31 14:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-30 21:59 - 2014-03-31 19:55 - 00000000 ____D () C:\FRST
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 20:38 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:42 - 2014-03-30 12:43 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:45 - 2014-03-30 11:52 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:00 - 2014-03-24 22:03 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 21:01 - 2014-03-21 21:22 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 22:58 - 2014-03-17 23:05 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:04 - 2014-03-17 12:05 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-16 19:17 - 2014-03-16 22:11 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 16:37 - 2014-03-16 17:00 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-10 21:49 - 2014-03-31 19:42 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-03-08 23:07 - 2014-03-09 01:28 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-05 11:23 - 2014-03-05 11:46 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks

==================== One Month Modified Files and Folders =======

2014-03-31 19:55 - 2014-03-31 19:55 - 00013548 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-03-31 19:55 - 2014-03-30 21:59 - 00000000 ____D () C:\FRST
2014-03-31 19:53 - 2014-03-31 19:16 - 07376130 _____ () C:\Users\KomaKuh\Desktop\SystemLook.txt
2014-03-31 19:44 - 2013-11-27 19:46 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Bewerbung
2014-03-31 19:42 - 2014-03-10 21:49 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-03-31 19:30 - 2014-03-31 19:30 - 00018048 _____ () C:\Users\KomaKuh\Downloads\Benotungsschema Praktikumsmappe 9.odt
2014-03-31 19:22 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-31 19:22 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-31 19:20 - 2010-11-21 08:50 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-03-31 19:20 - 2010-11-21 08:50 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-03-31 19:20 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Desk 365
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\WPM
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\Desk 365
2014-03-31 19:19 - 2011-06-11 02:58 - 00773680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-03-31 19:19 - 2011-06-11 02:58 - 00420912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-03-31 19:16 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-31 19:16 - 2014-03-31 19:15 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-31 19:16 - 2013-11-11 16:19 - 00001201 _____ () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-31 19:15 - 2014-03-31 19:15 - 00165376 _____ () C:\Users\KomaKuh\Desktop\SystemLook_x64.exe
2014-03-31 19:14 - 2014-03-31 19:11 - 00000000 ____D () C:\AdwCleaner
2014-03-31 19:14 - 2014-03-31 14:40 - 00000224 _____ () C:\Windows\setupact.log
2014-03-31 19:14 - 2013-11-11 16:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-31 19:14 - 2013-11-11 16:16 - 01535008 _____ () C:\Windows\WindowsUpdate.log
2014-03-31 19:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-31 19:12 - 2014-03-31 19:09 - 00000475 _____ () C:\Users\KomaKuh\Desktop\Neues Textdokument (4).txt
2014-03-31 19:09 - 2014-03-31 19:09 - 01950720 _____ () C:\Users\KomaKuh\Desktop\adwcleaner.exe
2014-03-31 19:06 - 2013-11-11 16:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-31 18:46 - 2013-11-11 19:33 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Skype
2014-03-31 15:48 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
2014-03-31 15:48 - 2014-03-31 15:47 - 00000000 ____D () C:\Users\KomaKuh\Downloads\mausi 3
2014-03-31 15:48 - 2013-11-17 17:32 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Deployment
2014-03-31 15:47 - 2014-03-31 15:47 - 00270615 _____ () C:\Users\KomaKuh\Downloads\Mausi3.zip
2014-03-31 15:28 - 2014-03-31 15:27 - 00000000 ____D () C:\Users\KomaKuh\Desktop\saves FRST
2014-03-31 15:23 - 2013-11-11 22:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-03-31 15:01 - 2013-11-11 16:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-31 15:01 - 2013-11-11 16:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-31 14:50 - 2013-12-08 21:17 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Battle.net
2014-03-31 14:40 - 2014-03-31 14:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 21:10 - 2014-01-16 19:46 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Media Player Classic
2014-03-30 20:54 - 2014-03-30 20:38 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
2014-03-30 17:47 - 2013-11-11 21:07 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\TS3Client
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:42 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:52 - 2014-03-30 11:45 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-30 08:54 - 2013-11-12 22:13 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\Spotify
2014-03-30 08:40 - 2013-11-24 15:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Overwolf
2014-03-30 03:37 - 2013-11-11 19:09 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\TS3Client
2014-03-29 23:42 - 2014-01-06 22:30 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-03-29 08:00 - 2013-11-12 22:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Spotify
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-25 17:21 - 2013-11-11 18:45 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:03 - 2014-03-24 22:00 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:51 - 2014-02-21 21:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\Users\Receful\AppData\Local\PMB Files
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-23 08:42 - 2013-11-24 15:23 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:23 - 2013-11-11 17:16 - 00000000 ____D () C:\ProgramData\AMD
2014-03-21 22:22 - 2013-11-11 16:31 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 22:18 - 2013-11-11 16:26 - 01592628 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-21 22:15 - 2013-12-08 21:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-21 21:22 - 2014-03-21 21:01 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 17:21 - 2013-11-11 17:20 - 00000000 ____D () C:\Users\KomaKuh\Desktop\hintergrund
2014-03-18 17:19 - 2014-02-12 10:51 - 00000000 ____D () C:\Users\KomaKuh\Documents\SelfMV
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 23:05 - 2014-03-17 22:58 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 22:26 - 2013-12-08 21:21 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:05 - 2014-03-17 12:04 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-17 11:30 - 2014-01-01 18:54 - 00000000 ____D () C:\Gothic II
2014-03-16 22:11 - 2014-03-16 19:17 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 17:00 - 2014-03-16 16:37 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:56 - 2014-01-01 18:54 - 00000000 ____D () C:\Program Files (x86)\JoWooD
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-09 01:28 - 2014-03-08 23:07 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-06 12:34 - 2013-11-11 19:33 - 00000000 ____D () C:\ProgramData\Skype
2014-03-05 12:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-03-05 11:46 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:24 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks

Some content of TEMP:
====================
C:\Users\KomaKuh\AppData\Local\Temp\57638uninstall.exe
C:\Users\KomaKuh\AppData\Local\Temp\93696uninstall.exe
C:\Users\KomaKuh\AppData\Local\Temp\htmlayout.dll
C:\Users\KomaKuh\AppData\Local\Temp\Quarantine.exe
C:\Users\KomaKuh\AppData\Local\Temp\setup.exe
C:\Users\KomaKuh\AppData\Local\Temp\Sqlite3.dll
C:\Users\KomaKuh\AppData\Local\Temp\tmp3534.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp5552.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp6A48.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmpD8B1.exe
C:\Users\Receful\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Receful\AppData\Local\Temp\WTFastSetupOW.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2010-11-21 05:24] - [2011-03-09 18:01] - 2872320 ____A (Microsoft Corporation) 9FF4D976D1696F114A5738842C1C45FF

C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-30 20:15

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---


Es gibt aber ein kleines Problemchen, denn die Systemlookdatei ist 7,02 mb groß, und die Maximalgröße bei txt Dateien liegt bei ungefähr 97,07 KB.
Egal ich versuchs wieder per Post hochzuladen

Ok wenn ich es versuche per Post hochzuladen, lädt er bis zu 100 %, will es dann abschicken und dann ist mein Bild in dem Tab nur noch weiß.
Hier der Link dazu http://www.trojaner-board.de/newrepl...reply&t=151756 :stirn:

sunjojo 31.03.2014 19:40

Zitat:

Egal ich versuchs wieder per Post hochzuladen
Ok, egal, lassen wir erstmal mit dem hochladen. Das wäre sowieso nur gewesen, um die Einträge aus der Uninstall Liste zu entfernen, aber das können wir auch am Ende machen :).

Vime 31.03.2014 20:38

Alles klar, wollte eigentlich nochmal fragen ob ichs irgendwo anders hochladen soll, aber mir solls recht rein :D

Achja mir ist gerade aufgefallen, das Google Chrome recht oft in den Prozessen an ist, obwohl ich es ausgeschaltet habe. Wenn ich die Prozesse dann beende starten sie automatisch nach ungefähr 5 Sekunden wieder. :O

sunjojo 01.04.2014 14:32

Ok, dann so weiter :):



Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

R2 desksvc; C:\Program Files (x86)\Desk 365\deskSvc.exe [425008 2014-03-31] (337 Technology Limited.)
R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [515584 2014-03-17] (Cherished Technololgy LIMITED)
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [496640 2014-03-31] (Cherished Technololgy LIMITED)
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginService\PluginService.exe
(337 Technology Limited.) C:\Program Files (x86)\Desk 365\deskSvc.exe
HKU\.DEFAULT\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [Desk 365] - C:\Program Files (x86)\Desk 365\desk365.exe [1017904 2014-03-31] (337 Technology Limited.)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-31]
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Desk 365
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\WPM
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\Desk 365
2014-03-31 19:16 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-31 19:15 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-30 20:38 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
Task: {BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} - System32\Tasks\Oxy => C:\Users\KomaKuh\AppData\Roaming\Oxy\Updater.exe [2014-03-30] () <==== ATTENTION


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Schritt 2
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Schritt 4
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, wird ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.



Poste folgende Logfiles in deiner nächsten Antwort:
  • FRST-Fix
  • MBAM-Scan
  • ESET-Scan
  • FRST-Scan

Vime 01.04.2014 19:19

Soo hier sind die nächsten Files :)

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by KomaKuh at 2014-04-01 17:59:47 Run:1
Running from C:\Users\KomaKuh\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
R2 desksvc; C:\Program Files (x86)\Desk 365\deskSvc.exe [425008 2014-03-31] (337 Technology Limited.)
R2 IePluginService; C:\ProgramData\IePluginService\PluginService.exe [515584 2014-03-17] (Cherished Technololgy LIMITED)
R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [496640 2014-03-31] (Cherished Technololgy LIMITED)
(Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginService\PluginService.exe
(337 Technology Limited.) C:\Program Files (x86)\Desk 365\deskSvc.exe
HKU\.DEFAULT\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [Desk 365] - C:\Program Files (x86)\Desk 365\desk365.exe [1017904 2014-03-31] (337 Technology Limited.)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\Program Files (x86)\SupTab\SearchProtect64.dll [96768 2014-03-05] (Skytech Co., Ltd.)
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => C:\Program Files (x86)\SupTab\SearchProtect32.dll [85504 2014-03-05] (Skytech Co., Ltd.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.qone8.com/?type=hp&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.qone8.com/web/?type=ds&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586&q={searchTerms}
BHO-x32: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-31]
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Desk 365
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\WPM
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\ProgramData\IePluginService
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-03-31 19:19 - 2014-03-31 19:19 - 00000000 ____D () C:\Program Files (x86)\Desk 365
2014-03-31 19:16 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-31 19:15 - 2014-03-31 19:16 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Oxy
2014-03-30 20:38 - 2014-03-30 20:54 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\qone8
2014-03-30 20:36 - 2014-03-30 20:36 - 00003604 _____ () C:\Windows\System32\Tasks\Oxy
2014-03-30 20:36 - 2014-03-30 20:36 - 00003576 _____ () C:\Windows\System32\Tasks\PileFile reminder
2014-03-30 20:36 - 2014-03-30 20:36 - 00003174 _____ () C:\Windows\System32\Tasks\PileFile logon
Task: {BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} - System32\Tasks\Oxy => C:\Users\KomaKuh\AppData\Roaming\Oxy\Updater.exe [2014-03-30] () <==== ATTENTION
       
*****************

desksvc => Service stopped successfully.
desksvc => Service deleted successfully.
IePluginService => Service stopped successfully.
IePluginService => Service deleted successfully.
Wpm => Service stopped successfully.
Wpm => Service deleted successfully.
C:\ProgramData\WPM\wprotectmanager.exe => No running process found
C:\ProgramData\IePluginService\PluginService.exe => No running process found
C:\Program Files (x86)\Desk 365\deskSvc.exe => No running process found
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetOpenWith => Value deleted successfully.
HKU\S-1-5-21-268757211-819875313-238986870-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Desk 365 => Value deleted successfully.
HKU\S-1-5-21-268757211-819875313-238986870-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInternetOpenWith => Value deleted successfully.
"C:\\PROGRA~2\\SupTab\\SEARCH~2.DLL" => Value Data removed successfully.
"C:\\PROGRA~2\\SupTab\\SEARCH~1.DLL" => Value Data removed successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key deleted successfully.
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma => Key deleted successfully.
C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\SupTab => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\Desk 365 => Moved successfully.
C:\ProgramData\WPM => Moved successfully.
C:\ProgramData\IePluginService => Moved successfully.
C:\Program Files (x86)\SupTab => Moved successfully.
C:\Program Files (x86)\Desk 365 => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\Oxy => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\qone8 => Moved successfully.
C:\Windows\System32\Tasks\Oxy => Moved successfully.
C:\Windows\System32\Tasks\PileFile reminder => Moved successfully.
C:\Windows\System32\Tasks\PileFile logon => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BF8C3626-AE7C-4F2A-8F1A-C5BD3C02D153} => Key deleted successfully.
C:\Windows\System32\Tasks\Oxy not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Oxy => Key deleted successfully.

