Nabend,
tut mir leid, dass ich mich so spät melde, habe spät angefangen und hat alles doch ein wenig gedauert^^
mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.04.2014
Suchlauf-Zeit: 21:08:16
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.27.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Collin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 276689
Verstrichene Zeit: 1 Std, 43 Min, 51 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.ReMarkit.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe, 2936, Löschen bei Neustart, [8c74976921dfb44c25eff68444be47b9]
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe, 2396, Löschen bei Neustart, [ad531ce46f9141bf6e95c9a1a260629e]
Module: 3
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [926edd23659bb8480548979e43bdda26],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [926edd23659bb8480548979e43bdda26],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll, Löschen bei Neustart, [ad531ce46f9141bf6e95c9a1a260629e],
Registrierungsschlüssel: 43
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [926edd23659bb8480548979e43bdda26],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [926edd23659bb8480548979e43bdda26],
PUP.Optional.SupTab.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [926edd23659bb8480548979e43bdda26],
PUP.Optional.SupTab.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [926edd23659bb8480548979e43bdda26],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [0df377899b65f40c84ee5ff3867b639d],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511421146}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440544424446}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550555425546}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660566426646}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550555425546}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660566426646}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440544424446}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0054246.BHO.1, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511421146}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0054246.BHO, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0054246.BHO, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0054246.BHO.1, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220522422246}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0054246.Sandbox.1, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0054246.Sandbox, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0054246.Sandbox, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0054246.Sandbox.1, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220522422246}, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511421146}\INPROCSERVER32, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [4eb235cb847c1de311281465cd3556aa],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [7e82a858fa06dc24ae8b7801e919ae52],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [1ce48878897767992bec9e0adf24e61a],
PUP.Optional.HQVideoPro.A, HKLM\SOFTWARE\WOW6432NODE\HQ-Video-Pro-1.9, In Quarantäne, [e41cbe426f918d731a6f04799d6521df],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerplus, In Quarantäne, [af51d42ce61a6d938ab8e59382801be5],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [ee128c74e11f2cd42feb41381be75ba5],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, In Quarantäne, [2ad65ca4c13f58a8cd098beed32ff907],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [1de3639ddb25ca36de5b6e0bcf3305fb],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [e41cc73924dc68988faaf2877a884db3],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [748ccd3325db827e2ceb0f99be45ac54],
PUP.Optional.ReMarkit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Re-markit, In Quarantäne, [8c74976921dfb44c25eff68444be47b9],
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, Löschen bei Neustart, [d42cd927c63a1ce496aedb9d32d07987],
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, Löschen bei Neustart, [1be5a858e02018e84cf84f297a889f61],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, Löschen bei Neustart, [0af68d7342bea65ab4868dece81ab749],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, Löschen bei Neustart, [7f81e21ee917a45c84b6f18849b950b0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Freeven, Löschen bei Neustart, [748c3ac65ba5c23e0d9499e3be44e719],
PUP.Optional.HQVideoProfessional.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQ-Video, Löschen bei Neustart, [52ae946c98689f61d0107908aa5821df],
