oShortyo | 27.05.2014 19:57 | MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.05.2014
Suchlauf-Zeit: 20:04:18
Logdatei: VerlaufMBAM.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.05.27.08
Rootkit Datenbank: v2014.05.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: alex
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 462548
Verstrichene Zeit: 18 Min, 7 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.AdPeak.A, C:\Program Files\004\rqpbhevlkc64.exe, 2132, Löschen bei Neustart, [6004d5810b708caae78f741d55adb54b]
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\CouponDownloaderService64.exe, 1888, Löschen bei Neustart, [21433c1a9be01a1cc9c97c094cb6926e]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 15
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [5c085bfb9cdfa1959d1d6ebe1ae8f907],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [5c085bfb9cdfa1959d1d6ebe1ae8f907],
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rqpbhevlkc64, In Quarantäne, [6004d5810b708caae78f741d55adb54b],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\Coupon Downloader, In Quarantäne, [ec78b89eadcef3431a222c6572903ec2],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\CouponDownloader, In Quarantäne, [550ffd594d2efd390e2fafe2c1415da3],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\coupon downloader, In Quarantäne, [d78d94c26c0f0c2ae25f860b60a2a957],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{813BA625-B0FA-48D8-9B75-59759C88C219}, In Quarantäne, [4c1834224f2cd85ed179226fbf430cf4],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\CouponDownloader, In Quarantäne, [e084dc7aa2d966d0c6777b16ba48e917],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [6afa282e7efdb680e602cb076c974bb5],
PUP.Optional.WpManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WPM, In Quarantäne, [d98b6de97407dc5a4b83705eb64d0bf5],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Coupon Downloader, In Quarantäne, [e480fc5a4536c274e35ba7ea9a686799],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\CouponDownloader, In Quarantäne, [acb8b2a46417b77fce71b4ddbe449868],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3645962933-2417628836-968681902-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [acb8c5911a6143f39b89eeba709202fe],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3645962933-2417628836-968681902-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [89db5600dba061d5ab86239bdd26f10f],
PUP.Optional.CouponDownloader.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CouponDownloaderService64, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
Registrierungswerte: 3
PUP.Optional.NextLive.A, HKU\S-1-5-21-3645962933-2417628836-968681902-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\Windows\SysWOW64\rundll32.exe "C:\Users\alex\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, In Quarantäne, [d78d7cda2952fe38b68c193c70918878]
PUP.Optional.WpManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WPM|ImagePath, C:\ProgramData\WPM\wprotectmanager.exe -service, In Quarantäne, [d98b6de97407dc5a4b83705eb64d0bf5]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3645962933-2417628836-968681902-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [89db5600dba061d5ab86239bdd26f10f]
Registrierungsdaten: 1
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1399720625&from=cor&uid=ST500DM002-1BD142_Z2AEGR6GXXXXZ2AEGR6G&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1399720625&from=cor&uid=ST500DM002-1BD142_Z2AEGR6GXXXXZ2AEGR6G&q={searchTerms}),Ersetzt,[b7ad421496e58ea8211511494eb62fd1]
Ordner: 16
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\cache, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.NextLive.A, C:\Users\alex\AppData\Roaming\newnext.me, In Quarantäne, [3232abab4f2c003657160376c33fdf21],
PUP.Optional.NextLive.A, C:\Users\alex\AppData\Roaming\newnext.me\cache, In Quarantäne, [3232abab4f2c003657160376c33fdf21],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\components, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\defaults, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\defaults\preferences, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.CouponDownloader.A, C:\Program Files\coupon downloader, In Quarantäne, [d98b4a0c3d3e74c289fda0e5738fdb25],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\Coupon Downloader, In Quarantäne, [c79d3a1cdd9ed264ee98097c1be7fb05],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader, Löschen bei Neustart, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\SSL, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
Dateien: 103
PUP.Optional.NextLive.A, C:\Users\alex\AppData\Roaming\newnext.me\nengine.dll, In Quarantäne, [d78d7cda2952fe38b68c193c70918878],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\Coupon Downloader\Coupon Downloader.dll, In Quarantäne, [5c085bfb9cdfa1959d1d6ebe1ae8f907],
PUP.Optional.CouponDownloader.A, C:\Temp\t_ie.exe, In Quarantäne, [0064a0b6700bf046053cf64d01ffa060],
PUP.Optional.InstallCore, C:\Users\alex\Downloads\CamStudio_Setup_v2.7.2_r326_(build_19Oct2013).exe, In Quarantäne, [cb9985d1037866d0d82d3d11dc2820e0],
PUP.Optional.NextLive.A, C:\Users\alex\AppData\Local\genienext\nengine.dll, In Quarantäne, [d490df77186353e3f25014417988ce32],
PUP.Optional.Superfish.A, C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [7de795c1a0db04325ae9d0bf927012ee],
PUP.Optional.Superfish.A, C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [65ffdb7b304b61d5d86b7e1179895ba5],
PUP.Optional.AdPeak.A, C:\Program Files\004\rqpbhevlkc64.exe, Löschen bei Neustart, [6004d5810b708caae78f741d55adb54b],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [640022347cffac8a8589287abf43c040],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\BCHelper.exe, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\fix2.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\icon.png, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\jquery4toolbar.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\lock.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\witapi.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\witmain.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\wittoolbar.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.Blabbers, C:\Users\alex\AppData\LocalLow\bbrs_002.tb\content\witwidgetapi.js, In Quarantäne, [273d70e6eb90dd59b2246f0780829967],
PUP.Optional.NextLive.A, C:\Users\alex\AppData\Roaming\newnext.me\nengine.cookie, In Quarantäne, [3232abab4f2c003657160376c33fdf21],
PUP.Optional.NextLive.A, C:\Users\alex\AppData\Roaming\newnext.me\cache\spark.bin, In Quarantäne, [3232abab4f2c003657160376c33fdf21],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\chrome.manifest, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\install.rdf, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\babylon.css, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\babylon.xul, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\mtstart.js, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\server.js, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\tmplt.js, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js, In Quarantäne, [e77d322493e8072f62d33e3f38ca5aa6],
PUP.Optional.CouponDownloader.A, C:\Program Files\coupon downloader\uninstaller.exe, In Quarantäne, [d98b4a0c3d3e74c289fda0e5738fdb25],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\Coupon Downloader\64.ico, In Quarantäne, [c79d3a1cdd9ed264ee98097c1be7fb05],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\Coupon Downloader\uninstall.exe, In Quarantäne, [c79d3a1cdd9ed264ee98097c1be7fb05],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\CouponDownloaderService64.exe, Löschen bei Neustart, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\Installbat64.dll, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\nfapi.dll, Löschen bei Neustart, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\nfregdrv.exe, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\ProtocolFilters.dll, Löschen bei Neustart, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.CouponDownloader.A, C:\Program Files\CouponDownloader\sample.dll, In Quarantäne, [21433c1a9be01a1cc9c97c094cb6926e],