==== End of Fixlog ====


Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 01.04.2014
Suchlauf-Zeit: 18:32:24
Logdatei: MBAM.txt
Administrator: Ja

Version: 2.00.0.1000
Malware Datenbank: v2014.04.01.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: KomaKuh

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 270664
Verstrichene Zeit: 16 Min, 6 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 1
Trojan.Clicker, C:\Users\KomaKuh\AppData\Local\GCC\Controller.exe, 4408, Löschen bei Neustart, [52aec63a39c751af7bec0a9fe61d13ed]

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 3
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [738de91729d7bb4507165fab19e99a66],
PUP.Optional.Qone8.A, HKLM\SOFTWARE\WOW6432NODE\qone8Software, In Quarantäne, [3fc1cf319769cb35a8ef3b4ffd06db25],
PUP.Optional.Desk365.A, HKLM\SOFTWARE\WOW6432NODE\V9\Desk 365, In Quarantäne, [d828c33dde22718f17c0006c2dd5a55b],

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 18
PUP.Optional.Desk365.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365, In Quarantäne, [728ed7290df34db3a8e988f8b44ffb05],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\en_us, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\es_es, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\pt_br, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\tr_tr, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\zh_cn, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\zh_tw, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\style, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],

Dateien: 65
Trojan.Clicker, C:\Users\KomaKuh\AppData\Local\GCC\Controller.exe, Löschen bei Neustart, [52aec63a39c751af7bec0a9fe61d13ed],
Trojan.Clicker, C:\Users\KomaKuh\AppData\Local\Temp\GCSetup_mk.exe, In Quarantäne, [fb05e41c29d7659b56111f8a22e1dd23],
PUP.Optional.Amonetize.A, C:\Users\KomaKuh\AppData\Local\Temp\OxyBrowserUpdater__3338_i491892894_il6465765.exe, In Quarantäne, [38c8837dbd43c040065480bc18e816ea],
PUP.Optional.Amonetize.A, C:\Users\KomaKuh\AppData\Local\Temp\setup.exe, In Quarantäne, [db2519e7718f0af65703bd7f0bf510f0],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\alilog.dll, In Quarantäne, [55ab34cca25e718f2be864cec9375ea2],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\package1.zip, In Quarantäne, [817f43bd7e8251af987b43ef5da3dd23],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\tmp\desk365.exe, In Quarantäne, [5ea26d934fb16f91b8e751bbed1434cc],
PUP.Optional.SupTab.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\tmp\SupTab.exe, In Quarantäne, [38c84bb532ce58a881caed48e41c827e],
PUP.Optional.WpManager, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396269694\tmp\wpm.exe, In Quarantäne, [3fc1be42da26af51840695c3e9180cf4],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\alilog.dll, In Quarantäne, [e41c29d7f40c4fb1d43fa092c43c17e9],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\package1.zip, In Quarantäne, [21dfcb3507f9b14f31e2be7432ce2ad6],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\tmp\desk365.exe, In Quarantäne, [7e829f61b74919e7d9c662aae61bd62a],
PUP.Optional.SupTab.A, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\tmp\SupTab.exe, In Quarantäne, [7987a15fde2256aacc7f2e0728d8c43c],
PUP.Optional.WpManager, C:\Users\KomaKuh\AppData\Local\Temp\fullpackage_temp1396286173\tmp\wpm.exe, In Quarantäne, [32ce10f028d8827e4743f068748dff01],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\tmp70FD\mp3_qone8.exe, In Quarantäne, [8d7327d9f40c06fa9e9ae965a65b19e7],
PUP.Optional.SkyTech.A, C:\Users\KomaKuh\AppData\Local\Temp\tmp896D\mp3_qone8.exe, In Quarantäne, [44bc2ad6fb057789063275d955ac05fb],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\eInstall.exe, In Quarantäne, [5ea2ff0123dd5da308975daf28d96e92],
PUP.Optional.Desk365.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365\eUninstall.lnk, In Quarantäne, [728ed7290df34db3a8e988f8b44ffb05],
PUP.Optional.Desk365.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365\Desk 365.lnk, In Quarantäne, [728ed7290df34db3a8e988f8b44ffb05],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\SendTo\Desk 365.lnk, In Quarantäne, [8080ac542dd3fe02bb446026a95aff01],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\main, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\msvcp100.dll, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\msvcr100.dll, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\segoeui.ttf, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\segoeuib.ttf, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\app_icon.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\change_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\combo_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\edit_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_back.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_button_skin.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_checked.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_intermediate.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_check_uncheck.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_logo.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\install_resource.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\patch_file_icon.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-error.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-info.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-question.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\pic-warning.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\popup_dialog_bk.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\progressbar_bk.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\progressbar_image.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\radio_normal.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\radio_selected.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\image\default\sys_close.png, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\4zip.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\AirZip.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\edesk.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\Install\gamelogin.inst, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\protocol.txt, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\en_us\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\es_es\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\pt_br\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\language\tr_tr\install_lang.ini, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\eDeskInstall.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\gamelogin.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\install_msgbox.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\languageSelect.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\layout\default\uninstgl.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.Desk365.A, C:\Users\KomaKuh\AppData\Local\Temp\Desk365\eInstall\style\install_style.xml, In Quarantäne, [e41c808005fb13ed815988c904fee818],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\icudt.dll, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\libcef.dll, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],
PUP.Optional.337Technologies.A, C:\Program Files (x86)\Common Files\337\libcef\1.1364.1123\locales\en-US.pak, In Quarantäne, [36ca2ad649b7a15fba2360f11fe3b34d],

Physische Sektoren: 0
(No malicious items detected)


(end)


Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=61e6d2c0060cb74c9137d571bd660410
# engine=17709
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-01 06:07:21
# local_time=2014-04-01 08:07:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 11943964 148005491 0 0
# scanned=253981
# found=0
# cleaned=0
# scan_time=4879



FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by KomaKuh (administrator) on KOMAKUH-PC on 01-04-2014 20:16:05
Running from C:\Users\KomaKuh\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(SlySoft, Inc.) C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\swriter.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Program Files (x86)\VideoLAN\VLC\vlc.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM-x32\...\Run: [CloneCDTray] - C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\.DEFAULT\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\.DEFAULT\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [380928 2009-06-14] (AMD)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-14] (Samsung)
HKU\S-1-5-21-268757211-819875313-238986870-1001\...\MountPoints2: {0b1400c0-4adb-11e3-9f77-806e6f6e6963} - D:\SETUP.EXE

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xFA610428EBDECE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - DefaultScope {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome:
=======
CHR HomePage: hxxp://www.google.com/de
CHR Extension: (Google Docs) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-11]
CHR Extension: (Google Drive) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-11]
CHR Extension: (YouTube) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-11]
CHR Extension: (Adblock Plus) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-11-11]
CHR Extension: (Google-Suche) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-11]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2013-11-26]
CHR Extension: (Google Wallet) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-11]
CHR Extension: (Google Mail) - C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-11]
CHR StartMenuInternet: Google Chrome - Chrome.exe

==================== Services (Whitelisted) =================

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-02-18] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [766736 2014-02-18] (BlueStack Systems, Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [98560 2014-02-16] (Overwolf LTD)

==================== Drivers (Whitelisted) ====================

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122128 2014-02-18] (BlueStack Systems)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-01] (Malwarebytes Corporation)
R3 SaiK1703; C:\Windows\System32\DRIVERS\SaiK1703.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
R3 SaiU1703; C:\Windows\System32\DRIVERS\SaiU1703.sys [47168 2012-09-20] (Saitek)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
U4 SR;
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-01 18:38 - 2014-04-01 18:38 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-01 18:37 - 2014-04-01 18:37 - 02347384 _____ (ESET) C:\Users\KomaKuh\Downloads\esetsmartinstaller_enu.exe
2014-04-01 18:35 - 2014-04-01 18:35 - 00014255 _____ () C:\Users\KomaKuh\Desktop\MBAM.txt
2014-04-01 18:33 - 2014-04-01 18:33 - 00023712 _____ () C:\Windows\PFRO.log
2014-04-01 18:14 - 2014-04-01 18:34 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-01 18:14 - 2014-04-01 18:34 - 00001098 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-01 18:14 - 2014-04-01 18:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-01 18:14 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-01 18:14 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-01 18:10 - 2014-04-01 18:13 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\KomaKuh\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-31 20:37 - 2014-04-01 18:33 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\GCC
2014-03-31 20:37 - 2014-03-31 20:37 - 00004534 _____ () C:\Windows\System32\Tasks\GC_Scheduler
2014-03-31 19:55 - 2014-04-01 20:16 - 00009786 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-03-31 19:30 - 2014-03-31 19:30 - 00018048 _____ () C:\Users\KomaKuh\Downloads\Benotungsschema Praktikumsmappe 9.odt
2014-03-31 19:16 - 2014-03-31 19:53 - 07376130 _____ () C:\Users\KomaKuh\Desktop\SystemLook.txt
2014-03-31 19:15 - 2014-03-31 19:15 - 00165376 _____ () C:\Users\KomaKuh\Desktop\SystemLook_x64.exe
2014-03-31 19:11 - 2014-03-31 19:14 - 00000000 ____D () C:\AdwCleaner
2014-03-31 19:09 - 2014-03-31 19:12 - 00000475 _____ () C:\Users\KomaKuh\Desktop\Neues Textdokument (4).txt
2014-03-31 19:09 - 2014-03-31 19:09 - 01950720 _____ () C:\Users\KomaKuh\Desktop\adwcleaner.exe
2014-03-31 15:48 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
2014-03-31 15:47 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\Downloads\mausi 3
2014-03-31 15:47 - 2014-03-31 15:47 - 00270615 _____ () C:\Users\KomaKuh\Downloads\Mausi3.zip
2014-03-31 15:27 - 2014-03-31 15:28 - 00000000 ____D () C:\Users\KomaKuh\Desktop\saves FRST
2014-03-31 14:40 - 2014-04-01 18:33 - 00000336 _____ () C:\Windows\setupact.log
2014-03-31 14:40 - 2014-03-31 14:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-30 21:59 - 2014-04-01 20:16 - 00000000 ____D () C:\FRST
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:42 - 2014-03-30 12:43 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:45 - 2014-03-30 11:52 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:00 - 2014-03-24 22:03 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 21:01 - 2014-03-21 21:22 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 22:58 - 2014-03-17 23:05 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:04 - 2014-03-17 12:05 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-16 19:17 - 2014-03-16 22:11 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 16:37 - 2014-03-16 17:00 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-10 21:49 - 2014-04-01 19:46 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-03-08 23:07 - 2014-03-09 01:28 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-05 11:23 - 2014-03-05 11:46 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks

==================== One Month Modified Files and Folders =======

2014-04-01 20:16 - 2014-03-31 19:55 - 00009786 _____ () C:\Users\KomaKuh\Desktop\FRST.txt
2014-04-01 20:16 - 2014-03-30 21:59 - 00000000 ____D () C:\FRST
2014-04-01 20:06 - 2013-11-11 16:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-01 19:46 - 2014-03-10 21:49 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Betriebspraktikum
2014-04-01 18:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-01 18:40 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-01 18:38 - 2014-04-01 18:38 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-01 18:38 - 2010-11-21 08:50 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-04-01 18:38 - 2010-11-21 08:50 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-04-01 18:38 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-01 18:37 - 2014-04-01 18:37 - 02347384 _____ (ESET) C:\Users\KomaKuh\Downloads\esetsmartinstaller_enu.exe
2014-04-01 18:36 - 2013-11-11 16:16 - 01541940 _____ () C:\Windows\WindowsUpdate.log
2014-04-01 18:35 - 2014-04-01 18:35 - 00014255 _____ () C:\Users\KomaKuh\Desktop\MBAM.txt
2014-04-01 18:34 - 2014-04-01 18:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-01 18:34 - 2014-04-01 18:14 - 00001098 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-01 18:33 - 2014-04-01 18:33 - 00023712 _____ () C:\Windows\PFRO.log
2014-04-01 18:33 - 2014-03-31 20:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\GCC
2014-04-01 18:33 - 2014-03-31 14:40 - 00000336 _____ () C:\Windows\setupact.log
2014-04-01 18:33 - 2013-11-11 16:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-01 18:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-01 18:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-04-01 18:27 - 2013-11-11 19:33 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Skype
2014-04-01 18:14 - 2014-04-01 18:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-01 18:14 - 2013-11-11 17:25 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Malwarebytes
2014-04-01 18:14 - 2013-11-11 17:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-01 18:13 - 2014-04-01 18:10 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\KomaKuh\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-31 20:37 - 2014-03-31 20:37 - 00004534 _____ () C:\Windows\System32\Tasks\GC_Scheduler
2014-03-31 19:53 - 2014-03-31 19:16 - 07376130 _____ () C:\Users\KomaKuh\Desktop\SystemLook.txt
2014-03-31 19:44 - 2013-11-27 19:46 - 00000000 ____D () C:\Users\KomaKuh\Desktop\Bewerbung
2014-03-31 19:30 - 2014-03-31 19:30 - 00018048 _____ () C:\Users\KomaKuh\Downloads\Benotungsschema Praktikumsmappe 9.odt
2014-03-31 19:19 - 2011-06-11 02:58 - 00773680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-03-31 19:19 - 2011-06-11 02:58 - 00420912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-03-31 19:16 - 2013-11-11 16:19 - 00001201 _____ () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-31 19:15 - 2014-03-31 19:15 - 00165376 _____ () C:\Users\KomaKuh\Desktop\SystemLook_x64.exe
2014-03-31 19:14 - 2014-03-31 19:11 - 00000000 ____D () C:\AdwCleaner
2014-03-31 19:12 - 2014-03-31 19:09 - 00000475 _____ () C:\Users\KomaKuh\Desktop\Neues Textdokument (4).txt
2014-03-31 19:09 - 2014-03-31 19:09 - 01950720 _____ () C:\Users\KomaKuh\Desktop\adwcleaner.exe
2014-03-31 15:48 - 2014-03-31 15:48 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
2014-03-31 15:48 - 2014-03-31 15:47 - 00000000 ____D () C:\Users\KomaKuh\Downloads\mausi 3
2014-03-31 15:48 - 2013-11-17 17:32 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Deployment
2014-03-31 15:47 - 2014-03-31 15:47 - 00270615 _____ () C:\Users\KomaKuh\Downloads\Mausi3.zip
2014-03-31 15:28 - 2014-03-31 15:27 - 00000000 ____D () C:\Users\KomaKuh\Desktop\saves FRST
2014-03-31 15:23 - 2013-11-11 22:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-03-31 15:01 - 2013-11-11 16:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-31 15:01 - 2013-11-11 16:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-31 14:50 - 2013-12-08 21:17 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Battle.net
2014-03-31 14:40 - 2014-03-31 14:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-30 21:58 - 2014-03-30 21:58 - 02157056 _____ (Farbar) C:\Users\KomaKuh\Desktop\FRST64.exe
2014-03-30 21:10 - 2014-01-16 19:46 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Media Player Classic
2014-03-30 17:47 - 2013-11-11 21:07 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\TS3Client
2014-03-30 12:45 - 2014-03-30 12:45 - 03331554 _____ () C:\Users\Receful\Downloads\15657-svu-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:43 - 02450164 _____ () C:\Users\Receful\Downloads\15428-ump-45-v-2.0-gtasa.zip
2014-03-30 12:43 - 2014-03-30 12:42 - 02084593 _____ () C:\Users\Receful\Downloads\120744-m1-garand-gtasa.zip
2014-03-30 12:41 - 2014-03-30 12:41 - 03200937 _____ () C:\Users\Receful\Downloads\120535-avtorifle-acw-r-gtasa.zip
2014-03-30 12:34 - 2014-03-30 12:34 - 03282233 _____ () C:\Users\Receful\Downloads\89977-desert-eagle-hd-gtasa.zip
2014-03-30 12:24 - 2014-03-30 12:24 - 00000000 ____D () C:\Users\Receful\Desktop\Alcis IMG Editor
2014-03-30 12:21 - 2014-03-30 12:21 - 02784984 _____ () C:\Users\Receful\Downloads\Alcis IMG Editor.rar
2014-03-30 11:52 - 2014-03-30 11:45 - 00000301 _____ () C:\Users\Receful\Desktop\Neues Textdokument.txt
2014-03-30 08:54 - 2013-11-12 22:13 - 00000000 ____D () C:\Users\Receful\AppData\Roaming\Spotify
2014-03-30 08:40 - 2013-11-24 15:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Overwolf
2014-03-30 03:37 - 2013-11-11 19:09 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\TS3Client
2014-03-29 23:42 - 2014-01-06 22:30 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-03-29 08:00 - 2013-11-12 22:16 - 00000000 ____D () C:\Users\Receful\AppData\Local\Spotify
2014-03-29 04:23 - 2014-03-29 04:23 - 00000807 _____ () C:\Users\Receful\Downloads\listen.asx
2014-03-25 17:21 - 2013-11-11 18:45 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
2014-03-24 22:06 - 2014-03-24 22:06 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-24 22:03 - 2014-03-24 22:00 - 32734976 _____ (DVDVideoSoft Ltd. ) C:\Users\KomaKuh\Downloads\FreeYouTubeDownload.exe
2014-03-23 17:51 - 2014-02-21 21:27 - 00000000 ____D () C:\Program Files (x86)\LOLReplay
2014-03-23 17:50 - 2014-03-23 17:50 - 01469184 _____ () C:\Users\KomaKuh\Downloads\LOLReplay-0.8.7.exe
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\Users\Receful\AppData\Local\PMB Files
2014-03-23 16:30 - 2013-11-30 01:31 - 00000000 ____D () C:\ProgramData\PMB Files
2014-03-23 08:42 - 2013-11-24 15:23 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-03-21 22:23 - 2014-03-21 22:23 - 00060993 _____ () C:\Windows\SysWOW64\CCCInstall_201403212123060303.log
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\ProgramData\ATI
2014-03-21 22:23 - 2014-03-21 22:23 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-03-21 22:23 - 2013-11-11 17:16 - 00000000 ____D () C:\ProgramData\AMD
2014-03-21 22:22 - 2013-11-11 16:31 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-03-21 22:21 - 2014-03-21 22:21 - 00000000 ____D () C:\Program Files\AMD
2014-03-21 22:18 - 2013-11-11 16:26 - 01592628 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-21 22:15 - 2013-12-08 21:17 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-21 21:22 - 2014-03-21 21:01 - 212753896 _____ (Advanced Micro Devices, Inc.) C:\Users\KomaKuh\Downloads\13-12_win7_win8_64_dd_ccc_whql.exe
2014-03-18 21:56 - 2014-03-18 21:56 - 00000013 _____ () C:\Users\KomaKuh\Desktop\geil.txt
2014-03-18 17:21 - 2013-11-11 17:20 - 00000000 ____D () C:\Users\KomaKuh\Desktop\hintergrund
2014-03-18 17:19 - 2014-02-12 10:51 - 00000000 ____D () C:\Users\KomaKuh\Documents\SelfMV
2014-03-18 16:34 - 2014-03-18 16:34 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-03-18 16:30 - 2014-03-18 16:30 - 00000000 ____D () C:\Users\Public\Documents\CrashDump
2014-03-17 23:05 - 2014-03-17 22:58 - 00000000 ____D () C:\Users\KomaKuh\Desktop\töhöhö
2014-03-17 22:26 - 2013-12-08 21:21 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-17 19:12 - 2014-03-17 19:12 - 00000610 _____ () C:\Users\KomaKuh\Desktop\Süß Sauer Mecces (1).txt
2014-03-17 12:05 - 2014-03-17 12:04 - 00000019 _____ () C:\Users\KomaKuh\Desktop\Ymrionn.txt
2014-03-17 11:30 - 2014-01-01 18:54 - 00000000 ____D () C:\Gothic II
2014-03-16 22:11 - 2014-03-16 19:17 - 00035067 _____ () C:\Gothic.RPT
2014-03-16 17:00 - 2014-03-16 16:37 - 00000743 _____ () C:\Users\KomaKuh\Desktop\Ymironn.lnk
2014-03-16 16:56 - 2014-01-01 18:54 - 00000000 ____D () C:\Program Files (x86)\JoWooD
2014-03-16 16:37 - 2014-03-16 16:37 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
2014-03-09 01:28 - 2014-03-08 23:07 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-03-08 23:07 - 2014-03-08 23:07 - 00000000 ____D () C:\ProgramData\Picroma
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\Documents\SavedGames
2014-03-08 00:45 - 2014-03-08 00:45 - 00000000 ____D () C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 12:34 - 2014-03-06 12:34 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Skype
2014-03-06 12:34 - 2013-11-11 19:33 - 00000000 ____D () C:\ProgramData\Skype
2014-03-05 12:26 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-03-05 11:46 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-03-05 11:24 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Users\KomaKuh\AppData\Local\Bluestacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-03-05 11:23 - 2014-03-05 11:23 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-03-05 09:26 - 2014-04-01 18:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-01 18:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2013-11-11 17:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

Some content of TEMP:
====================
C:\Users\KomaKuh\AppData\Local\Temp\57638uninstall.exe
C:\Users\KomaKuh\AppData\Local\Temp\93696uninstall.exe
C:\Users\KomaKuh\AppData\Local\Temp\htmlayout.dll
C:\Users\KomaKuh\AppData\Local\Temp\Quarantine.exe
C:\Users\KomaKuh\AppData\Local\Temp\Sqlite3.dll
C:\Users\KomaKuh\AppData\Local\Temp\tmp3534.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp5300.tmp.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp5552.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp6A48.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmp6DE1.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmpD877.exe
C:\Users\KomaKuh\AppData\Local\Temp\tmpD8B1.exe
C:\Users\Receful\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Receful\AppData\Local\Temp\WTFastSetupOW.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2010-11-21 05:24] - [2011-03-09 18:01] - 2872320 ____A (Microsoft Corporation) 9FF4D976D1696F114A5738842C1C45FF

C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-30 20:15

==================== End Of Log ============================

--- --- ---

sunjojo 01.04.2014 21:53

Ok, wenn du jetzt keine weiteren Probleme mehr hast, sind wir fertig :).



Schritt 1
Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
  • Öffne die TFC.exe.
    Vista und Win 7 User mit Rechtsklick "als Administrator starten".
  • Schließe alle anderen Programme.
  • Drücke auf den Button Start.
  • Falls du zu einem Neustart aufgefordert wirst, bestätige diesen.

Updates
Internet Explorer 11
  • Lade dir bitte den Internet Explorer 11 herunter und installiere diesen. Auch wenn du den Internet Explorer nicht primär verwenden solltest, ist es trotzdem wichtig, diesen aktuell zu halten.

Java Version 7 Update 51
Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 7 Update 51 ) herunter laden.
  • Entferne den Haken bei "Installieren Sie die Ask-Toolbar ..." während der Installation.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Haken gesetzt ist und klicke OK.
  • Klicke erneut OK.

Adobe Reader Version XI (11.0.06)
Adobe Flash Player Version 12.0.0.77
  • Deinstalliere bitte deine aktuelle(n) Version(en) des Adobe Flash Players.
  • Lade dir die neuste Version hier herunter: Adobe - Adobe Flash Player installieren
  • Entferne den Hacken für das optionale Angebot "McAfee Security Scan Plus".

Cleanup
Falls du Malwarebytes Anti-Malware und den ESET Online Scanner nicht mehr behalten möchtest, kannst du diese über die Systemsteuerung deinstallieren. Ich empfehle dir, mindestens ein Programm zu behalten (näheres in den Tipps).
Windows XP: Start --> Systemsteuerung --> Kategorieansicht auswählen (falls nicht voreingestellt) --> Software
Windows Vista/7: Start --> Systemsteuerung --> Anzeige (oben-rechts) auf Kategorie stellen (falls nicht voreingestellt) --> Programme deinstallieren (Unterpunkt von Programme)
Windows 8: Suchen --> "Systemsteuerung" in das Suchfeld eingeben --> Systemsteuerung auswählen --> Programme deinstallieren (Unterpunkt von Programme)
Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



In deinen Logfiles sehe ich im Moment keine schädlichen Einträge mehr, du bist in meinen Augen Clean. Für die Zukunft habe ich dir Tipps aufgeschrieben, damit du uns in nächster Zeit nicht mehr brauchst :).