PUP.Optional.Qone8, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [cc340af620e010f069ad882059aad729],
PUP.Optional.Softonic.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Löschen bei Neustart, [0df38d73ea16c739e965443043bf45bb],
Registrierungswerte: 2
PUP.Optional.NextLive.A, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\Windows\SysWOW64\rundll32.exe "C:\Users\Collin\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, Löschen bei Neustart, [ac5412eeb24e9d634c5490c0d52cd32d]
PUM.Bad.Proxy, HKU\S-1-5-21-669750612-4099681080-2224479282-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:13828, Löschen bei Neustart, [d8287789cf3102fec97193223ac950b0]
Registrierungsdaten: 6
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B),Ersetzt,[6f91fb0524dc1ce4f276c1663fc54eb2]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[ae5260a03ec27888b7e250e13dc731cf]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B&q={searchTerms}),Ersetzt,[4eb2629e758bea16590d210630d4629e]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B),Ersetzt,[e61a37c9c43c8779d88cbe69ca3ab54b]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1397923092&from=tugs&uid=TOSHIBAXMK7559GSXP_91FAB0Q3BXX91FAB0Q3B),Ersetzt,[6c94c73946ba847cd6920522dc280df3]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[16ea867ae11f39c709902809897b8a76]
Ordner: 40
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.OpenCandy, C:\Users\Collin\AppData\Roaming\OpenCandy, In Quarantäne, [cd33f0102bd588782f6281e2808229d7],
PUP.Optional.OpenCandy, C:\Users\Collin\AppData\Roaming\OpenCandy\C0C88DEB32DE42E68AD37C273F1793EB, In Quarantäne, [cd33f0102bd588782f6281e2808229d7],
PUP.Optional.OpenCandy, C:\Users\Collin\AppData\Roaming\OpenCandy\E6F35348C12A400A8A3FD792EC8D8B6B, In Quarantäne, [cd33f0102bd588782f6281e2808229d7],
PUP.Optional.NextLive.A, C:\Users\Collin\AppData\Roaming\newnext.me, In Quarantäne, [6f91eb1532ceff01c384e67fff03837d],
PUP.Optional.NextLive.A, C:\Users\Collin\AppData\Roaming\newnext.me\cache, In Quarantäne, [6f91eb1532ceff01c384e67fff03837d],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, In Quarantäne, [f808f20ef808649c91cf87df976ba060],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [f808f20ef808649c91cf87df976ba060],
PUP.Optional.HQVideoPro.A, C:\Program Files (x86)\HQ-Video-Pro-1.9, In Quarantäne, [e020f0104db3827ef874d98fe61cb848],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft, Löschen bei Neustart, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.WebsSearches.A, C:\Users\Collin\AppData\Roaming\webssearches, In Quarantäne, [89774bb5ec145fa1d0c599d17f83b749],
PUP.Optional.WebsSearches.A, C:\Users\Collin\AppData\Roaming\webssearches\images, In Quarantäne, [89774bb5ec145fa1d0c599d17f83b749],
PUP.Optional.WebsSearches.A, C:\Users\Collin\AppData\Roaming\webssearches\log, In Quarantäne, [89774bb5ec145fa1d0c599d17f83b749],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
Dateien: 103
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [926edd23659bb8480548979e43bdda26],
PUP.Optional.NextLive.A, C:\Users\Collin\AppData\Roaming\newnext.me\nengine.dll, In Quarantäne, [ac5412eeb24e9d634c5490c0d52cd32d],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, In Quarantäne, [0df377899b65f40c84ee5ff3867b639d],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus-bho64.dll, In Quarantäne, [ad53d32d15eb669a77ed0364ac557789],
PUP.Optional.OpenCandy.A, C:\Users\Collin\AppData\Roaming\OpenCandy\E6F35348C12A400A8A3FD792EC8D8B6B\Setupsft_chr_p1v7.exe, In Quarantäne, [19e730d09d638d732bbe7ba80df76997],
PUP.Optional.SupTab.A, C:\Users\Collin\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [f60a39c7916f27d91439bf76f7092ad6],
PUP.Optional.NextLive.A, C:\Users\Collin\AppData\Local\genienext\nengine.dll, In Quarantäne, [ad53a858827ef50b57494b05ff02f709],
Trojan.Agent.OLG, C:\Users\Collin\Desktop\Programme\Yu-Gi-Oh! Power of Chaos LEGEND REBORN\All Cards - UNLOCKER\AllCards.exe, In Quarantäne, [4db37987c53b0cf4f0f6e1705da405fb],
RiskWare.Tool.CK, C:\Users\Collin\Desktop\Programme\OFFICE 2007\Generateur_Office.exe, In Quarantäne, [db2539c7837d8a7638607930c53c8b75],
PUP.Optional.QuickStart.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, In Quarantäne, [cf31db255ea2718fb53ba7d043bf9868],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\background.html, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\54246.crx, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\54246.xpi, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\MediaPlayerplus.ico, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\Uninstall.exe, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.MediaPlayerplus.A, C:\Program Files (x86)\MediaPlayerplus\utils.exe, In Quarantäne, [0bf5c33d10f0d729360a393f000233cd],