PUP.Optional.SweetPage.A, C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.sweet-page.com/?type=hp&ts=1399720625&from=cor&uid=ST500DM002-1BD142_Z2AEGR6GXXXXZ2AEGR6G" ],), Ersetzt,[6bf9352191eaa6903d7fcdbab94b06fa]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.admin", false);), Ersetzt,[501474e2aad1b581595a444243c12bd5]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.aflt", "orgnl");), Ersetzt,[30343026413a31057c37e6a00004ed13]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.bbDpng", 4);), Ersetzt,[87ddc78f2e4d241205aefd890bf915eb]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltSrch", false);), Ersetzt,[5f05a2b46d0ea294446f4343699ba759]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.hmpg", false);), Ersetzt,[b1b325310279e84ea3108ef8f212b848]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastDP", 4);), Ersetzt,[a4c09abccfac57df0da6bec83dc79769]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastVrsnTs", "");), Ersetzt,[3f253521bdbe5fd70da6810557adc63a]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "10.0");), Ersetzt,[244098be83f8e254b5fee79f25dfa45c]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTab", true);), Ersetzt,[68fcdf77bdbe64d29a19275fc044f40c]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");), Ersetzt,[8bd9cd89accff244941f572f1be91ae6]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.noFFXTlbr", false);), Ersetzt,[a8bc1343d0ab83b3ddd67c0a6e966f91]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.propectorlck", 66920144);), Ersetzt,[4c180056c9b2e84e466db1d5d72ddd23]
PUP.Optional.Babylon.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.smplGrp", "free");), Ersetzt,[73f13a1c88f31620971c6d1952b22fd1]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods._xpiupdate", true);), Ersetzt,[95cfd87ec9b2c96d3d7c3f4740c4db25]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.aflt", "_#wbst");), Ersetzt,[550f84d2a2d9e74fbefb256151b36e92]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");), Ersetzt,[b4b00452adcea2943485751113f1966a]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.firstRun", false);), Ersetzt,[0460e373b9c2e353a6138600bd47d828]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.first_time", false);), Ersetzt,[e183a8ae4833c67080395135fa0ab64a]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.id", "_#644e7958f35242a7839b103a004013d3");), Ersetzt,[a3c174e2225971c525940e7841c3b24e]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.instlDay", "_#15204");), Ersetzt,[13515cfa334892a420995531cb39a15f]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");), Ersetzt,[9fc562f4b9c2b18589309bebf90b946c]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.sid", "_#644e7958f35242a7839b103a004013d3");), Ersetzt,[5c080b4ba2d96accf6c36026be46a45c]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.uninst", true);), Ersetzt,[1b4994c26b1075c1cfea0383d72d926e]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.update", "_#v1.4.0");), Ersetzt,[aaba3a1c0a717eb83c7de3a38e769d63]
PUP.Optional.FaceMoods.A, C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");), Ersetzt,[9ec6c88e9be071c5bffacbbb9d678f71]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v3.211 - Bericht erstellt am 27/05/2014 um 20:35:23
# Aktualisiert 26/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : alex - GOTTHEIT
# Gestartet von : C:\Users\alex\Downloads\adwcleaner_3.211.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : MgAssistService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Maximizer
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Program Files (x86)\YourFileDownloader
Ordner Gelöscht : C:\Users\alex\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\alex\AppData\Local\genienext
Ordner Gelöscht : C:\Users\alex\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\alex\AppData\LocalLow\BabylonToolbar
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Advanced System Protector
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\sweet-page
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\YourFileDownloader
Ordner Gelöscht : C:\Users\alex\Documents\Mobogenie
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Conduit
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\CT2613550
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\bbrs_002@blabbers.com
Ordner Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\ffxtlbr@babylon.com
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}
Ordner Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{fc2b76fc-2132-4d80-a9a3-1f5c6e49066b}
Datei Gelöscht : C:\Users\alex\daemonprocess.txt
Datei Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\6umqdxa8.default\user.js
Datei Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\9vlvub1i.default\user.js
Datei Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\qk9uu440.default\user.js
Datei Gelöscht : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\user.js
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Advanced System Protector
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}]
Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\Microsoft\Babylon
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\YourFileDownloader
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\YourFileDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Speed Maximizer_is1
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\6umqdxa8.default\prefs.js ]
[ Datei : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\9vlvub1i.default\prefs.js ]
[ Datei : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\qk9uu440.default\prefs.js ]
[ Datei : C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\prefs.js ]
Zeile gelöscht : user_pref("CT2613550..clientLogIsEnabled", true);
Zeile gelöscht : user_pref("CT2613550..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Zeile gelöscht : user_pref("CT2613550..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Zeile gelöscht : user_pref("CT2613550.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Zeile gelöscht : user_pref("CT2613550.CurrentServerDate", "22-4-2011");
Zeile gelöscht : user_pref("CT2613550.DialogsAlignMode", "LTR");
Zeile gelöscht : user_pref("CT2613550.DialogsGetterLastCheckTime", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.DownloadReferralCookieData", "");
Zeile gelöscht : user_pref("CT2613550.EMailNotifierPollDate", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedLastCount3082739963941193807", 402);
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255190875796966", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255191286404846", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255191690696803", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255191830767423", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255192204641884", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255192330261614", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255192609293799", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255192844976705", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193025486845", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193127848905", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193189289837", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193256322449", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193310202497", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193760634970", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255193813312257", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255194862513855", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedPollDate7861255194875474195", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.FeedTTL7861255190875796966", 5);
Zeile gelöscht : user_pref("CT2613550.FeedTTL7861255191286404846", 2);