Tipps - Frequently Asked Questions (FAQ)/Häufig gestellte Fragen

Welcher Antivirenscanner ist der Beste?
  • Die Antwort auf die Frage ist im Grunde einfach: keiner. Es gibt keinen Antivirenscanner, der immer alle Schädlinge sofort erkennt und dich 100%ig schützt. Alles vom Menschen geschaffene ist fehlerhaft und es ist ratsam, sich nur begrenzt darauf zu verlassen. Das heißt nicht, dass die Verwendung eines Antivirenprogramms keinen Sinn macht, aber es sollte als zusätzliche Hilfe angesehen werden. Die Hauptverantwortung liegt bei dir und deinem Verhalten im Internet selbst.
  • Benutze nur einen Antivirenscanner/Hintergrundwächter, niemals zwei oder mehrere. Diese könnten sich gegenseitig blockieren und dir mehr schaden, als helfen. Es ist nicht unbedingt nötig, sich kostenpflichtige Antivirenprogramme für viel Geld zu kaufen. Achte darauf, dass immer die neuesten Updates heruntergeladen werden. Ein veralteter Antivirenscanner ist nutzlos!
  • Außerdem kannst du dein Betriebssystem mit On-Demand Sannern überprüfen. Solche Scanner laufen nicht permanent im Hintergrund, sondern scannen nur "auf Knopfdruck" dein System. Damit holst du dir eine zweite Meinung ein. Gute On-Demand Scanner, die auch wir zur Kontrolle benutzen, sind Malwarebytes Anti Malware und der ESET Online Scanner.
    • Malwarebytes Anti-Malware (Anleitung zur Verwendung) ist eines der besten und zuverlässigsten Programme in der Malwareentfernung. Scanne dein System einmal pro Woche oder einmal in zwei Wochen.
    • Der ESET Online Scanner (Anleitnung zur Verwendung) ist kostenlos und scannt dein System und deine Dateien sehr gründlich. Deswegen kann der Scan bei vielen Dateien mehrere Stunden dauern. Scanne dein System nach deinem eigenem Ermessen. Falls schädliche Dateien gefunden werden, handle nicht eigenmächtig!
Aber Updates muss ich immer installieren, oder?
  • Die Aktualität von Software ist sehr wichtig und unbedingt notwendig. Veraltete Programme stellen Schwachstellen dar, die sich Angreifer gerne zur Nutze machen. Daher ist es wichtig, immer die neueste Version der jeweiligen Software installiert zu haben. Dies fängt beim Betriebssystem an. Du solltest das neueste Service Pack installiert und automatische Updates eingeschaltet haben.
    Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
    Windows 8: Suchen --> "Systemsteuerung" in das Suchfeld eingeben --> Systemsteuerung auswählen --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Häufig werden Sicherheitslücken von älteren Java Versionen, dem Flash-Player und PDF-Reader ausgenutzt. Du kannst hier überprüfen, ob diese häufig missbrauchte Software aktuell ist: PluginCheck
Ok, muss ich auf etwas achten, wenn ich im Internet surfe?
  • Mit dem richtigen Verhalten im Internet fängt der Schutz vor Infektionen an. Es gibt inzwischen viele virtuelle Betrugsversuche oder Tricks zum Täuschen, sowie im echten Leben. Um sich dort zu schützen, hast du bestimmte Angewohnheiten. Diese können auf das Surfverhalten übertragen werden. Zur Verdeutlichung stelle ich dir einen kleinen Vergleich zum Leben her:

    Verhalten im LebenVerhalten im Internet
    Du überprüfst vorher die Läden, in denen du einkaufst.Klicke nicht auf alle Seiten/Werbungen/PopUps, weil diese bunt sind oder tolle Preise versprechen.
    Du achtest auf die Qualität, wenn du Produkte kaufst.Lade dir Programme nur von original Herstellerseiten herunter und nicht von Softonic oder ähnlichem. Diese birgen häufig die Gefahr, sich zusätzlich Adware herunterzuladen.
    Du öffnest keine Briefe oder Pakete ohne zu gucken, von wem diese sind.Öffne nur Anhänge von Emails, wenn der Absender bekannt ist. Überprüfe, ob zum Beispiel eine Rechnung im Anhang wirklich von der Firma versendet wurde. Häufig werden gefälschte Emails mit schädlichem Anhang verschickt!

    Handle mit Bedacht und überlege zuerst, bevor du etwas anklickst, herunterlädst oder öffnest!
  • Vermeide das Besuchen von pornographischen, Pokerspiel oder weiteren dubiosen Webseiten. Diese birgen ein besonders großes Infektionsrisiko.
Welche Programme sollte ich nicht verwenden?
  • Wenn du neue Software installierst, besteht häufig die Auswahl, eine weitere Toolbar (oder ähnliches) zu installieren. Entferne generell den Haken bei optionalen Zusatzprogrammen. Diese verlangsamen in der Regel deinen Browser und können ein erhöhtes Infektionsrisiko bedeuten.
  • Registry Cleaner versprechen meist einen großen Performancegewinn, wenn verwaiste Einträge in der Regsitry entfernt werden. Dieser angebliche Gewinn ist kaum bis gar nicht bemerkbar. Außerdem wird häufig verschwiegen, dass falsche Änderungen der Registry zu schwerwiegenden Folgen führen können. Deswegen sollte so wenig wie möglich an der Registry verändert werden. Zerstörst du die Registry, zerstörst du Windows!
  • Filesharing oder Peer-to-Peer Programme ermöglichen es, Dateien mit anderen Nutzern auszutauschen. Es ist möglich, dass du dir eine infizierte Datei herunterlädst (auch versteckt in angeblich legalen Versionen von bekannten Programmen). Du kannst niemals wissen, woher diese stammen. Daher sollte diese Art von Software mit äußerster Vorsicht oder gar nicht benutzt werden.
    • Lade dir vor allem keine Cracks (illegale Versione einer Software) herunter. Das ist rechtlich nicht erlaubt und du kannst dafür bestraft werden. Außerdem ist bei solcher Software das Infektionsrisiko am höchsten, da Cracks sehr häufig versteckte Malware enthalten.
Gibt es noch weitere Tipps, um mich zu schützen?
  • Achte auf die Endung von Dateien, die dir zugesendet wurden. Häufig versuchen Malwareschreiber mit Tricks wie Rechnung.pdf.exe dich zu täuschen. Wenn die Dateiendung ausgeblendet wird, bleibt Rechnung.pdf übrig, was den Anschein einer normalen PDF-Datei macht. Lass dir daher bekannte Dateiendung anzeigen (Anleitung: http://www.trojaner-board.de/59624-a...-sichtbar.html)
  • Surfe mit einem Konto mit eingeschränkten Rechten. Durch Administratorrechte kann Malware ohne Probleme zahlreiche Änderungen am System vornehmen, zum Beispiel Sicherheitseinstellungen verändern oder auf Systemdateien zugreifen.
  • Verwende nicht immer das gleiche Passwort. Falls dein Passwort durch entsprechende Malware herausgefunden wird, könnte auf alle Konten von dir zugegriffen werden.
  • Lege in regelmäßigen Abständen Backups (Was sind Backups?) von deinem System an. Dadurch ist ein Datenverlust durch Malware oder Hardwareschäden verkraftbar und es ist vergleichsweise einfach, den Rechner auf den Stand des letzten Backups zu bringen. Damit du deine Daten nicht manuell sichern musst, gibt es Backup-Programme wie Paragon Backup & Recovery.
  • Deaktiviere das Autorun-Feature von Windows. Dies ermöglicht, dass zum Beispiel CDs, DVDs oder Programme auf USB-Sticks alleine starten. Häufig nutzen Malwareschreiber genau diese Funktion aus. In solchen Fällen befindet sich Malware auf dem USB-Stick und wird automatisch beim Anschließen an den Computer ausgeführt. Um das zu verhinden, deaktiviere die Autorun-Funktion: http://www.trojaner-board.de/83238-a...sschalten.html.


Wenn du die Arbeit des Trojaner-Boards unterstützen möchtest, kannst du gerne spenden :).

Ich wünsche dir eine schöne und malwarefreie Zeit :daumenhoc.

Vime 02.04.2014 12:43

Danke dir für alles Jonas, kann mein PC endlich starten ohne dass ich von Oxy direkt gestört werde :D

Hätte noch eine Frage, und zwar wenn ich meinen PC wieder starte und Google Chrome öffne, ist immer noch die Startseite von oxy namens qone8 offen, weswegen ich bei jedem PC Start die Startseite meines Browsers ändern muss. Kannst du mir da irgend nen Rat geben ?

Auch ist qone8 nicht mehr als Startseite festgelegt erscheint aber trotzdem nach jedem Start

sunjojo 02.04.2014 18:14

Zitat:

Hätte noch eine Frage, und zwar wenn ich meinen PC wieder starte und Google Chrome öffne, ist immer noch die Startseite von oxy namens qone8 offen, weswegen ich bei jedem PC Start die Startseite meines Browsers ändern muss. Kannst du mir da irgend nen Rat geben ?

Auch ist qone8 nicht mehr als Startseite festgelegt erscheint aber trotzdem nach jedem Start
Nur bei Google Chrome? Mach bitte mal folgendes:



Schritt 1
Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
  • Starte die sc-cleaner.exe mit einem Doppelclick.
  • Bestätige die Meldung Shortcut Cleaner Finished am Ende des Suchlaufs mit Ok.
  • Eine Logdatei wird sich öffnen (sc-cleaner.txt).
  • Poste den Inhalt mit deiner nächsten Antwort.


Besteht das Problem immernoch?

Vime 02.04.2014 18:34

Also, es im IE ist es auch als Startseite, obwohl bei Startseite www.google.com angegeben ist.


Code:

Shortcut Cleaner 1.3.1 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
 hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/

Windows Version: Windows 7 Ultimate Service Pack 1
Program started at: 04/02/2014 07:29:14 PM.

Scanning for registry hijacks:

 * No issues found in the Registry.

Searching for Hijacked Shortcuts:

Searching C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\

Searching C:\ProgramData\Microsoft\Windows\Start Menu\

Searching C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\

Searching C:\Users\Public\Desktop\

Searching C:\Users\KomaKuh\Desktop


0 bad shortcuts found.

Program finished at: 04/02/2014 07:29:17 PM
Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s)

Soll ich dir den Link der Startseite mal schicken ? :D

Auf der Seite passiert nichts bis auf "Werbung", und wollte es ehrlich gesagt nich ausprobieren irgendwo drauf zu drücken, immer direkt neuen Tab gestartet.

sunjojo 02.04.2014 18:44

Zitat:

Auf der Seite passiert nichts bis auf "Werbung", und wollte es ehrlich gesagt nich ausprobieren irgendwo drauf zu drücken, immer direkt neuen Tab gestartet.
Hartnäckig das Teil. Mach mal bitte folgendes:


Schritt 1
Öffne deinen Google Chrome Browser.
  • Klicke auf das Chrome-Menü http://www.trojaner-board.de/picture...&pictureid=489 (rechts im Browser).
  • Wähle nun "Einstellungen" in dem Menü aus.
  • Scrolle nach unten und klicke "Erweiterte Einstellungen anzeigen" an.
  • Nun werden dir weitere Optionen angezeigt. Wähle http://www.trojaner-board.de/picture...&pictureid=490 aus (letzter Punkt der Einstellungsmöglichkeiten).
  • Ein Fenster wird geöffnet, in welchem du "Zurücksetzen" auswählst.
  • Jetzt werden deine aktuellen Browsereinstellungen zurückgesetzt (Startseite, Suchseite, ...), Erweiterungen und Designs deaktiviert.

Schritt 2
Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden ).
  • Doppelklick auf die OTL.exe
  • Oben findest Du ein Kästchen mit Ausgabe. Wähle bitte Minimal Ausgabe
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in den Thread.

Ist das Problem in Google Chrome noch vorhanden?



Poste folgende Logfiles in deiner nächsten Antwort:
  • OTL-Scan

Vime 03.04.2014 16:09

Ist in Google Chrome noch vorhanden.