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit Update.job, In Quarantäne, [f20e3ac6817f1ce4799c12687989bc44],
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit_wd.job, In Quarantäne, [a15f847ca15ffa06e62fd9a10ef45aa6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [2ad6857b7789f40c5a7fa2e06b9740c0],
PUP.Optional.ReMarkit.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe, Löschen bei Neustart, [8c74976921dfb44c25eff68444be47b9],
PUP.Optional.OpenCandy, C:\Users\Collin\AppData\Roaming\OpenCandy\C0C88DEB32DE42E68AD37C273F1793EB\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [cd33f0102bd588782f6281e2808229d7],
PUP.Optional.NextLive.A, C:\Users\Collin\AppData\Roaming\newnext.me\nengine.cookie, In Quarantäne, [6f91eb1532ceff01c384e67fff03837d],
PUP.Optional.NextLive.A, C:\Users\Collin\AppData\Roaming\newnext.me\cache\spark.bin, In Quarantäne, [6f91eb1532ceff01c384e67fff03837d],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [f808f20ef808649c91cf87df976ba060],
PUP.Optional.HQVideoPro.A, C:\Program Files (x86)\HQ-Video-Pro-1.9\53172.crx, In Quarantäne, [e020f0104db3827ef874d98fe61cb848],
PUP.Optional.HQVideoPro.A, C:\Program Files (x86)\HQ-Video-Pro-1.9\53172.xpi, In Quarantäne, [e020f0104db3827ef874d98fe61cb848],
PUP.Optional.HQVideoPro.A, C:\Program Files (x86)\HQ-Video-Pro-1.9\Uninstall.exe, In Quarantäne, [e020f0104db3827ef874d98fe61cb848],
PUP.Optional.HQVideoPro.A, C:\Program Files (x86)\HQ-Video-Pro-1.9\utils.exe, In Quarantäne, [e020f0104db3827ef874d98fe61cb848],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\158.crx, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\158.dat, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\158.xpi, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\a.db, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\b.db, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL.exe, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.bin, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll, Löschen bei Neustart, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.ini, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe, Löschen bei Neustart, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Sqlite3.dll, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Uninstall.exe, In Quarantäne, [ad531ce46f9141bf6e95c9a1a260629e],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\b.html, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\b.js, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\c.js, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\icon128.png, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\icon16.png, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\icon48.png, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
PUP.Optional.TheBestDeals.A, C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\manifest.json, In Quarantäne, [b947b44cb7498c742921bfb0c93950b0],
Physische Sektoren: 0
(No malicious items detected)
(end) Adwcleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.204 - Bericht erstellt am 27/04/2014 um 22:01:59
# Aktualisiert 26/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Collin - COLLIN-HP
# Gestartet von : C:\Users\Collin\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : ICQ Service
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\AnyProtectEx
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Collin\.android
Ordner Gelöscht : C:\Users\Collin\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Collin\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Collin\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\Collin\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Collin\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Collin\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Collin\Documents\Mobogenie
Datei Gelöscht : C:\Users\Collin\daemonprocess.txt
Datei Gelöscht : C:\Users\Collin\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\Collin\AppData\Roaming\aps.scan.results
Datei Gelöscht : C:\Users\Collin\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP1.job
Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP1
Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP2.job
Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP2
Datei Gelöscht : C:\Windows\Tasks\APSnotifierPP3.job
Datei Gelöscht : C:\Windows\System32\Tasks\APSnotifierPP3