Zeile gelöscht : user_pref("CT2613550.FeedTTL7861255191830767423", 30);
Zeile gelöscht : user_pref("CT2613550.FeedTTL7861255192844976705", 5);
Zeile gelöscht : user_pref("CT2613550.FeedTTL7861255193256322449", 5);
Zeile gelöscht : user_pref("CT2613550.FeedTTL7861255193310202497", 2);
Zeile gelöscht : user_pref("CT2613550.FirstServerDate", "22-4-2011");
Zeile gelöscht : user_pref("CT2613550.FirstTimeFF3", true);
Zeile gelöscht : user_pref("CT2613550.GroupingServerCheckInterval", 1440);
Zeile gelöscht : user_pref("CT2613550.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Zeile gelöscht : user_pref("CT2613550.HasUserGlobalKeys", true);
Zeile gelöscht : user_pref("CT2613550.InstallationAndCookieDataSentCount", 1);
Zeile gelöscht : user_pref("CT2613550.InstallationType", "UnknownIntegration");
Zeile gelöscht : user_pref("CT2613550.InstalledDate", "Fri Apr 22 2011 11:41:51 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.IsGrouping", false);
Zeile gelöscht : user_pref("CT2613550.IsMulticommunity", false);
Zeile gelöscht : user_pref("CT2613550.IsOpenThankYouPage", false);
Zeile gelöscht : user_pref("CT2613550.IsOpenUninstallPage", true);
Zeile gelöscht : user_pref("CT2613550.LanguagePackLastCheckTime", "Fri Apr 22 2011 11:41:56 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.LanguagePackReloadIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2613550.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Zeile gelöscht : user_pref("CT2613550.LastLogin_3.3.3.2", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.LatestVersion", "3.3.3.2");
Zeile gelöscht : user_pref("CT2613550.Locale", "de-de");
Zeile gelöscht : user_pref("CT2613550.MCDetectTooltipHeight", "83");
Zeile gelöscht : user_pref("CT2613550.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Zeile gelöscht : user_pref("CT2613550.MCDetectTooltipWidth", "295");
Zeile gelöscht : user_pref("CT2613550.SearchFromAddressBarIsInit", true);
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabEnabled", true);
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabLastCheckTime", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2613550.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Zeile gelöscht : user_pref("CT2613550.ServiceMapLastCheckTime", "Fri Apr 22 2011 11:41:48 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.SettingsLastCheckTime", "Fri Apr 22 2011 11:41:48 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.SettingsLastUpdate", "1300822090");
Zeile gelöscht : user_pref("CT2613550.ThirdPartyComponentsInterval", 504);
Zeile gelöscht : user_pref("CT2613550.ThirdPartyComponentsLastCheck", "Fri Apr 22 2011 11:41:48 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.ThirdPartyComponentsLastUpdate", "1255344657");
Zeile gelöscht : user_pref("CT2613550.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2613550");
Zeile gelöscht : user_pref("CT2613550.UserID", "UN26110693853251377");
Zeile gelöscht : user_pref("CT2613550.alertChannelId", "1006347");
Zeile gelöscht : user_pref("CT2613550.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdownload.conduit.com/\"}");
Zeile gelöscht : user_pref("CT2613550.globalFirstTimeInfoLastCheckTime", "Fri Apr 22 2011 11:41:52 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.isAppTrackingManagerOn", true);
Zeile gelöscht : user_pref("CT2613550.myStuffEnabled", true);
Zeile gelöscht : user_pref("CT2613550.myStuffPublihserMinWidth", 400);
Zeile gelöscht : user_pref("CT2613550.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Zeile gelöscht : user_pref("CT2613550.myStuffServiceIntervalMM", 1440);
Zeile gelöscht : user_pref("CT2613550.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Zeile gelöscht : user_pref("CT2613550.testingCtid", "");
Zeile gelöscht : user_pref("CT2613550.toolbarAppMetaDataLastCheckTime", "Fri Apr 22 2011 11:41:49 GMT+0200");
Zeile gelöscht : user_pref("CT2613550.toolbarContextMenuLastCheckTime", "Fri Apr 22 2011 11:41:55 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "CT2613550");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2613550", "\"1280438147\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=de-de", "hrY3aRo68pvVAKwJTjMFmA==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=de-de", "uwY9T5AsudBxjradvWCAOA==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=de-de", "D/tN3YiKFksK+RjZytPhIA==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=de-de", "SuMy8xgBA7+FodOxmk9aiQ==");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"803651ba7facb1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2613550", "\"634386539058500000\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2613550/CT2613550", "\"1300822090\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/50/261/CT2613550/Images/634084971246361250.png", "\"462e8b16c4eaca1:0\"");
Zeile gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de-de", "\"634351849102130000\"");
Zeile gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Apr 22 2011 11:41:55 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.locale", "en");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri Apr 22 2011 11:41:46 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
Zeile gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Zeile gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Zeile gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Zeile gelöscht : user_pref("CommunityToolbar.alert.userId", "1f347ba2-2bcd-4805-bf5c-998ca4a0c5e9");
Zeile gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Fri Apr 22 2011 11:41:55 GMT+0200");
Zeile gelöscht : user_pref("CommunityToolbar.globalUserId", "6cf9d92f-578c-4ebc-a953-47611137b1ce");
Zeile gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Zeile gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.admin", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.aflt", "orgnl");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.bbDpng", 4);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.dfltSrch", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.hmpg", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.lastDP", 4);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.lastVrsnTs", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "10.0");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newTab", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_FFUP");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.propectorlck", 66920144);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.smplGrp", "free");
Zeile gelöscht : user_pref("extensions.facemoods._xpiupdate", true);
Zeile gelöscht : user_pref("extensions.facemoods.aflt", "_#wbst");
Zeile gelöscht : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4");
Zeile gelöscht : user_pref("extensions.facemoods.firstRun", false);
Zeile gelöscht : user_pref("extensions.facemoods.first_time", false);
Zeile gelöscht : user_pref("extensions.facemoods.id", "_#644e7958f35242a7839b103a004013d3");
Zeile gelöscht : user_pref("extensions.facemoods.instlDay", "_#15204");
Zeile gelöscht : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com");
Zeile gelöscht : user_pref("extensions.facemoods.sid", "_#644e7958f35242a7839b103a004013d3");
Zeile gelöscht : user_pref("extensions.facemoods.uninst", true);
Zeile gelöscht : user_pref("extensions.facemoods.update", "_#v1.4.0");
Zeile gelöscht : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5");
Zeile gelöscht : user_pref("extensions.ffxtlbr@Facemoods.com.install-event-fired", true);
Zeile gelöscht : user_pref("extensions.ffxtlbr@babylon.com.install-event-fired", true);
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.hotspotshield.com/g/results.php?c=s&q=");
[ Datei : C:\Users\Alex 2\AppData\Roaming\Mozilla\Firefox\Profiles\z5o7txf5.default\prefs.js ]
Zeile gelöscht : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\11.1.0.12");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid=%7Bb317a4a0-ad96-4053-9df5-ea1a0f572ed2%7D&mid=899b88d05df444d0b122888305ab0f4b-874ce4798f999b867eddc6c8df08b313a2d08c64&ds=or011&v=11.1.0.1[...]