Code:

OTL logfile created on: 02.04.2014 20:13:03 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\KomaKuh\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,04 Gb Available Physical Memory | 51,10% Memory free
8,00 Gb Paging File | 5,63 Gb Available in Paging File | 70,37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 725,47 Gb Free Space | 77,89% Space Free | Partition Type: NTFS
Drive F: | 7,26 Gb Total Space | 0,01 Gb Free Space | 0,08% Space Free | Partition Type: FAT32
 
Computer Name: KOMAKUH-PC | User Name: KomaKuh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\KomaKuh\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\LoLLauncher.exe ()
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.78\deploy\LolClient.exe ()
PRC - C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe ()
PRC - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
PRC - C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\RiotLauncher.dll ()
MOD - C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\LoLLauncher.exe ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll ()
MOD - C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.78\deploy\LolClient.exe ()
MOD - C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\e329906c12dea639b0bb56143dfa8fc4\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\e9883c6aff20fa3611ffe42322bf8a51\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\835995cb3fbaa0382d4eb962a88f503e\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\aab789fb8e9675f0a3d90602148e2175\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\0a81bada44a029dd28fed217513ad24d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\c945f3a92565d12cb482a0345d9856e5\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\bfbc088cc59aba62f5329e591625e5f4\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6fa468188705932387c89c28c77e3367\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d5cfc19d54290dc150dedcc6a58cf6ba\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\62babec3a3f651eb0214234a160a975d\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\0bcfa477c2670c4343ffdf576810d81d\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\bff5f538eab1eb8a5c42e9867715de33\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\10ac4ed5a22a4882529e01cf7bd8b895\mscorlib.ni.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AMD FUEL Service) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (OverwolfUpdaterService) -- C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe (Overwolf LTD)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (sscdmdm) -- C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) -- C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) -- C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (SaiNtBus) -- C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) -- C:\Windows\SysNative\drivers\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK1703) -- C:\Windows\SysNative\drivers\SaiK1703.sys (Saitek)
DRV:64bit: - (SaiU1703) -- C:\Windows\SysNative\drivers\SaiU1703.sys (Saitek)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (xnacc) -- C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (AtiPcie) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:64bit: - (ElbyCDFL) -- C:\Windows\SysNative\drivers\ElbyCDFL.sys (SlySoft, Inc.)
DRV - (AODDriver4.2.0) -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ElbyCDFL) -- C:\Windows\SysWOW64\drivers\ElbyCDFL.sys (SlySoft, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{758B870D-DF78-4A6A-9955-DEDDCACF94DC}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FA 61 04 28 EB DE CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {758B870D-DF78-4A6A-9955-DEDDCACF94DC}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
IE - HKCU\..\SearchScopes\{758B870D-DF78-4A6A-9955-DEDDCACF94DC}: "URL" = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
 
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: hxxp://www.google.com/de
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.4_0\
CHR - Extension: Google-Suche = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Auto Replay for YouTubeâ„¢ = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb\1.9.33_0\
CHR - Extension: Google Wallet = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Google Mail = C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Programme\SmartTechnology\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Programme\SmartTechnology\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [CloneCDTray] C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPath = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{83289611-1BCC-4EF6-A775-A8C441C32F86}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0b1400c0-4adb-11e3-9f77-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0b1400c0-4adb-11e3-9f77-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014.04.02 20:12:01 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\KomaKuh\Desktop\OTL.exe
[2014.04.02 14:28:07 | 000,692,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.04.02 14:28:07 | 000,071,048 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.04.02 14:28:06 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2014.04.02 14:25:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014.04.02 14:25:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2014.04.02 14:06:23 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2014.04.02 14:06:19 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2014.04.02 14:06:19 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2014.04.02 14:06:19 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014.04.02 14:06:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014.04.02 13:59:24 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014.04.02 13:57:33 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2014.04.02 13:55:05 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014.04.02 13:55:05 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014.04.02 13:55:02 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014.04.02 13:55:02 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014.04.02 13:55:02 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014.04.02 13:55:02 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014.04.02 13:55:02 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014.04.02 13:55:02 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014.04.02 13:55:02 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014.04.02 13:55:02 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014.04.02 13:55:02 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014.04.02 13:55:02 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014.04.02 13:55:02 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014.04.02 13:55:02 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014.04.02 13:55:02 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014.04.02 13:55:02 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014.04.02 13:55:02 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014.04.02 13:55:02 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014.04.02 13:55:02 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014.04.02 13:55:02 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014.04.02 13:55:02 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014.04.02 13:55:02 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014.04.02 13:55:02 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014.04.02 13:55:02 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014.04.02 13:55:02 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014.04.02 13:55:02 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014.04.02 13:55:02 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014.04.02 13:55:02 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014.04.02 13:55:02 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014.04.02 13:55:02 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014.04.02 13:55:02 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014.04.02 13:55:02 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014.04.02 13:55:02 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014.04.02 13:55:02 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014.04.02 13:55:02 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014.04.02 13:55:02 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014.04.02 13:55:02 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014.04.02 13:55:02 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014.04.02 13:55:02 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014.04.02 13:55:02 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014.04.02 13:55:02 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014.04.02 13:55:02 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014.04.02 13:55:02 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014.04.02 13:55:02 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014.04.02 13:55:02 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014.04.02 13:55:02 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014.04.02 13:55:02 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2014.04.02 13:55:02 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014.04.02 13:55:01 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014.04.02 13:55:01 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014.04.02 13:55:01 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014.04.02 13:55:01 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014.04.02 13:55:01 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014.04.02 13:55:01 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014.04.02 13:55:01 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014.04.02 13:55:01 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014.04.02 13:55:01 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014.04.02 13:55:01 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014.04.02 13:55:01 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014.04.02 13:55:01 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014.04.02 13:55:01 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014.04.02 13:55:01 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014.04.02 13:55:01 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014.04.02 13:55:01 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014.04.02 13:55:01 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014.04.02 13:55:01 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014.04.02 13:55:01 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014.04.02 13:55:01 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014.04.02 13:55:01 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014.04.02 13:55:01 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014.04.02 13:55:01 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014.04.02 13:55:01 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014.04.02 13:55:01 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014.04.02 13:55:01 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014.04.02 13:55:01 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014.04.02 13:55:01 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014.04.02 13:55:01 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014.04.02 13:55:01 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014.04.02 13:55:01 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2014.04.02 13:55:01 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014.04.02 13:54:19 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2014.04.02 13:54:19 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2014.04.02 13:54:19 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2014.04.02 13:54:19 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2014.04.02 13:54:18 | 005,549,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014.04.02 13:54:18 | 003,969,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014.04.02 13:54:18 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014.04.02 13:54:18 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2014.04.02 13:54:18 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2014.04.02 13:54:18 | 000,859,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2014.04.02 13:54:18 | 000,619,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2014.04.02 13:54:18 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2014.04.02 13:54:18 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2014.04.02 13:54:18 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2014.04.02 13:54:18 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2014.04.02 13:54:18 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2014.04.01 18:14:28 | 000,119,512 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.04.01 18:14:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014.04.01 18:14:21 | 000,088,280 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014.04.01 18:14:21 | 000,063,192 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014.04.01 18:14:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014.03.31 20:37:04 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Local\GCC
[2014.03.31 19:20:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\337
[2014.03.31 15:48:15 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Appadaumen.de
[2014.03.31 15:27:50 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\Desktop\saves FRST
[2014.03.30 12:35:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\www.GameModding.net
[2014.03.24 22:06:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2014.03.24 22:06:18 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
[2014.03.24 22:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft
[2014.03.24 22:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft
[2014.03.23 08:42:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Overwolf
[2014.03.21 22:23:18 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2014.03.21 22:23:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2014.03.21 22:22:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2014.03.21 22:21:10 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2014.03.19 16:16:30 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\Desktop\Skin Installer
[2014.03.18 16:34:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2014.03.18 16:30:10 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CrashDump
[2014.03.17 22:58:11 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\Desktop\töhöhö
[2014.03.16 16:37:06 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
[2014.03.16 16:37:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer
[2014.03.10 21:49:56 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\Desktop\Betriebspraktikum
[2014.03.08 23:07:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Picroma
[2014.03.08 23:07:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cube World
[2014.03.08 23:07:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cube World
[2014.03.08 11:22:18 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Local\ElevatedDiagnostics
[2014.03.08 00:45:58 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Roaming\Rogue Legacy
[2014.03.08 00:45:57 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\Documents\SavedGames
[2014.03.06 12:34:56 | 000,000,000 | ---D | C] -- C:\Users\KomaKuh\AppData\Local\Skype
[2014.03.06 12:34:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014.03.06 12:34:47 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2014.03.05 11:23:22 | 000,000,000 | ---D | C] -- C:\ProgramData\BlueStacksSetup
 
========== Files - Modified Within 30 Days ==========
 
[2014.04.02 20:12:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\KomaKuh\Desktop\OTL.exe
[2014.04.02 20:06:00 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.04.02 19:32:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.04.02 15:06:00 | 000,001,108 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.04.02 14:30:06 | 000,000,905 | ---- | M] () -- C:\Users\KomaKuh\Desktop\Mausi3.application - Verknüpfung.lnk
[2014.04.02 14:28:07 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014.04.02 14:28:07 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014.04.02 14:25:32 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014.04.02 14:21:50 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.04.02 14:21:50 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.04.02 14:06:16 | 001,619,284 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.04.02 14:06:16 | 000,699,092 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2014.04.02 14:06:16 | 000,653,930 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.04.02 14:06:16 | 000,149,232 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2014.04.02 14:06:16 | 000,121,802 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.04.02 14:01:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.04.02 14:00:57 | 3220,525,056 | -HS- | M] () -- C:\hiberfil.sys
[2014.04.02 13:55:05 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014.04.02 13:55:05 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014.04.02 13:55:02 | 005,765,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014.04.02 13:55:02 | 001,926,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014.04.02 13:55:02 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014.04.02 13:55:02 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014.04.02 13:55:02 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014.04.02 13:55:02 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014.04.02 13:55:02 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014.04.02 13:55:02 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014.04.02 13:55:02 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014.04.02 13:55:02 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014.04.02 13:55:02 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014.04.02 13:55:02 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014.04.02 13:55:02 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014.04.02 13:55:02 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014.04.02 13:55:02 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014.04.02 13:55:02 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014.04.02 13:55:02 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014.04.02 13:55:02 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014.04.02 13:55:02 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014.04.02 13:55:02 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014.04.02 13:55:02 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014.04.02 13:55:02 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014.04.02 13:55:02 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014.04.02 13:55:02 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014.04.02 13:55:02 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014.04.02 13:55:02 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014.04.02 13:55:02 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014.04.02 13:55:02 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014.04.02 13:55:02 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014.04.02 13:55:02 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014.04.02 13:55:02 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014.04.02 13:55:02 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014.04.02 13:55:02 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014.04.02 13:55:02 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014.04.02 13:55:02 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014.04.02 13:55:02 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014.04.02 13:55:02 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014.04.02 13:55:02 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014.04.02 13:55:02 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014.04.02 13:55:02 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014.04.02 13:55:02 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014.04.02 13:55:02 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014.04.02 13:55:02 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014.04.02 13:55:02 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014.04.02 13:55:02 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2014.04.02 13:55:02 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2014.04.02 13:55:02 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014.04.02 13:55:01 | 001,993,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014.04.02 13:55:01 | 001,228,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014.04.02 13:55:01 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014.04.02 13:55:01 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014.04.02 13:55:01 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014.04.02 13:55:01 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014.04.02 13:55:01 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014.04.02 13:55:01 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014.04.02 13:55:01 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014.04.02 13:55:01 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014.04.02 13:55:01 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014.04.02 13:55:01 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014.04.02 13:55:01 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014.04.02 13:55:01 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014.04.02 13:55:01 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014.04.02 13:55:01 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014.04.02 13:55:01 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014.04.02 13:55:01 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014.04.02 13:55:01 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014.04.02 13:55:01 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014.04.02 13:55:01 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014.04.02 13:55:01 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014.04.02 13:55:01 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014.04.02 13:55:01 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014.04.02 13:55:01 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014.04.02 13:55:01 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014.04.02 13:55:01 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014.04.02 13:55:01 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014.04.02 13:55:01 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014.04.02 13:55:01 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014.04.02 13:55:01 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2014.04.02 13:55:01 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2014.04.02 13:55:01 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014.04.02 13:54:19 | 000,362,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2014.04.02 13:54:19 | 000,243,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2014.04.02 13:54:19 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2014.04.02 13:54:19 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2014.04.02 13:54:18 | 005,549,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014.04.02 13:54:18 | 003,969,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014.04.02 13:54:18 | 003,914,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014.04.02 13:54:18 | 001,732,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2014.04.02 13:54:18 | 000,878,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2014.04.02 13:54:18 | 000,859,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdh.dll
[2014.04.02 13:54:18 | 000,619,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdh.dll
[2014.04.02 13:54:18 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2014.04.02 13:54:18 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2014.04.02 13:54:18 | 000,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2014.04.02 13:54:18 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2014.04.02 13:54:18 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2014.04.01 18:34:59 | 000,119,512 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.04.01 18:34:24 | 000,001,098 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.03.31 19:19:14 | 000,773,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr100.dll
[2014.03.31 19:19:14 | 000,420,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp100.dll
[2014.03.21 22:18:55 | 001,592,628 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.03.16 22:11:44 | 000,035,067 | ---- | M] () -- C:\Gothic.RPT
[2014.03.16 17:00:01 | 000,000,743 | ---- | M] () -- C:\Users\KomaKuh\Desktop\Ymironn.lnk
[2014.03.05 09:26:18 | 000,063,192 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014.03.05 09:26:08 | 000,088,280 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014.03.05 09:26:04 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
 