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{372479DD-B552-F0A8-F0E5-EEEEA6602285}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_ikea-home-planer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_ikea-home-planer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
*************************
AdwCleaner[R0].txt - [7203 octets] - [27/04/2014 21:53:17]
AdwCleaner[S0].txt - [6215 octets] - [27/04/2014 22:01:59]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6275 octets] ########## --- --- ---
JRT.txt: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Collin on 27.04.2014 at 22:18:30,23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{42218EA0-A1A3-4FAE-BBF7-7482498E8022}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{74FED47D-911D-4547-BEF1-555B2396451A}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{42218EA0-A1A3-4FAE-BBF7-7482498E8022}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\shoB23E.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoC734.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Empty Folder] C:\Users\Collin\appdata\local\{5C629015-1CB8-4666-BE94-CF5BC22595FE}
Successfully deleted: [Empty Folder] C:\Users\Collin\appdata\local\{80BAFD0F-ECCA-442F-BAE9-C7D89B2FDD8B}
Successfully deleted: [Empty Folder] C:\Users\Collin\appdata\local\{8644E06D-3362-4DB8-A471-D74F4BD506DC}
Successfully deleted: [Empty Folder] C:\Users\Collin\appdata\local\{9171C419-23AF-45D7-A70E-2E616C06CCB5}
Successfully deleted: [Empty Folder] C:\Users\Collin\appdata\local\{E2AA2232-9CF7-499A-A6D3-9678CACB19F1}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.04.2014 at 22:39:56,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und abschließend das frische FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-04-2014
Ran by Collin (administrator) on COLLIN-HP on 27-04-2014 22:45:09
Running from C:\Users\Collin\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
() C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
() C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-10] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-06-08] (IDT, Inc.)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [42808 2011-06-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation)
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [168504 2011-06-28] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-05-17] (EasyBits Software AS)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Guard.Mail.ru.gui] => C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [1564368 2012-03-30] ()
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-29] (Easybits)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-22] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {42218EA0-A1A3-4FAE-BBF7-7482498E8022} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKCU - DefaultScope {74FED47D-911D-4547-BEF1-555B2396451A} URL =
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
BHO: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: ICQ Sparberater - {0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: TrueSuite Website Log On - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-07-15] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-06-07]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Docs) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-15]
CHR Extension: (Google Drive) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-15]
CHR Extension: (YouTube) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-15]
CHR Extension: (Google Search) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-15]
CHR Extension: (Website Logon) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfaldikcoaplhepekpbngkepfcoiihef [2013-11-15]
CHR Extension: (Google Wallet) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-15]
CHR Extension: (Gmail) - C:\Users\Collin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-15]
CHR HKLM-x32\...\Chrome\Extension: [dfaldikcoaplhepekpbngkepfcoiihef] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-08-22]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [240736 2013-10-07] (WildTangent)
R2 Guard.Mail.ru; C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [1564368 2012-03-30] ()
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-27 22:39 - 2014-04-27 22:39 - 00001780 _____ () C:\Users\Collin\Desktop\JRT.txt
2014-04-27 22:18 - 2014-04-27 22:18 - 00000000 ____D () C:\Windows\ERUNT
2014-04-27 22:16 - 2014-04-27 22:16 - 01016261 _____ (Thisisu) C:\Users\Collin\Desktop\JRT.exe
2014-04-27 22:04 - 2014-04-27 22:04 - 00006375 _____ () C:\Users\Collin\Desktop\AdwCleaner[S0].txt
2014-04-27 21:53 - 2014-04-27 22:02 - 00000000 ____D () C:\AdwCleaner