-\\ Google Chrome v35.0.1916.114
[ Datei : C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [23460 octets] - [27/05/2014 20:33:23]
AdwCleaner[S0].txt - [22716 octets] - [27/05/2014 20:35:23]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [22777 octets] ########## --- --- ---
[/CODE]
JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by alex on 27.05.2014 at 20:41:39,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Successfully deleted: [File] C:\Users\alex\AppData\Roaming\mozilla\firefox\profiles\yv0afey1.default\extensions\searchy@searchy.xpi
Successfully deleted the following from C:\Users\alex\AppData\Roaming\mozilla\firefox\profiles\yv0afey1.default\prefs.js
user_pref("socialfixer.100000217732050/typeahead_new", "for (;;);{\"__ar\":1,\"payload\":{\"entries\":[{\"uid\":100003109857242,\"photo\":\"hxxp:\\/\\/profile.ak.fbcdn.net\\/h
Emptied folder: C:\Users\alex\AppData\Roaming\mozilla\firefox\profiles\yv0afey1.default\minidumps [45 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.05.2014 at 20:52:22,45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by alex (administrator) on GOTTHEIT on 27-05-2014 20:53:31
Running from C:\Users\alex\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Check Point Software Technologies) C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
() C:\Program Files\MySQL\MySQL Server 5.7\bin\mysqld.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccsvchst.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files\USBLogon\usblonsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccsvchst.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech Inc.) C:\Program Files\Logitech\SetPoint II\SetPointII.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ISW] => [X]
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [USBLogon] => C:\Program Files\USBLogon\usblondetect.exe [12288 2013-10-01] (Quadsoft)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10396440 2014-04-15] (Logitech Inc.)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [73360 2011-12-18] (Check Point Software Technologies LTD)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SetPointII.lnk
ShortcutTarget: SetPointII.lnk -> C:\Program Files\Logitech\SetPoint II\SetPointII.exe (Logitech Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
BHO-x32: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coIEPlg.dll (Symantec Corporation)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKLM-x32 - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/esnlaunch,version=1.118.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Form History Control - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\formhistory@yahoo.com [2014-02-09]
FF Extension: FoxyProxy Standard - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\foxyproxy@eric.h.jung [2014-02-06]
FF Extension: Browser Backgrounds - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{3e0c7f3a-3f50-4730-beb5-4a9a10e2831c} [2013-10-19]
FF Extension: EPUBReader - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2013-12-07]
FF Extension: iMacros for Firefox - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-05-24]
FF Extension: Nightly Tester Tools - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29} [2013-11-01]
FF Extension: WOT - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26]
FF Extension: Cookies Manager+ - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2013-07-23]
FF Extension: Open With Photoshop - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{f3f219f9-cbce-467e-b8fe-6e076d29665c} [2014-04-14]
FF Extension: Cookie Importer - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\cookieimporter@krk.xpi [2012-03-03]
FF Extension: Firebug - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\firebug@software.joehewitt.com.xpi [2012-03-03]
FF Extension: gui:config - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\guiconfig@slosd.net.xpi [2012-03-03]
FF Extension: No Name - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\lessChrome.HD@prospector.labs.mozilla.xpi [2012-03-03]
FF Extension: Personas Plus - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\personas@christopher.beard.xpi [2012-03-03]
FF Extension: Test Pilot - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\testpilot@labs.mozilla.com.xpi [2012-03-03]
FF Extension: ShowIP - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}.xpi [2012-03-03]
FF Extension: Stylish - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2012-03-03]
FF Extension: Facebook New Tab - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{5e2b2bcc-767d-4077-bf8e-67d7a9861ec4}.xpi [2012-05-18]
FF Extension: MeasureIt - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{75CEEE46-9B64-46f8-94BF-54012DE155F0}.xpi [2012-03-03]
FF Extension: Tamper Data - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}.xpi [2012-03-10]
FF Extension: Password Exporter - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2012-03-03]
FF Extension: Web Developer - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2012-03-03]
FF Extension: Adblock Plus - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-03-03]
FF Extension: Pixlr Grabber - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}.xpi [2012-03-03]
FF Extension: Download Statusbar - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2012-03-03]
FF Extension: Tab Mix Plus - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2012-03-03]
FF Extension: Greasemonkey - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012-08-25]
FF Extension: HackBar - C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\yv0afey1.default\Extensions\{F5DDF39C-9293-4d5e-9AA8-E04E6DD5E9B4}.xpi [2012-05-10]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-05-09]
FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: Adobe Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012-03-03]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012-03-03]
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\IPSFF [2013-10-12]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\coFFPlgn\ []
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-02]
CHR Extension: (Google Drive) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-02]
CHR Extension: (YouTube) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-02]
CHR Extension: (Google-Suche) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-02]
CHR Extension: (Norton Identity Safe for Google Chrome™) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2013-10-02]
CHR Extension: (Google Wallet) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-02]
CHR Extension: (Google Mail) - C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-02]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\Exts\Chrome.crx [2014-02-03]
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2010-02-03] (Microsoft Corporation)