========== Files Created - No Company Name ==========
 
[2014.04.02 14:30:06 | 000,000,905 | ---- | C] () -- C:\Users\KomaKuh\Desktop\Mausi3.application - Verknüpfung.lnk
[2014.04.02 14:28:08 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.04.02 14:25:32 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2014.04.02 14:25:32 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2014.04.02 13:55:02 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2014.04.02 13:55:01 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2014.04.01 18:14:23 | 000,001,098 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.03.16 19:17:22 | 000,035,067 | ---- | C] () -- C:\Gothic.RPT
[2014.03.16 16:37:06 | 000,000,743 | ---- | C] () -- C:\Users\KomaKuh\Desktop\Ymironn.lnk
[2014.02.12 11:04:41 | 000,003,584 | ---- | C] () -- C:\Users\KomaKuh\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014.01.26 23:12:35 | 000,000,218 | ---- | C] () -- C:\Users\KomaKuh\AppData\Local\recently-used.xbel
[2014.01.01 19:36:22 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2014.01.01 19:13:30 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2013.12.19 19:33:02 | 000,000,145 | ---- | C] () -- C:\Users\KomaKuh\AppData\Roaming\WB.CFG
[2013.12.06 17:44:26 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2013.11.11 19:18:03 | 000,000,600 | ---- | C] () -- C:\Users\KomaKuh\AppData\Local\PUTTY.RND
[2013.11.11 17:18:04 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.11.11 16:31:34 | 000,015,872 | ---- | C] () -- C:\Windows\AsTaskSched.dll
[2013.11.11 16:31:31 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2013.11.11 16:28:22 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013.11.11 16:28:22 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2013.11.11 16:28:21 | 000,810,496 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2013.11.11 16:28:21 | 000,183,808 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2013.11.11 16:28:21 | 000,080,896 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013.11.11 16:26:25 | 001,592,628 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.10.08 15:39:08 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013.10.08 15:39:08 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013.10.08 14:56:12 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013.10.08 14:56:12 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013.04.18 20:07:00 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2013.04.18 20:06:46 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2013.04.18 20:06:46 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013.04.18 20:06:46 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013.04.18 20:06:46 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
 
========== ZeroAccess Check ==========
 
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 40 bytes -> C:\ProgramData\MTA San Andreas All:NT
@Alternate Data Stream - 40 bytes -> C:\ProgramData:NT

< End of report >

Code:

OTL Extras logfile created on: 02.04.2014 20:13:03 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\KomaKuh\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,04 Gb Available Physical Memory | 51,10% Memory free
8,00 Gb Paging File | 5,63 Gb Available in Paging File | 70,37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 725,47 Gb Free Space | 77,89% Space Free | Partition Type: NTFS
Drive F: | 7,26 Gb Total Space | 0,01 Gb Free Space | 0,08% Space Free | Partition Type: FAT32
 
Computer Name: KOMAKUH-PC | User Name: KomaKuh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [userfull] -- cmd.exe /c takeown /f "%1" /r /d j && icacls "%1" /grant Benutzer:F /T /C /L (Microsoft Corporation)
Directory [usernormal] -- cmd.exe /c icacls "%1" /reset /T /C /L (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [userfull] -- cmd.exe /c takeown /f "%1" /r /d j && icacls "%1" /grant Benutzer:F /T /C /L (Microsoft Corporation)
Directory [usernormal] -- cmd.exe /c icacls "%1" /reset /T /C /L (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2380258265-3006174749-279724184-1001]
"EnableNotifications" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{123BC611-7280-469C-926A-36375E023C51}" = rport=445 | protocol=6 | dir=out | app=system |
"{2321D26D-472D-43B5-8B7A-3767D81B3A60}" = rport=137 | protocol=17 | dir=out | app=system |
"{2E2FEE7D-10D9-4C42-8E7A-86A5B10BB242}" = lport=445 | protocol=6 | dir=in | app=system |
"{3308C10C-1958-4F84-8AF9-33C330344195}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{353F8A4A-79ED-4A17-8E31-0F517ECD5312}" = lport=138 | protocol=17 | dir=in | app=system |
"{3A91A7B9-8D82-4C80-A088-093CBFF16CF6}" = lport=58384 | protocol=17 | dir=in | name=pando media booster |
"{3EF2E380-920A-4150-AC82-DF9BE48BAFD5}" = lport=10243 | protocol=6 | dir=in | app=system |
"{57B9813C-CEDC-4876-AA69-BD09575919E4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{59541B7F-4B62-4670-813C-97E9DC89F186}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5ACA6D1F-FD3B-4D40-8B7C-E4FFF8FD6401}" = lport=137 | protocol=17 | dir=in | app=system |
"{6148403F-E4CC-4285-ADA8-3F02D8D870B0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{795422A6-82A2-43AA-8D76-8CF8ECBABCE4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F308C44-BF89-48AE-96EB-1BE93B50BA8D}" = lport=139 | protocol=6 | dir=in | app=system |
"{84F33D9F-2B02-47A5-A8FD-7D3009CFBA2C}" = rport=138 | protocol=17 | dir=out | app=system |
"{91C636D5-4E34-4C65-8355-54B16C2224C8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9B24AA5D-D72F-4324-ABF5-27C56F849D3B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A2726D34-2827-48F6-BBD2-49E6C9C4911C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{ABE50411-0FC0-4B1F-A6AD-70857082DD52}" = lport=58384 | protocol=6 | dir=in | name=pando media booster |
"{ADF79002-7EC9-4E8F-AF0A-5C51B8CE97AF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BF856515-90F4-45D4-9FBC-99657762BEC3}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BF99DC54-058A-4FEA-8F65-CA9FEFC3DD6C}" = lport=58384 | protocol=6 | dir=in | name=pando media booster |
"{D09D56C7-EF29-43A5-80C3-AAC92EF559FC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D3308BE6-5AB7-4A85-A711-C9D7BE6432D9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D6579A1F-A669-49DF-A114-26A8F71D91E9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E8EC7D2E-DDE3-4B11-ACFD-474597F6E2B1}" = lport=58384 | protocol=17 | dir=in | name=pando media booster |
"{EB80B1FA-1CB8-4C09-8D6B-8FB68B5A6928}" = rport=139 | protocol=6 | dir=out | app=system |
"{F2EC83F9-45C3-4FB0-92C4-F7A2ECB45815}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05644A68-8E66-4477-B7F8-E21A056AB7E3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe |
"{073F862F-B86D-4F6C-84EC-12B951CD55DD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0F3333EB-564E-45DA-9C9A-4181B79B42E5}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{0F6E570C-8D65-4CEB-88B8-6BB424C632B0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{14545E69-3317-4E20-B48A-B59A82D897F5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{172A775C-1420-41C4-8696-B59C4A4879F3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{17E8C5C0-2E8B-45AF-A083-6D004E6308EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hammerwatch\hammerwatch.exe |
"{1B76E08C-48C9-4F9C-BCE5-DFE5ACD622D5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2305F6CF-D1C0-4B12-B32C-9F614A1361C0}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{242AB66A-C631-40F8-AE87-A64B7930CF76}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{268EE28F-AE75-4F42-809C-45E1E6B89281}" = protocol=6 | dir=in | app=c:\users\receful\appdata\roaming\spotify\spotify.exe |
"{2DEAD4CC-0E48-4AA2-B2AB-031D0FA735D1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\10000000\10000000.exe |
"{2F1A22C8-9881-4278-AB9A-02B3C91FD277}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{31002B09-DD0D-4DCB-AE27-A02D6ABF2117}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2581\agent.exe |
"{3489CFF0-3F16-4F2F-86E0-1B0DB7C29060}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{36932388-7DBC-4A76-8C5A-A640A7AC0C33}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{36B76C9B-9F0C-4AD9-AB68-5A79812EE8AF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{3A0E02C1-E6AA-43A2-A937-8E26E218BFA4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{3B7EEBC3-D54D-46B0-BDB3-7F47341FF01A}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{3E10EE02-0720-4F7F-B3BC-6637FE1CE0B7}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3F89260A-AE24-4432-B879-9713A0520A44}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe |
"{43F8239A-159C-4766-BC74-7E228BC6B21B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{44EBE429-3984-4095-93F6-83EE3662CA66}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{45A0002A-60C3-49F1-AF43-B77F17351EBC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe |
"{4BDC25F8-22B4-4D65-B298-9D855CE318A0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{4EB3B81D-C723-43F2-BC61-01675BB0573B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{52EC4B7A-B390-448C-8282-6C9BF3F8B62A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hammerwatch\editor\hammereditor.exe |
"{530FD36F-3E8A-41F0-AF4B-CF706CE19F74}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{543ACA61-7906-4C8D-8044-A2853D9A10C0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5DC143CE-7654-4DC3-A178-0985D2211DB2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\loadout\loadout.exe |
"{62F12AB0-9177-476F-8B54-F96B9736D82E}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe |
"{64CAD4B1-9FF1-4E31-B01B-EF7332C0BD4C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{64D35019-6E2E-40CA-B42C-A46845D92D9B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{68F69380-B5B2-4FA6-93E4-FFE0B565ECBE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\koareckoning\reckoning.exe |
"{692B9AE0-46EC-42F1-9B76-6F8DA4A4F561}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{6A2CB3E8-2593-4C6E-80A6-FDD112A50BE2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe |
"{6DA84F03-C563-49FE-B3E5-A92EF37264D4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spectraball\spectraball.exe |
"{6EBC1B17-2808-4583-B25D-A4031790A11D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{6F37618F-A043-487D-B3D0-A4475041AC44}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{6FCC4032-1355-4C77-A130-5CDFEDF27763}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supercratebox\supercratebox.exe |
"{745A0279-61C8-48BE-9F65-20581C640E84}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{76B94758-0E1C-407A-9C83-4AF9560C49B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{773B497E-C736-47EF-802D-F8744328239E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{7A3278DD-46EB-4613-9181-325805A3CE91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rogue legacy\roguelegacy.exe |
"{7C9596AB-26B5-4E12-93AE-933BA030C1F3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{7DE02477-5C65-45D1-8399-DC9B1BC399F9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7EBB09DD-4E7D-4714-AA89-041BDE94C3AA}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{83F47E0C-FE16-4313-8219-5A07115133FB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\final exam\final_exam.exe |
"{8D3FBDC2-AB4C-4AC9-9DEB-2C96F33E88DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{8F80A044-4F47-4087-87C3-7A26A5D9B9B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{8FDC356D-2BAD-4484-8DB4-87E98330C3BA}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9139D2BC-D031-4B08-A3F4-3884AA4D14DA}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{95B384E4-1F1A-49DC-8B81-C34E14D51FF7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supercratebox\supercratebox.exe |
"{97A05DCA-D182-44C1-8EE4-38ED4584C2EF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spectraball\spectraball.exe |
"{990C10B8-554B-4478-B020-0F56F61625CE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rogue legacy\roguelegacy.exe |
"{9A80CCC8-8EDC-4AF7-9EB6-ADFB69E8932F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\electronicsuperjoy\electronicsuperjoy.exe |
"{A0789EA1-03D9-41F5-93D8-5F7DE0FB9752}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\electronicsuperjoy\electronicsuperjoy.exe |
"{A1485D23-E8FE-4DB3-9560-863421EBF058}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{A717024E-C9DF-4258-99DE-8B04AEE7CCE6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A9DB2AF9-3A81-4057-8196-79A61A0FA152}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AE457D62-EF48-46D5-9F84-E73770939E82}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{AF8D90F5-EBF8-46CC-9C1B-C3E51FF0C141}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B05E8976-C2CA-478A-B62B-3AF8BA077F31}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe |
"{B8CC5A7D-ADAA-446E-BC44-CE8724958E4E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"{B8CF4C45-DDAA-4C5E-A1A9-54E1D2609B8A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{BB5CAE00-59B9-4AC1-9417-F993E30422E0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{BF2D62DA-EDD7-4E1F-96D1-A37F3A2E3D1F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\final exam\final_exam.exe |
"{C26E9A55-8230-4B44-88FE-6619F7BB3FDC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\path of exile\pathofexilesteam.exe |
"{C2984DAD-62EA-4139-884B-33559D2A1B22}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{C2E01FD5-C7D9-46B5-AD15-A53CE11677C6}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{C348057A-76C8-4EA2-A73B-292326A11A65}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C3832544-6C89-4FAC-A7D3-EBD2961F8701}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\10000000\10000000.exe |
"{C475EA98-42C8-49CF-98DF-D5F9A8B6AD38}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2581\agent.exe |
"{C8003B3A-A7F8-45D6-BFD6-37A27B12345E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{CCBA237B-0303-483B-ABA3-01F5D22E2227}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{CD57A3F5-92E6-411B-8003-8BBD0BFA1BD1}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-x.x.x.x-4.0.0.12911-eu-downloader.exe |
"{D34BDA32-1DE4-46B0-B1A3-8C5002BAB451}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\path of exile\pathofexilesteam.exe |
"{D4ED9D56-D5E6-4C90-A1CF-56FAA6137768}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe |
"{D55BEF1F-F90C-445A-A049-E2E0F68ED087}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2426\agent.exe |
"{D88235A3-3D1A-40D1-9074-01728F73A826}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D97672EA-4AE9-4314-800D-574069F9E514}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2417\agent.exe |
"{DC66BC16-D453-4C06-BB7F-54A06E4DB5DC}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{DCB32BAE-2278-4EFF-9C51-5E8EC4A3BE16}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe |
"{DCC68D8C-9019-462B-9728-AF485A48D352}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2426\agent.exe |
"{DFBEDDA0-896F-4C40-A698-563DDCE18050}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\loadout\loadout.exe |
"{E3848140-CBBF-403B-B168-C3CFBC42C453}" = protocol=17 | dir=in | app=c:\users\receful\appdata\roaming\spotify\spotify.exe |
"{E58FF873-FEF5-4070-ACD8-15DF8C1E6359}" = dir=in | app=c:\users\komakuh\appdata\local\gcc\controller.exe |
"{E628905F-C648-4674-88BD-6CEE18118932}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\koareckoning\reckoning.exe |
"{E64ABAE6-861E-493A-899A-7BBAA3AEDB24}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{EA4A7E52-EF5E-47D7-9A51-5EB5849DD6D6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\counter-strike source\hl2.exe |
"{EB839A38-86F0-4EA0-A26A-B0DBEEEACAC4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2417\agent.exe |
"{EFCE340A-3C36-44CC-AA3D-65EA8CC7A06C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F04FA9F1-401A-4682-82A9-940365753DF0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{F0C58EB9-DCF3-4D29-A133-E0F334E1C17C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hammerwatch\editor\hammereditor.exe |
"{F5E1BFFB-A591-49BD-9F3F-ECE413BC36B0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hammerwatch\hammerwatch.exe |
"{F8A88E17-93B8-4FEF-86CA-27EDD6713A86}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe |
"{F8D4AFE3-F0F0-48CC-9838-81DFB3AD75CE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe |
"{FC9EF6EB-9937-44B7-B82F-39FD9235DAD5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FF401AEE-26F8-455A-823D-75267CE1BD26}" = protocol=6 | dir=out | app=system |
"{FFE6D4EF-0F74-4A4D-81C3-1DB5D5649AB1}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe |
"TCP Query User{54E3560D-7728-4D5F-8638-5E92B3BD4117}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{E52B67A4-ECB0-4234-9D2A-4A9B91528961}C:\program files (x86)\lolreplay\lolreplay.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lolreplay\lolreplay.exe |
"TCP Query User{F10CDE77-3B98-49A4-BC49-C7DF5FCE31A8}C:\program files (x86)\lucasarts\star wars battlefront\gamedata\battlefront.exe" = protocol=6 | dir=in | app=c:\program files (x86)\lucasarts\star wars battlefront\gamedata\battlefront.exe |
"UDP Query User{7C7A69E3-8F3A-4468-8892-412C235A01B9}C:\program files (x86)\lolreplay\lolreplay.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lolreplay\lolreplay.exe |
"UDP Query User{907FB873-A117-4A4C-B501-748C0A027090}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{B0A733A0-5A9A-4B89-BF7B-D041F3D508C7}C:\program files (x86)\lucasarts\star wars battlefront\gamedata\battlefront.exe" = protocol=17 | dir=in | app=c:\program files (x86)\lucasarts\star wars battlefront\gamedata\battlefront.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{308051DA-0048-7A07-FE8B-9B6EC119A9E8}" = AMD Catalyst Install Manager
"{44AAA767-F540-F091-4571-ADCBC10B0C92}" = AMD Fuel
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{7D2019DF-713F-B6ED-8C87-14363B081FB2}" = AMD Drag and Drop Transcoding
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{AEF57B06-B494-8180-AFC7-05EFB1DB2B64}" = ccc-utility64
"{BD1BCEF8-5CD6-D8ED-7D36-31C2172076EA}" = AMD Media Foundation Decoders
"{C9193CBB-C31A-412A-A074-AD08F0F2CF3D}" = Smart Technology Programming Software 7.0.27.13
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{ED273D26-E354-1A5B-A0D0-CB5258D43BD2}" = AMD Wireless Display v3.0
"{FCC4426F-0296-D30D-729C-E76C8E7252C7}" = AMD Accelerated Video Transcoding
"CCleaner" = CCleaner
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v4.5.0
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"TeamSpeak 3 Client" = TeamSpeak 3 Client
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{046B79EE-7ED3-37A4-621A-FE297EF484C2}" = CCC Help Greek
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}" = OpenOffice 4.0.1
"{10CB5DDD-38E1-2EB2-F62C-C1948A99943E}" = AMD Catalyst Control Center
"{1194740D-0DB8-A508-31BA-E722597B4516}" = Catalyst Control Center Graphics Previews Common
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FB16E3B-3AFB-46CB-6E83-2F5A0CF4ED16}" = Catalyst Control Center Localization All
"{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 51
"{2E3A81FB-7952-F8CB-9AD5-50544E2F4838}" = CCC Help Czech
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{4172E797-CE12-AC47-05B7-0E48BDB33E75}" = CCC Help Russian
"{4428AEE6-FA5E-2913-8D12-B410E85E11AA}" = CCC Help Spanish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FF1533E-FF2C-A04A-25DD-A8AEC6FA106B}" = CCC Help Chinese Standard
"{517CC397-B22F-4593-8DCB-DE72CC541E9A}" = League of Legends
"{6071CB80-DABC-B10D-F244-7F410FB3B150}" = CCC Help Polish
"{6343B6BA-F97F-B336-9ED8-FFD43776E84D}" = CCC Help Finnish
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{8D3A11D0-D925-FA0F-43F3-242E49975CD2}" = CCC Help Danish
"{8EF39A9F-6A57-9706-86A5-9312D9ED8016}" = CCC Help Portuguese
"{92352C97-C657-DB89-5F3A-E8C3789D9C89}" = CCC Help Chinese Traditional
"{95545E55-3309-1929-FF41-2908A9706742}" = CCC Help Turkish
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CA5F712-9CAA-B3CB-02D3-7134DFC8801E}" = CCC Help French
"{A128A816-FD3F-990E-DD80-E1735BD718AE}" = CCC Help Italian
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Deutsch
"{AFC9ECA9-6A4E-1370-98F3-002B63B5AF8E}" = CCC Help Thai
"{B3491D28-DCF7-0D3E-1B3F-28E6FCDE659F}" = HydraVision
"{B88F2045-CF9A-996C-1670-6F7D65F1D18A}" = CCC Help Norwegian
"{BED96D0C-7743-3CE3-F7DF-A0A4475FBF2F}" = CCC Help Hungarian
"{C3592426-531E-4110-911D-BFECE2CE284B}" = puush
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{C79CB9C7-10A4-4814-8402-F574672C2192}" = Star Wars Battlefront
"{CB79256B-C0E0-40C6-8EB7-BDD796203581}" = Catalyst Control Center - Branding
"{D692A0E0-1BBB-4E9C-826E-4254EE330830}_is1" = Cube World version 0.0.1
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{E297492A-E114-CAE0-502E-5F36C386DD30}" = CCC Help Dutch
"{E6533A85-ED92-F897-2B68-58AC3BD87F94}" = CCC Help English
"{EBAC163A-588E-1E5A-3CE8-826E9A449244}" = CCC Help Korean
"{ED65BD75-CEF3-C0C2-9E9C-FA567484FF60}" = CCC Help Japanese
"{EEB34D84-92A1-7BE3-6DB7-ABD1C4912D6B}" = Catalyst Control Center InstallProxy
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F1289D68-1C48-930F-51CF-577BDB371252}" = CCC Help Swedish
"{F3F340A5-64EC-AEEC-4BDF-DC537D390BF5}" = CCC Help German
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{FE8E927E-8099-4C6B-A337-1CAB00E213C7}" = Overwolf
"123 Free Solitaire_is1" = 123 Free Solitaire v10.0
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Battle.net" = Battle.net
"CloneCD" = CloneCD
"Free YouTube Download_is1" = Free YouTube Download version 3.2.30.319
"Game Booster_is1" = Game Booster
"GigaClicks Crawler" = GigaClicks Crawler
"Google Chrome" = Google Chrome
"Gothic II" = Gothic II
"Gothic II - Die Nacht des Raben" = Gothic II - Die Nacht des Raben
"Gothic Multiplayer" = Gothic Multiplayer
"HashCheck Shell Extension" = HashCheck Shell Extension (x86-32)
"Hearthstone" = Hearthstone
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.0.0 (Full)
"League of Legends 3.0.1" = League of Legends
"LOLReplay" = LOLReplay
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware Version 2.00.0.1000
"MTA:SA 1.3" = MTA:SA v1.3.4
"OpenAL" = OpenAL
"PhotoScape" = PhotoScape
"RocketDock_is1" = RocketDock 1.3.5
"Steam App 102500" = Kingdoms of Amalur: Reckoning™
"Steam App 105600" = Terraria
"Steam App 113200" = The Binding of Isaac
"Steam App 1250" = Killing Floor
"Steam App 18300" = Spectraball
"Steam App 208090" = Loadout
"Steam App 212800" = Super Crate Box
"Steam App 214560" = Mark of the Ninja
"Steam App 227580" = 10,000,000
"Steam App 233190" = Final Exam
"Steam App 234160" = Strike Suit Infinity
"Steam App 238960" = Path of Exile
"Steam App 239070" = Hammerwatch
"Steam App 240" = Counter-Strike: Source
"Steam App 241600" = Rogue Legacy
"Steam App 244870" = Electronic Super Joy
"Steam App 4000" = Garry's Mod
"Steam App 42700" = Call of Duty: Black Ops
"Steam App 42710" = Call of Duty: Black Ops - Multiplayer
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Steam App 730" = Counter-Strike: Global Offensive
"Super Hexagon_is1" = Super Hexagon
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.7
"WinRAR archiver" = WinRAR 5.00 (32-bit)
"World of Warcraft" = World of Warcraft
"WPM" = WPM17.8.0.3442
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{56837588-F559-40CF-91D9-D439D405FB28}" = PileFile reminder
"{9AAF2503-6CD5-414A-B5BA-37639B76C91F}" = Oxy
"4729debaf2cd0ca4" = Mausi3
"93bb1775721ec2cc" = Launcher omfg.gg
"www.mondgesaenge.de - G2ADB" = Gothic II Addon-Datenbank
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 01.04.2014 12:33:16 | Computer Name = KomaKuh-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
 Cannot start service.  Service did not stop gracefully the last time it was run.