2014-04-27 21:33 - 2014-04-27 21:33 - 01329501 _____ () C:\Users\Collin\Desktop\adwcleaner.exe
2014-04-27 21:32 - 2014-04-27 21:32 - 00031178 _____ () C:\Users\Collin\Desktop\mbam.txt
2014-04-27 19:21 - 2014-04-27 21:29 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 19:20 - 2014-04-27 19:20 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-27 19:20 - 2014-04-27 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-27 19:20 - 2014-04-27 19:20 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-27 19:20 - 2014-04-27 19:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-27 19:20 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-27 19:20 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-27 19:20 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-27 18:57 - 2014-04-27 18:57 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Collin\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-26 13:10 - 2014-04-26 13:10 - 00035821 _____ () C:\ComboFix.txt
2014-04-26 12:44 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-26 12:44 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-26 12:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-26 12:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-26 12:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-26 12:44 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-26 12:44 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-26 12:44 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-26 12:42 - 2014-04-26 13:10 - 00000000 ____D () C:\Qoobox
2014-04-26 12:42 - 2014-04-26 13:07 - 00000000 ____D () C:\Windows\erdnt
2014-04-26 12:42 - 2014-04-26 12:42 - 00000000 ___RD () C:\Users\Collin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-26 02:45 - 2014-04-26 02:45 - 05196870 ____R (Swearware) C:\Users\Collin\Desktop\ComboFix.exe
2014-04-24 17:33 - 2014-04-27 22:08 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForCollin
2014-04-24 17:33 - 2014-04-27 22:08 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleForCollin.job
2014-04-24 15:04 - 2014-04-24 15:04 - 00004925 _____ () C:\Users\Collin\Desktop\Gmer.txt
2014-04-24 14:44 - 2014-04-24 14:44 - 00380416 _____ () C:\Users\Collin\Desktop\Gmer-19357.exe
2014-04-24 14:39 - 2014-04-24 14:41 - 00021455 _____ () C:\Users\Collin\Desktop\Addition.txt
2014-04-24 14:37 - 2014-04-27 22:45 - 00017310 _____ () C:\Users\Collin\Desktop\FRST.txt
2014-04-24 14:37 - 2014-04-27 22:45 - 00000000 ____D () C:\FRST
2014-04-24 14:33 - 2014-04-24 14:33 - 02061824 _____ (Farbar) C:\Users\Collin\Desktop\FRST64.exe
2014-04-24 14:31 - 2014-04-24 14:31 - 00000474 _____ () C:\Users\Collin\Desktop\defogger_disable.log
2014-04-24 14:31 - 2014-04-24 14:31 - 00000000 _____ () C:\Users\Collin\defogger_reenable
2014-04-24 14:30 - 2014-04-24 14:30 - 00050477 _____ () C:\Users\Collin\Desktop\Defogger.exe
2014-04-22 16:03 - 2014-04-22 16:03 - 00000000 __SHD () C:\Users\Collin\AppData\Local\EmieUserList
2014-04-22 16:03 - 2014-04-22 16:03 - 00000000 __SHD () C:\Users\Collin\AppData\Local\EmieSiteList
2014-04-22 16:00 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-22 16:00 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-22 16:00 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-22 16:00 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-22 15:59 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-22 15:59 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-22 15:59 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-22 15:59 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-22 15:59 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-22 15:59 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-22 15:59 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-22 15:59 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-22 15:59 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-22 15:59 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-22 15:59 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-22 15:59 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-22 15:59 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-22 15:59 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-22 15:59 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-22 15:59 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-22 15:59 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-22 15:59 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-22 15:59 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-22 15:59 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-22 15:59 