R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1315728 2013-09-02] (Binary Fortress Software)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation)
R2 IswSvc; C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe [827520 2011-11-03] (Check Point Software Technologies)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S4 MSSQL$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [206424 2012-02-11] (Microsoft Corporation)
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [191064 2012-02-11] (Microsoft Corporation)
S4 MySQL56; C:\ProgramData\MySQL\MySQL Server 5.6\my.ini [14249 2013-12-18] ()
R2 MySQL57; C:\ProgramData\MySQL\MySQL Server 5.7\my.ini [14284 2013-12-28] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccSvcHst.exe [138272 2012-06-16] (Symantec Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [99616 2014-03-05] (Overwolf LTD)
S4 SQLAgent$SQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [438360 2012-02-11] (Microsoft Corporation)
S4 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [597080 2012-02-11] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation)
R2 USBLogonService; C:\Program Files\USBLogon\usblonsvc.exe [12288 2013-10-01] ()
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-05] (Microsoft Corporation)
S2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [2420616 2011-12-18] (Check Point Software Technologies LTD)
S2 AviraUpgradeService; "C:\Windows\TEMP\AVSETUP_51f63be4\avupgsvc.exe" /TEMPSTART:""C:\Windows\TEMP\AVSETUP_51f63be4\setup.exe" /NOTEMPCLEANUP /CROSSUPGRADE"
==================== Drivers (Whitelisted) ====================
S2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\BASHDefs\20140510.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\0604010.00E\ccSetx64.sys [167072 2012-06-07] (Symantec Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [271424 2012-03-23] (DT Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-05-13] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\IPSDefs\20140526.001\IDSvia64.sys [525016 2014-04-11] (Symantec Corporation)
R2 ISWKL; C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys [33672 2011-11-03] (Check Point Software Technologies)
R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20140527.001\ENG64.SYS [126040 2014-05-13] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.0.0.145\Definitions\VirusDefs\20140527.001\EX64.SYS [2099288 2014-05-13] (Symantec Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61736 2014-02-28] (NetFilterSDK.com)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
S3 SipIMNDI; C:\Windows\System32\DRIVERS\SipIMNDI64.sys [28192 2009-10-15] (T-Systems International GmbH)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\0604010.00E\SRTSP64.SYS [737952 2012-07-06] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\0604010.00E\SRTSPX64.SYS [37536 2012-07-06] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\0604010.00E\SYMDS64.SYS [451192 2011-08-16] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\0604010.00E\SYMEFA64.SYS [1129120 2012-05-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2012-05-17] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\0604010.00E\Ironx64.SYS [190072 2011-11-16] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\0604010.00E\SYMNETS.SYS [405624 2011-11-16] (Symantec Corporation)
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2011-08-19] (The OpenVPN Project)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [454232 2011-05-07] (Check Point Software Technologies LTD)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-27 20:52 - 2014-05-27 20:52 - 00001259 _____ () C:\Users\alex\Desktop\JRT.txt
2014-05-27 20:41 - 2014-05-27 20:41 - 00000000 ____D () C:\Windows\ERUNT
2014-05-27 20:39 - 2014-05-27 20:39 - 00022950 _____ () C:\Users\alex\Desktop\AdwCleaner[S0].txt
2014-05-27 20:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-27 20:32 - 2014-05-27 20:35 - 00000000 ____D () C:\AdwCleaner
2014-05-27 20:31 - 2014-05-27 20:31 - 00027209 _____ () C:\Users\alex\Desktop\VerlaufMBAM.txt
2014-05-27 20:03 - 2014-05-27 20:40 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-27 20:02 - 2014-05-27 20:02 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-27 20:02 - 2014-05-27 20:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-27 20:02 - 2014-05-27 20:02 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-27 20:02 - 2014-05-27 20:02 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-27 20:02 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-27 20:02 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-27 20:02 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-26 23:44 - 2014-05-26 23:44 - 00030131 _____ () C:\ComboFix.txt
2014-05-26 23:16 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-26 23:16 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-26 23:16 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-26 23:16 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-26 23:16 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-26 23:16 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-26 23:16 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-26 23:16 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-26 23:15 - 2014-05-26 23:44 - 00000000 ____D () C:\Qoobox
2014-05-26 23:14 - 2014-05-26 23:42 - 00000000 ____D () C:\Windows\erdnt
2014-05-26 23:14 - 2014-05-26 23:14 - 05200919 ____R (Swearware) C:\Users\alex\Downloads\ComboFix.exe
2014-05-26 22:58 - 2014-05-26 22:58 - 00001264 _____ () C:\Users\alex\Desktop\Revo Uninstaller.lnk
2014-05-26 22:58 - 2014-05-26 22:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-26 09:55 - 2014-05-26 09:55 - 01016261 _____ (Thisisu) C:\Users\alex\Downloads\JRT.exe
2014-05-26 09:54 - 2014-05-26 09:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\alex\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-26 09:54 - 2014-05-26 09:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\alex\Downloads\revosetup95.exe
2014-05-26 09:54 - 2014-05-26 09:54 - 01327971 _____ () C:\Users\alex\Downloads\adwcleaner_3.211.exe
2014-05-26 09:47 - 2014-05-27 20:01 - 00084362 _____ () C:\Users\alex\Downloads\Addition.txt
2014-05-26 09:46 - 2014-05-27 20:53 - 00025612 _____ () C:\Users\alex\Downloads\FRST.txt
2014-05-26 09:46 - 2014-05-27 20:53 - 00000000 ____D () C:\FRST
2014-05-26 09:45 - 2014-05-26 09:45 - 02066944 _____ (Farbar) C:\Users\alex\Downloads\FRST64.exe
2014-05-25 19:35 - 2011-02-15 16:56 - 00000000 ____D () C:\Users\alex\Downloads\So.spielt.das.Leben.German.720p.BluRay.x264.REPACK-DECENT
2014-05-25 19:18 - 2014-05-25 19:19 - 00000000 ____D () C:\Users\alex\Downloads\App.2013.German.1080p.BluRay.x264-iFPD
2014-05-25 19:18 - 2014-05-25 19:18 - 01940221 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part10.rar
2014-05-25 19:17 - 2014-05-25 19:34 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part09.rar
2014-05-25 19:17 - 2014-05-25 19:34 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part08.rar