  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)    bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
 state)
 
Error - 01.04.2014 12:35:00 | Computer Name = KomaKuh-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 01.04.2014 13:05:13 | Computer Name = KomaKuh-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\KomaKuh\Downloads\esetsmartinstaller_enu.exe".
 Fehler in  Manifest- oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche
 Komponentenversion steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.
In
 Konflikt stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error - 01.04.2014 14:15:31 | Computer Name = KomaKuh-PC | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files
 (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in  Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error - 01.04.2014 15:33:24 | Computer Name = KomaKuh-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: LoLLauncher.exe, Version: 2.5.0.425,
 Zeitstempel: 0x5334c623  Name des fehlerhaften Moduls: LoLLauncher.exe, Version:
2.5.0.425, Zeitstempel: 0x5334c623  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0022c60a
ID
 des fehlerhaften Prozesses: 0xb28  Startzeit der fehlerhaften Anwendung: 0x01cf4ddea7fe6fa3
Pfad
 der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\LoLLauncher.exe
Pfad
 des fehlerhaften Moduls: C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.205\deploy\LoLLauncher.exe
Berichtskennung:
 7d024142-b9d4-11e3-b976-90e6ba34e272
 
Error - 02.04.2014 07:30:06 | Computer Name = KomaKuh-PC | Source = BstHdAndroidSvc | ID = 0
Description = Der Dienst kann nicht gestartet werden. System.ApplicationException:
 Cannot start service.  Service did not stop gracefully the last time it was run.

  bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)    bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object
 state)
 
Error - 02.04.2014 07:31:49 | Computer Name = KomaKuh-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 02.04.2014 08:02:50 | Computer Name = KomaKuh-PC | Source = WinMgmt | ID = 10
Description =
 
Error - 02.04.2014 08:29:57 | Computer Name = KomaKuh-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Mausi3.exe, Version: 1.0.2925.34192,
 Zeitstempel: 0x477e7410  Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229,
 Zeitstempel: 0x51fb1677  Ausnahmecode: 0xc0020001  Fehleroffset: 0x000000000000940d
ID
 des fehlerhaften Prozesses: 0xf98  Startzeit der fehlerhaften Anwendung: 0x01cf4e6f32cb0f4f
Pfad
 der fehlerhaften Anwendung: C:\Users\KomaKuh\AppData\Local\Apps\2.0\4L28KQPD.WKY\5JQD6MWH.54T\maus..tion_f895ba69515cc005_0001.0000_6d7bddd445faee20\Mausi3.exe
Pfad
 des fehlerhaften Moduls: C:\Windows\system32\KERNELBASE.dll  Berichtskennung: 7f9c54ff-ba62-11e3-9cf3-90e6ba34e272
 
Error - 02.04.2014 13:27:13 | Computer Name = KomaKuh-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: League of Legends.exe, Version: 4.4.0.1885,
 Zeitstempel: 0x533a292a  Name des fehlerhaften Moduls: League of Legends.exe, Version:
 4.4.0.1885, Zeitstempel: 0x533a292a  Ausnahmecode: 0xc0000005  Fehleroffset: 0x00578890
ID
 des fehlerhaften Prozesses: 0x13ac  Startzeit der fehlerhaften Anwendung: 0x01cf4e95c60b9ecf
Pfad
 der fehlerhaften Anwendung: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.16\deploy\League
 of Legends.exe  Pfad des fehlerhaften Moduls: C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.1.16\deploy\League
 of Legends.exe  Berichtskennung: 0726588d-ba8c-11e3-9cf3-90e6ba34e272
 
[ System Events ]
Error - 28.03.2014 10:31:29 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 29.03.2014 08:56:04 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 30.03.2014 02:39:03 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 30.03.2014 14:46:06 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 31.03.2014 08:40:10 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 31.03.2014 13:14:57 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 01.04.2014 11:56:59 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 01.04.2014 12:33:16 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 02.04.2014 07:30:06 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7023
Description = Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler
 beendet:  %%1064
 
Error - 02.04.2014 07:40:16 | Computer Name = KomaKuh-PC | Source = Service Control Manager | ID = 7034
Description = Dienst "BlueStacks Log Rotator Service" wurde unerwartet beendet.
Dies ist bereits 1 Mal passiert.
 