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-22 15:59 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-22 15:59 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-22 15:59 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-22 15:59 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-22 15:59 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-22 15:59 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-22 15:59 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-22 15:59 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-22 15:59 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-22 15:59 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-22 15:59 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-22 15:59 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-22 15:59 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-22 15:59 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-22 15:59 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-22 15:59 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-22 15:59 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-22 15:59 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-22 15:59 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-22 15:59 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-22 15:59 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-22 15:59 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-22 15:59 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-19 18:03 - 2014-04-19 19:06 - 00000000 ___RD () C:\Users\Collin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 18:02 - 2014-04-19 18:02 - 00003158 _____ () C:\Windows\System32\Tasks\{63413530-4970-4B09-9431-53CAB00FB246}
2014-04-19 17:59 - 2014-04-19 18:02 - 00000000 ____D () C:\ProgramData\WPM
2014-04-19 17:58 - 2014-04-19 17:58 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-17 11:18 - 2014-04-17 11:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-17 11:18 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-17 11:18 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-17 11:18 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-17 11:18 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-17 11:17 - 2014-04-17 11:18 - 00005449 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-15 13:04 - 2014-04-15 13:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RStudio
2014-04-15 13:04 - 2014-04-15 13:04 - 00000000 ____D () C:\Program Files\RStudio
2014-04-13 16:12 - 2014-04-13 16:12 - 00003606 _____ () C:\Users\Collin\Desktop\DATEN.csv
2014-04-09 13:45 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 13:45 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 13:45 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 13:45 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 13:45 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 13:45 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 13:45 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 13:45 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 13:45 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 13:45 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 13:45 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 13:45 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 13:45 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 13:45 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 13:45 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 13:45 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 13:45 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-07 13:35 - 2014-04-07 13:36 - 00000000 ____D () C:\Users\Collin\Desktop\Bilder
2014-04-07 13:29 - 2014-04-07 13:29 - 00000000 ____D () C:\Users\Collin\AppData\Roaming\OpenOffice
2014-04-07 13:28 - 2014-04-07 13:28 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk
2014-04-07 13:28 - 2014-04-07 13:28 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2014-04-07 13:27 - 2014-04-07 13:28 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-04-07 12:12 - 2014-04-15 02:30 - 00012618 _____ () C:\Users\Collin\Desktop\Stundenplan SS2014.ods
2014-03-31 14:48 - 2014-03-31 14:48 - 00000165 ____H () C:\Users\Collin\Desktop\~$Stundenplan WS 2013.xlsx
2014-03-28 16:54 - 2014-03-28 16:54 - 00002217 _____ () C:\Users\Collin\Desktop\HP Support Assistant.lnk
2014-03-28 16:49 - 2014-03-28 16:49 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
==================== One Month Modified Files and Folders =======
2014-04-27 22:45 - 2014-04-24 14:37 - 00017310 _____ () C:\Users\Collin\Desktop\FRST.txt