2014-05-25 19:16 - 2014-05-25 19:35 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part05.rar
2014-05-25 19:16 - 2014-05-25 19:34 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part04.rar
2014-05-25 19:16 - 2014-05-25 19:34 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part07.rar
2014-05-25 19:16 - 2014-05-25 19:34 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part06.rar
2014-05-25 19:15 - 2014-05-25 19:34 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part03.rar
2014-05-25 19:15 - 2014-05-25 19:34 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part01.rar
2014-05-25 19:15 - 2014-05-25 19:32 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part02.rar
2014-05-25 19:14 - 2014-05-25 19:18 - 92638531 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part21.rar
2014-05-25 19:13 - 2014-05-25 19:17 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part20.rar
2014-05-25 19:12 - 2014-05-25 19:17 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part18.rar
2014-05-25 19:12 - 2014-05-25 19:16 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part19.rar
2014-05-25 19:12 - 2014-05-25 19:16 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part16.rar
2014-05-25 19:12 - 2014-05-25 19:16 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part15.rar
2014-05-25 19:12 - 2014-05-25 19:15 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part17.rar
2014-05-25 19:11 - 2014-05-25 19:15 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part14.rar
2014-05-25 19:11 - 2014-05-25 19:15 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part13.rar
2014-05-25 19:11 - 2014-05-25 19:15 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part12.rar
2014-05-25 19:11 - 2014-05-25 19:14 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part11.rar
2014-05-25 19:07 - 2014-05-25 19:13 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part02.rar
2014-05-25 19:07 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part09.rar
2014-05-25 19:07 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part07.rar
2014-05-25 19:07 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part04.rar
2014-05-25 19:07 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part03.rar
2014-05-25 19:07 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part10.rar
2014-05-25 19:07 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part08.rar
2014-05-25 19:07 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part06.rar
2014-05-25 19:07 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part05.rar
2014-05-25 19:07 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part01.rar
2014-05-21 11:27 - 2014-05-21 11:27 - 00262144 ____N () C:\Windows\Minidump\052114-40451-01.dmp
2014-05-19 00:21 - 2014-05-19 00:21 - 57961276 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(3D)(720p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 55187202 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(720p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 17244386 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(3D)(360p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 16751837 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(3D)(360p_VP8-Vorbis).webm
2014-05-19 00:21 - 2014-05-19 00:21 - 16640994 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(360p_VP8-Vorbis).webm
2014-05-19 00:21 - 2014-05-19 00:21 - 13878372 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(360p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 07132731 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(240p_H.263-MP3).flv
2014-05-19 00:21 - 2014-05-19 00:21 - 04403879 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(240p_H.264-AAC).3gp
2014-05-19 00:21 - 2014-05-19 00:21 - 01568770 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(144p_H.264-AAC).3gp
2014-05-18 17:36 - 2014-05-18 17:36 - 00002026 _____ () C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2014-05-17 22:48 - 2013-08-18 22:42 - 00000226 _____ () C:\Users\alex\Downloads\Installation.txt
2014-05-17 22:48 - 2013-08-18 22:41 - 00000000 ____D () C:\Users\alex\Downloads\App
2014-05-17 20:12 - 2014-05-17 20:13 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
2014-05-17 20:07 - 2014-05-17 20:07 - 62122112 _____ (Logitech Inc.) C:\Users\alex\Downloads\LGS_8.53.154_x64_Logitech(1).exe
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Users\alex\Downloads\g19_VLC-200-i686-plugin
2014-05-17 14:17 - 2014-05-17 14:17 - 00049451 _____ () C:\Users\alex\Downloads\g19_VLC-200-i686-plugin.7z
2014-05-17 13:55 - 2014-03-15 11:54 - 00079880 _____ () C:\Users\alex\Downloads\LogiLCD32.zip
2014-05-17 13:55 - 2014-03-15 11:54 - 00069014 _____ () C:\Users\alex\Downloads\LogiLCD64.zip
2014-05-17 13:33 - 2014-05-17 20:13 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2014-05-17 13:33 - 2014-05-17 20:13 - 00001164 _____ () C:\Windows\LkmdfCoInst.log
2014-05-17 13:33 - 2014-05-17 13:33 - 00000000 ____D () C:\Users\alex\AppData\Local\Logitech
2014-05-17 13:29 - 2014-05-17 13:29 - 00000000 ____D () C:\Users\alex\AppData\Roaming\Logitech
2014-05-17 13:29 - 2014-05-17 13:29 - 00000000 ____D () C:\Users\alex\AppData\Roaming\Logishrd
2014-05-17 13:28 - 2014-05-17 13:29 - 62122112 _____ (Logitech Inc.) C:\Users\alex\Downloads\LGS_8.53.154_x64_Logitech.exe
2014-05-13 12:30 - 2012-12-28 10:26 - 00000000 ____D () C:\Users\alex\Downloads\mp3dioef
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part09.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part08.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part07.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part06.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part05.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part04.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part03.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part02.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part01.rar
2014-05-13 12:23 - 2014-05-13 12:30 - 186434075 _____ () C:\Users\alex\Downloads\mp3dioef.part10.rar
2014-05-13 12:05 - 2013-10-29 23:35 - 00000000 ____D () C:\Users\alex\Downloads\BMW.Navigation.DVD.Road.Map.Europe.PROFESSIONAL.2014.Blitzer.Edition.DVD2
2014-05-13 12:00 - 2014-05-13 12:02 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part36.rar
2014-05-13 12:00 - 2014-05-13 12:02 - 108266536 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part37.rar
2014-05-13 11:59 - 2014-05-13 12:02 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part35.rar
2014-05-13 11:58 - 2014-05-13 12:02 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part34.rar
2014-05-13 11:58 - 2014-05-13 12:02 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part33.rar
2014-05-13 11:58 - 2014-05-13 12:02 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part31.rar
2014-05-13 11:58 - 2014-05-13 12:01 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part32.rar