 
< End of report >

Hab heut erste Mal PC gestartet, jetzt ist da erstmal Werbung : Ihr Windows in 3 Schritten reparieren. Microsoft Certified. Dürfen die sowas überhaupt in ihre Fake Werbung reinmachen :D

sunjojo 03.04.2014 18:12

Ok, in dem OTL Logfile sehe ich auch nichts weltbewegendes, aber mache bitte folgendes:



Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Program Files (x86)\Common Files\337
Reg: reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{56837588-F559-40CF-91D9-D439D405FB28}" /f
Reg: reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{9AAF2503-6CD5-414A-B5BA-37639B76C91F}" /f


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Schritt 2
Synchronisierst du Google Chrome mit deinem Konto? Wenn ja, bitte das deaktivieren. Deinstalliere bitte deinen Google Chrome Browser vollständig und installiere diesen wieder.


Tritt das Problem weiterhin auf? Mach bitte einen Screenshot und hänge diesen hier an.

Hast du "DVDVideoSoft" heruntergeladen?

Vime 03.04.2014 18:26

Noch eine Frage bevor ich Google Chrome deinstalliere.
Werden meine Lesezeichen gespeichert und beim neuinstallieren wieder verwendet ?
DvDVideoSoft nicht direkt sondern nur Free Youtube Downloader. Möchte nämlich gerne Musik hören ohne meinen Browser, weil ich nur eine 2k Leitung besitze.


Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by KomaKuh at 2014-04-03 19:24:19 Run:1
Running from C:\Users\KomaKuh\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Program Files (x86)\Common Files\337
Reg: reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{56837588-F559-40CF-91D9-D439D405FB28}" /f
Reg: reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{9AAF2503-6CD5-414A-B5BA-37639B76C91F}" /f
*****************

C:\Program Files (x86)\Common Files\337 => Moved successfully.

========= reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{56837588-F559-40CF-91D9-D439D405FB28}" /f =========

Der Vorgang wurde erfolgreich beendet.



========= End of Reg: =========


========= reg delete "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{9AAF2503-6CD5-414A-B5BA-37639B76C91F}" /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


==== End of Fixlog ====


sunjojo 03.04.2014 18:35

Zitat:

Werden meine Lesezeichen gespeichert und beim neuinstallieren wieder verwendet ?
Ne, deine Lesezeichen werden nicht gespeichert, aber ich hab noch eine Möglichkeit, bevor du Google Chrome deinstallierst. Probiere das mal aus, besteht das Problem weiterhin noch?



Schritt 1
Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
  • Bitte deaktiviere während des Scans alle Virenscanner, da sie das Ergebnis beeinflussen können.
  • Starte die zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und sollte nicht 1:1 auf andere Computer übernommen werden.
  • Kopiere den Text der folgenden Box in das Skriptfenster von zoek:
    Code:

    FFdefaults;
    CHRdefaults;
    iedefaults;
    emptyclsid;
    autoclean;

  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchgelaufen ist.
  • Wenn das Tool fertig ist, wird sich eine Logdatei öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken)

Schritt 2
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
C:\Program Files (x86)\DVDVideoSoft
C:\Program Files (x86)\Common Files\DVDVideoSoft


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Vime 03.04.2014 18:54

Muss dich echt mal loben Jonas, antwortest so schnell und bekommst alles hin, die Startseite ist futsch. Mann eh du hasts drauf :D

Code:

Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by KomaKuh on 03.04.2014 at 19:40:56,31.
Microsoft Windows 7 eXtreme™ Draconis Edition  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\KomaKuh\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

03.04.2014 19:42:47 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\windows\SysNative\tasks\Desk 365 RunAsStdUser deleted
"C:\PROGRA~3\Package Cache" deleted

==== Chrome Look ======================

Auto Replay for YouTubeâ„¢ - KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb
BTTV - Receful\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped
Auto Replay for YouTubeâ„¢ - Receful\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb
Auto Refresh Plus - Receful\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilipfekkmncanaajkapbpancpelijih

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{758B870D-DF78-4A6A-9955-DEDDCACF94DC}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{758B870D-DF78-4A6A-9955-DEDDCACF94DC} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Reset Google Chrome ======================

C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Receful\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Receful\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== shortcuts on Users Desktops ======================

C:\Users\KomaKuh\Desktop\Gothic II - Die Nacht des Raben.lnk - C:\Program Files (x86)\JoWooD\Gothic II\UNWISE.EXE /W9 "C:\Program Files (x86)\JoWooD\Gothic II\INSTALL.LOG"
C:\Users\KomaKuh\Desktop\Gothic II Addon-Datenbank.lnk - C:\Program Files (x86)\www.mondgesaenge.de\G2ADB\index.htm
C:\Users\KomaKuh\Desktop\Mausi3.application - Verknüpfung.lnk - 
C:\Users\KomaKuh\Desktop\osu.lnk - 
C:\Users\KomaKuh\Desktop\Star Wars Battlefront spielen.lnk - C:\Program Files (x86)\LucasArts\Star Wars Battlefront\LaunchBF.exe
C:\Users\KomaKuh\Desktop\Wow.exe - Verknüpfung.lnk - 
C:\Users\KomaKuh\Desktop\Ymironn.lnk - C:\Gothic II\System\GMPLauncher.exe
C:\Users\KomaKuh\Desktop\saves FRST\mbam-log-2014-03-30 (20-40-45).txt - Verknüpfung.lnk - 
C:\Users\Receful\Desktop\Eigene Musik - Verknüpfung.lnk - 
C:\Users\Receful\Desktop\PhotoScape.lnk - C:\Program Files (x86)\PhotoScape\PhotoScape.exe
C:\Users\Receful\Desktop\Spotify.lnk - C:\Users\Receful\AppData\Roaming\Spotify\spotify.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Public\Desktop\MTA San Andreas 1.3.lnk - C:\Program Files (x86)\MTA San Andreas 1.3\Multi Theft Auto.exe

==== shortcuts in Users Start Menu ======================

C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1031-7B44-AB0000000001}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\AMD Catalyst Control Center.lnk - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\Hilfe.lnk - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe Start Help -help
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cube World\Cube World.lnk - C:\Program Files (x86)\Cube World\CubeLauncher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Free YouTube Download.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube Download\FreeYTVDownloader.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Log Report.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\DVSSysReport.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Premium Membership.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\PremiumMembershipOffer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Uninstall.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\Uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://start.qone8.com/?type=sc&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer\Gothic Multiplayer.lnk - C:\Gothic II\System\GMPLauncher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer\Uninstall.lnk - C:\Gothic II\uninstallgmp.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gothic Multiplayer\Website.lnk - C:\Gothic II\Gothic Multiplayer.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab about
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab update
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware entfernen.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\www.GameModding.net\GTA San Andreas\Uninstall(Desert Eagle)89977-desert-eagle-hd-gtasa.lnk - C:\Program Files (x86)\Rockstar Games\GTA SAN ANDREAS\www.GameModding.net\Uninstall(Desert Eagle)89977-desert-eagle-hd-gtasa.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\www.GameModding.net\GTA San Andreas\Uninstall(M4)120535-avtorifle-acw-r-gtasa.lnk - C:\Program Files (x86)\Rockstar Games\GTA SAN ANDREAS\www.GameModding.net\Uninstall(M4)120535-avtorifle-acw-r-gtasa.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\www.GameModding.net\GTA San Andreas\Uninstall(MP5)15428-ump-45-v-2.0-gtasa.lnk - C:\Program Files (x86)\Rockstar Games\GTA SAN ANDREAS\www.GameModding.net\Uninstall(MP5)15428-ump-45-v-2.0-gtasa.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\www.GameModding.net\GTA San Andreas\Uninstall(Rifle)120744-m1-garand-gtasa.lnk - C:\Program Files (x86)\Rockstar Games\GTA SAN ANDREAS\www.GameModding.net\Uninstall(Rifle)120744-m1-garand-gtasa.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\www.GameModding.net\GTA San Andreas\Uninstall(Sniper Rifle)15657-svu-gtasa.lnk - C:\Program Files (x86)\Rockstar Games\GTA SAN ANDREAS\www.GameModding.net\Uninstall(Sniper Rifle)15657-svu-gtasa.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://start.qone8.com/?type=sc&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe /lite
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://start.qone8.com/?type=sc&ts=1396286207&from=mp3&uid=WDCXWD10EZEX-60ZF5A0_WD-WMC1S484558645586
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\lol.launcher.lnk - C:\Riot Games\League of Legends\lol.launcher.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Neues Textdokument 9F7P-8GGK-R4SU-4A7Z.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\OpenOffice.lnk - C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\sfBot.lnk - C:\Users\KomaKuh\Desktop\SFBot\sfBot.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Silkroad Online Launcher.lnk - C:\Program Files (x86)\DuckRoad-80-Valentus\silkroad.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamSpeak 3 Client.lnk - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Wow.exe - Verknüpfung.lnk - 
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files (x86)\PhotoScape\PhotoScape.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - 
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - 
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MTA San Andreas 1.3.lnk - C:\Program Files (x86)\MTA San Andreas 1.3\Multi Theft Auto.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Play League of Legends.lnk - C:\Riot Games\League of Legends\lol.launcher.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamSpeak 3 Client.lnk - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\teeworlds.lnk - C:\Users\Receful\Documents\tw\teeworlds.exe
C:\Users\Receful\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe

==== shortcuts After Repair ======================

C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\KomaKuh\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesAirMessage deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\KomaKuh\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\KomaKuh\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Receful\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=132 folders=37 28009854 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\KomaKuh\AppData\Local\Temp will be emptied at reboot
C:\Users\Receful\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\KomaKuh\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 03.04.2014 at 19:50:32,78 ======================

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by KomaKuh at 2014-04-03 19:53:05 Run:2
Running from C:\Users\KomaKuh\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft
C:\Program Files (x86)\DVDVideoSoft
C:\Program Files (x86)\Common Files\DVDVideoSoft
*****************

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft => Moved successfully.
C:\Users\KomaKuh\AppData\Roaming\DVDVideoSoft => Moved successfully.
C:\Program Files (x86)\DVDVideoSoft => Moved successfully.
C:\Program Files (x86)\Common Files\DVDVideoSoft => Moved successfully.

==== End of Fixlog ====


sunjojo 03.04.2014 19:49

Zitat:

Muss dich echt mal loben Jonas, antwortest so schnell und bekommst alles hin, die Startseite ist futsch. Mann eh du hasts drauf
Danke für dein Lob, aber den Tipp mit Zoek habe ich von einem Kollegen bekommen ;). Ist die Webung in allen Browsern verschwunden?

Hast du noch weitere Fragen?

Vime 03.04.2014 20:00

Jup ist überall weg, bin dir überaus dankbar :)
Auch wenn der Support hier perfekt ist, hoffe ich die nächste Zeit nicht hier zu landen :D
Sind auch keine weiteren Fragen mehr vorhanden.

Mit freundlichen Grüßen,
virusfreier Vime

sunjojo 03.04.2014 20:03

Hallo Vime,

schön, dass wir dir helfen konnten :abklatsch:.

Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht, damit erhalte ich keine Benachrichtungen über neue Antworten in diesem Thread. Solltest Du das Thema erneut brauchen, schicke mir bitte eine private Nachricht.

Jeder Andere bitte hier klicken und einen eigenen Thread erstellen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 14:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19