2014-04-27 22:45 - 2014-04-24 14:37 - 00000000 ____D () C:\FRST
2014-04-27 22:39 - 2014-04-27 22:39 - 00001780 _____ () C:\Users\Collin\Desktop\JRT.txt
2014-04-27 22:21 - 2013-11-14 22:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-27 22:20 - 2013-11-14 22:51 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-27 22:18 - 2014-04-27 22:18 - 00000000 ____D () C:\Windows\ERUNT
2014-04-27 22:16 - 2014-04-27 22:16 - 01016261 _____ (Thisisu) C:\Users\Collin\Desktop\JRT.exe
2014-04-27 22:13 - 2011-11-16 10:28 - 01461411 _____ () C:\Windows\WindowsUpdate.log
2014-04-27 22:11 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-27 22:11 - 2009-07-14 06:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-27 22:08 - 2014-04-24 17:33 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForCollin
2014-04-27 22:08 - 2014-04-24 17:33 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleForCollin.job
2014-04-27 22:04 - 2014-04-27 22:04 - 00006375 _____ () C:\Users\Collin\Desktop\AdwCleaner[S0].txt
2014-04-27 22:03 - 2013-11-14 22:51 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-27 22:03 - 2010-11-21 05:47 - 00568258 _____ () C:\Windows\PFRO.log
2014-04-27 22:03 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-27 22:03 - 2009-07-14 06:51 - 00149732 _____ () C:\Windows\setupact.log
2014-04-27 22:02 - 2014-04-27 21:53 - 00000000 ____D () C:\AdwCleaner
2014-04-27 22:02 - 2011-12-24 19:47 - 00000000 ____D () C:\Users\Collin
2014-04-27 21:33 - 2014-04-27 21:33 - 01329501 _____ () C:\Users\Collin\Desktop\adwcleaner.exe
2014-04-27 21:32 - 2014-04-27 21:32 - 00031178 _____ () C:\Users\Collin\Desktop\mbam.txt
2014-04-27 21:29 - 2014-04-27 19:21 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 19:20 - 2014-04-27 19:20 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-27 19:20 - 2014-04-27 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-27 19:20 - 2014-04-27 19:20 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-27 19:20 - 2014-04-27 19:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-27 18:57 - 2014-04-27 18:57 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Collin\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-27 17:45 - 2013-11-12 10:04 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{8284362C-B5C4-4E7C-B824-25F2F57764D4}
2014-04-26 13:10 - 2014-04-26 13:10 - 00035821 _____ () C:\ComboFix.txt
2014-04-26 13:10 - 2014-04-26 12:42 - 00000000 ____D () C:\Qoobox
2014-04-26 13:07 - 2014-04-26 12:42 - 00000000 ____D () C:\Windows\erdnt
2014-04-26 13:06 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-26 12:42 - 2014-04-26 12:42 - 00000000 ___RD () C:\Users\Collin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-26 02:45 - 2014-04-26 02:45 - 05196870 ____R (Swearware) C:\Users\Collin\Desktop\ComboFix.exe
2014-04-25 18:34 - 2012-01-10 00:42 - 00000000 ____D () C:\Users\Collin\AppData\Local\CrashDumps
2014-04-24 18:19 - 2012-07-18 21:05 - 00000216 _____ () C:\Users\Collin\Desktop\FILME.txt
2014-04-24 17:32 - 2012-01-16 22:52 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-24 17:32 - 2011-12-30 01:26 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-04-24 15:04 - 2014-04-24 15:04 - 00004925 _____ () C:\Users\Collin\Desktop\Gmer.txt
2014-04-24 14:44 - 2014-04-24 14:44 - 00380416 _____ () C:\Users\Collin\Desktop\Gmer-19357.exe
2014-04-24 14:41 - 2014-04-24 14:39 - 00021455 _____ () C:\Users\Collin\Desktop\Addition.txt
2014-04-24 14:33 - 2014-04-24 14:33 - 02061824 _____ (Farbar) C:\Users\Collin\Desktop\FRST64.exe
2014-04-24 14:31 - 2014-04-24 14:31 - 00000474 _____ () C:\Users\Collin\Desktop\defogger_disable.log
2014-04-24 14:31 - 2014-04-24 14:31 - 00000000 _____ () C:\Users\Collin\defogger_reenable
2014-04-24 14:30 - 2014-04-24 14:30 - 00050477 _____ () C:\Users\Collin\Desktop\Defogger.exe
2014-04-22 16:03 - 2014-04-22 16:03 - 00000000 __SHD () C:\Users\Collin\AppData\Local\EmieUserList
2014-04-22 16:03 - 2014-04-22 16:03 - 00000000 __SHD () C:\Users\Collin\AppData\Local\EmieSiteList
2014-04-22 16:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-19 19:06 - 2014-04-19 18:03 - 00000000 ___RD () C:\Users\Collin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-19 19:06 - 2012-03-21 11:28 - 00000000 ___HD () C:\Users\Collin\Documents\Runes of Magic
2014-04-19 19:06 - 2012-03-21 11:05 - 00000000 ____D () C:\Program Files (x86)\Runes of Magic
2014-04-19 19:06 - 2012-03-12 14:45 - 00000000 ____D () C:\Users\Collin\AppData\Roaming\RStudio
2014-04-19 19:06 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-19 19:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-04-19 18:02 - 2014-04-19 18:02 - 00003158 _____ () C:\Windows\System32\Tasks\{63413530-4970-4B09-9431-53CAB00FB246}