2014-05-13 11:57 - 2014-05-13 12:01 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part30.rar
2014-05-13 11:56 - 2014-05-13 12:00 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part29.rar
2014-05-13 11:55 - 2014-05-13 12:01 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part28.rar
2014-05-13 11:55 - 2014-05-13 12:00 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part26.rar
2014-05-13 11:55 - 2014-05-13 12:00 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part25.rar
2014-05-13 11:55 - 2014-05-13 11:59 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part27.rar
2014-05-13 11:55 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part24.rar
2014-05-13 11:54 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part23.rar
2014-05-13 11:54 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part22.rar
2014-05-13 11:54 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part21.rar
2014-05-13 11:51 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part19.rar
2014-05-13 11:51 - 2014-05-13 11:54 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part20.rar
2014-05-13 11:50 - 2014-05-13 11:57 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part18.rar
2014-05-13 11:50 - 2014-05-13 11:56 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part15.rar
2014-05-13 11:50 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part16.rar
2014-05-13 11:50 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part13.rar
2014-05-13 11:50 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part12.rar
2014-05-13 11:50 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part11.rar
2014-05-13 11:50 - 2014-05-13 11:54 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part17.rar
2014-05-13 11:50 - 2014-05-13 11:54 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part14.rar
2014-05-13 11:46 - 2014-05-13 11:51 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part10.rar
2014-05-13 11:46 - 2014-05-13 11:51 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part05.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part09.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part08.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part07.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part06.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part04.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part03.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part02.rar
2014-05-13 11:46 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part01.rar
2014-05-10 16:02 - 2014-05-10 16:02 - 00000000 ____D () C:\Users\alex\Documents\StreamTransport
2014-05-10 14:02 - 2014-05-10 16:02 - 720968130 _____ () C:\Users\alex\Documents\livestream2.flv
2014-05-10 14:01 - 2014-05-10 14:01 - 00001091 _____ () C:\Users\Public\Desktop\StreamTransport.lnk
2014-05-10 14:01 - 2014-05-10 14:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamTransport
2014-05-10 14:01 - 2014-05-10 14:01 - 00000000 ____D () C:\Program Files (x86)\StreamTransport
2014-05-10 14:00 - 2014-05-10 14:00 - 16038592 _____ () C:\Users\alex\Downloads\Streamtransport_1.1.4.0.zip
2014-05-10 13:55 - 2014-05-10 13:55 - 00629584 _____ (Chip Digital GmbH) C:\Users\alex\Downloads\StreamTransport - CHIP-Downloader.exe
2014-05-10 13:50 - 2014-05-10 13:50 - 00629584 _____ (Chip Digital GmbH) C:\Users\alex\Downloads\Screen Recorder - CHIP-Downloader.exe
2014-05-10 13:23 - 2014-05-10 13:23 - 00629584 _____ (Chip Digital GmbH) C:\Users\alex\Downloads\Game Cam - CHIP-Downloader.exe
2014-05-10 13:16 - 2014-05-27 20:25 - 00000000 ____D () C:\Program Files\004
2014-05-09 21:46 - 2014-05-27 20:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-28 22:55 - 2014-05-20 15:10 - 00000000 ____D () C:\Users\alex\AppData\Local\Purplizer
==================== One Month Modified Files and Folders =======
2014-05-27 20:53 - 2014-05-26 09:46 - 00025612 _____ () C:\Users\alex\Downloads\FRST.txt
2014-05-27 20:53 - 2014-05-26 09:46 - 00000000 ____D () C:\FRST
2014-05-27 20:52 - 2014-05-27 20:52 - 00001259 _____ () C:\Users\alex\Desktop\JRT.txt
2014-05-27 20:46 - 2013-10-02 08:15 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-27 20:45 - 2009-07-14 06:45 - 00012960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-27 20:45 - 2009-07-14 06:45 - 00012960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-27 20:44 - 2009-07-14 19:58 - 00918084 _____ () C:\Windows\system32\perfh007.dat
2014-05-27 20:44 - 2009-07-14 19:58 - 00220550 _____ () C:\Windows\system32\perfc007.dat
2014-05-27 20:44 - 2009-07-14 07:13 - 02170582 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-27 20:42 - 2012-03-03 22:10 - 01308974 _____ () C:\Windows\WindowsUpdate.log
2014-05-27 20:41 - 2014-05-27 20:41 - 00000000 ____D () C:\Windows\ERUNT
2014-05-27 20:40 - 2014-05-27 20:03 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-27 20:39 - 2014-05-27 20:39 - 00022950 _____ () C:\Users\alex\Desktop\AdwCleaner[S0].txt
2014-05-27 20:39 - 2013-10-02 08:15 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-27 20:38 - 2014-02-13 10:51 - 00000000 ____D () C:\ProgramData\USBLogon
2014-05-27 20:37 - 2012-03-03 22:24 - 01287894 _____ () C:\Windows\PFRO.log
2014-05-27 20:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-27 20:37 - 2009-07-14 06:51 - 00067143 _____ () C:\Windows\setupact.log
2014-05-27 20:35 - 2014-05-27 20:32 - 00000000 ____D () C:\AdwCleaner
2014-05-27 20:35 - 2014-05-09 21:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-27 20:35 - 2012-03-03 22:16 - 00000000 ____D () C:\Users\alex
2014-05-27 20:31 - 2014-05-27 20:31 - 00027209 _____ () C:\Users\alex\Desktop\VerlaufMBAM.txt
2014-05-27 20:27 - 2014-02-21 09:53 - 00000000 ____D () C:\Users\alex\AppData\Local\TSVNCache
2014-05-27 20:25 - 2014-05-10 13:16 - 00000000 ____D () C:\Program Files\004
2014-05-27 20:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Globalization
2014-05-27 20:22 - 2012-08-04 21:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-27 20:02 - 2014-05-27 20:02 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-27 20:02 - 2014-05-27 20:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-27 20:02 - 2014-05-27 20:02 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-27 20:02 - 2014-05-27 20:02 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-27 20:01 - 2014-05-26 09:47 - 00084362 _____ () C:\Users\alex\Downloads\Addition.txt
2014-05-26 23:44 - 2014-05-26 23:44 - 00030131 _____ () C:\ComboFix.txt
2014-05-26 23:44 - 2014-05-26 23:15 - 00000000 ____D () C:\Qoobox
2014-05-26 23:44 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-05-26 23:42 - 2014-05-26 23:14 - 00000000 ____D () C:\Windows\erdnt
2014-05-26 23:37 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-26 23:33 - 2009-07-14 04:34 - 19660800 _____ () C:\Windows\system32\config\system.bak
2014-05-26 23:33 - 2009-07-14 04:34 - 153878528 _____ () C:\Windows\system32\config\software.bak