2014-04-19 18:02 - 2014-04-19 17:59 - 00000000 ____D () C:\ProgramData\WPM
2014-04-19 17:58 - 2014-04-19 17:58 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-19 17:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-17 12:08 - 2011-07-16 07:32 - 00700134 _____ () C:\Windows\system32\perfh007.dat
2014-04-17 12:08 - 2011-07-16 07:32 - 00149984 _____ () C:\Windows\system32\perfc007.dat
2014-04-17 12:08 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-17 11:20 - 2013-11-06 11:15 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-17 11:18 - 2014-04-17 11:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-17 11:18 - 2014-04-17 11:17 - 00005449 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-17 11:18 - 2013-11-06 11:15 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-15 13:04 - 2014-04-15 13:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RStudio
2014-04-15 13:04 - 2014-04-15 13:04 - 00000000 ____D () C:\Program Files\RStudio
2014-04-15 02:30 - 2014-04-07 12:12 - 00012618 _____ () C:\Users\Collin\Desktop\Stundenplan SS2014.ods
2014-04-14 20:13 - 2014-04-17 11:18 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-04-17 11:18 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-04-17 11:18 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-04-17 11:18 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-13 16:12 - 2014-04-13 16:12 - 00003606 _____ () C:\Users\Collin\Desktop\DATEN.csv
2014-04-13 14:49 - 2011-12-24 19:54 - 00000000 ____D () C:\Users\Collin\AppData\Roaming\Skype
2014-04-10 03:06 - 2012-09-04 09:09 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 03:05 - 2013-07-16 01:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 03:02 - 2012-09-27 18:44 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-08 13:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-08 12:52 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-08 09:40 - 2009-07-14 06:45 - 00370840 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-07 13:36 - 2014-04-07 13:35 - 00000000 ____D () C:\Users\Collin\Desktop\Bilder
2014-04-07 13:36 - 2012-03-13 01:36 - 00000000 ___RD () C:\Users\Collin\Desktop\Programme
2014-04-07 13:34 - 2012-03-13 01:41 - 00000000 ____D () C:\Users\Collin\Desktop\Uni
2014-04-07 13:29 - 2014-04-07 13:29 - 00000000 ____D () C:\Users\Collin\AppData\Roaming\OpenOffice
2014-04-07 13:29 - 2011-12-24 19:52 - 00092944 _____ () C:\Users\Collin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-07 13:28 - 2014-04-07 13:28 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.0.1.lnk
2014-04-07 13:28 - 2014-04-07 13:28 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.1
2014-04-07 13:28 - 2014-04-07 13:27 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-04-07 12:13 - 2011-12-28 14:28 - 00000000 ____D () C:\Users\Collin\AppData\Roaming\SoftGrid Client
2014-04-07 02:00 - 2012-12-06 15:18 - 00003220 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForCOLLIN-HP$
2014-04-07 02:00 - 2012-12-06 15:18 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForCOLLIN-HP$.job
2014-04-03 09:51 - 2014-04-27 19:20 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-27 19:20 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-27 19:20 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 14:48 - 2014-03-31 14:48 - 00000165 ____H () C:\Users\Collin\Desktop\~$Stundenplan WS 2013.xlsx
2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-28 16:54 - 2014-03-28 16:54 - 00002217 _____ () C:\Users\Collin\Desktop\HP Support Assistant.lnk
2014-03-28 16:54 - 2011-07-15 22:07 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2014-03-28 16:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help
2014-03-28 16:51 - 2011-07-15 22:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-28 16:51 - 2011-07-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-03-28 16:49 - 2014-03-28 16:49 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-03-28 16:46 - 2011-07-15 22:10 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-03-28 16:45 - 2011-02-10 21:23 - 00000000 ____D () C:\SWSetup
2014-03-28 01:15 - 2013-11-14 22:51 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-28 01:15 - 2013-11-14 22:51 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
Some content of TEMP:
====================
C:\Users\Collin\AppData\Local\Temp\avgnt.exe
C:\Users\Collin\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 21:40
==================== End Of Log ============================ --- --- ---
--- --- --- |