2014-05-26 23:33 - 2009-07-14 04:34 - 09175040 _____ () C:\Windows\system32\config\default.bak
2014-05-26 23:33 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-05-26 23:33 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-05-26 23:14 - 2014-05-26 23:14 - 05200919 ____R (Swearware) C:\Users\alex\Downloads\ComboFix.exe
2014-05-26 22:58 - 2014-05-26 22:58 - 00001264 _____ () C:\Users\alex\Desktop\Revo Uninstaller.lnk
2014-05-26 22:58 - 2014-05-26 22:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-26 09:55 - 2014-05-26 09:55 - 01016261 _____ (Thisisu) C:\Users\alex\Downloads\JRT.exe
2014-05-26 09:54 - 2014-05-26 09:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\alex\Downloads\mbam-setup-2.0.2.1012.exe
2014-05-26 09:54 - 2014-05-26 09:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\alex\Downloads\revosetup95.exe
2014-05-26 09:54 - 2014-05-26 09:54 - 01327971 _____ () C:\Users\alex\Downloads\adwcleaner_3.211.exe
2014-05-26 09:45 - 2014-05-26 09:45 - 02066944 _____ (Farbar) C:\Users\alex\Downloads\FRST64.exe
2014-05-26 08:52 - 2012-03-03 22:35 - 00000000 ____D () C:\Users\alex\AppData\Roaming\TS3Client
2014-05-25 19:35 - 2014-05-25 19:16 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part05.rar
2014-05-25 19:34 - 2014-05-25 19:17 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part09.rar
2014-05-25 19:34 - 2014-05-25 19:17 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part08.rar
2014-05-25 19:34 - 2014-05-25 19:16 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part04.rar
2014-05-25 19:34 - 2014-05-25 19:16 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part07.rar
2014-05-25 19:34 - 2014-05-25 19:16 - 524288003 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part06.rar
2014-05-25 19:34 - 2014-05-25 19:15 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part03.rar
2014-05-25 19:34 - 2014-05-25 19:15 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part01.rar
2014-05-25 19:32 - 2014-05-25 19:15 - 524288012 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part02.rar
2014-05-25 19:19 - 2014-05-25 19:18 - 00000000 ____D () C:\Users\alex\Downloads\App.2013.German.1080p.BluRay.x264-iFPD
2014-05-25 19:18 - 2014-05-25 19:18 - 01940221 _____ () C:\Users\alex\Downloads\sospieltdasleben.720p_rp.part10.rar
2014-05-25 19:18 - 2014-05-25 19:14 - 92638531 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part21.rar
2014-05-25 19:17 - 2014-05-25 19:13 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part20.rar
2014-05-25 19:17 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part18.rar
2014-05-25 19:16 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part19.rar
2014-05-25 19:16 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part16.rar
2014-05-25 19:16 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part15.rar
2014-05-25 19:15 - 2014-05-25 19:12 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part17.rar
2014-05-25 19:15 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part14.rar
2014-05-25 19:15 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part13.rar
2014-05-25 19:15 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part12.rar
2014-05-25 19:14 - 2014-05-25 19:11 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part11.rar
2014-05-25 19:13 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part02.rar
2014-05-25 19:12 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part09.rar
2014-05-25 19:12 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part07.rar
2014-05-25 19:12 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part04.rar
2014-05-25 19:12 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part03.rar
2014-05-25 19:11 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part10.rar
2014-05-25 19:11 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part08.rar
2014-05-25 19:11 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part06.rar
2014-05-25 19:11 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part05.rar
2014-05-25 19:11 - 2014-05-25 19:07 - 110100480 _____ () C:\Users\alex\Downloads\RGPD2M2NF816NP1A3.part01.rar
2014-05-25 19:05 - 2012-03-18 22:54 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2014-05-24 21:26 - 2012-04-15 09:35 - 00000000 ____D () C:\Program Files (x86)\Guild Wars 2
2014-05-22 03:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-21 11:28 - 2012-03-18 17:40 - 00000000 ____D () C:\Windows\Minidump
2014-05-21 11:27 - 2014-05-21 11:27 - 00262144 ____N () C:\Windows\Minidump\052114-40451-01.dmp
2014-05-20 21:20 - 2012-04-11 08:46 - 00000000 ____D () C:\Users\alex\Documents\GUILD WARS 2
2014-05-20 15:10 - 2014-04-28 22:55 - 00000000 ____D () C:\Users\alex\AppData\Local\Purplizer
2014-05-20 13:30 - 2014-01-09 09:38 - 00000000 ____D () C:\Users\alex\AppData\Roaming\Guild Wars 2
2014-05-19 13:36 - 2014-01-16 10:49 - 00000000 ____D () C:\Users\alex\AppData\Local\Overwolf
2014-05-19 13:34 - 2012-12-10 07:54 - 00000344 _____ () C:\Windows\lgfwup.ini
2014-05-19 13:34 - 2012-12-10 07:54 - 00000000 ____D () C:\Program Files (x86)\lg_fwupdate
2014-05-19 00:21 - 2014-05-19 00:21 - 57961276 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(3D)(720p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 55187202 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(720p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 17244386 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(3D)(360p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 16751837 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(3D)(360p_VP8-Vorbis).webm
2014-05-19 00:21 - 2014-05-19 00:21 - 16640994 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(360p_VP8-Vorbis).webm
2014-05-19 00:21 - 2014-05-19 00:21 - 13878372 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(360p_H.264-AAC).mp4
2014-05-19 00:21 - 2014-05-19 00:21 - 07132731 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(240p_H.263-MP3).flv
2014-05-19 00:21 - 2014-05-19 00:21 - 04403879 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(240p_H.264-AAC).3gp
2014-05-19 00:21 - 2014-05-19 00:21 - 01568770 _____ () C:\Users\alex\Downloads\Cro feat. Casper - Nie Auf (Full HD) (InOfficial Video) Lyrics(144p_H.264-AAC).3gp
2014-05-18 17:36 - 2014-05-18 17:36 - 00002026 _____ () C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2014-05-18 17:36 - 2012-03-03 23:40 - 00002465 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
2014-05-18 17:36 - 2012-03-03 23:40 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
2014-05-18 17:36 - 2012-03-03 23:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2014-05-17 23:29 - 2012-03-03 22:36 - 00000000 ____D () C:\Users\alex\AppData\Roaming\vlc
2014-05-17 20:13 - 2014-05-17 20:12 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
2014-05-17 20:13 - 2014-05-17 13:33 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2014-05-17 20:13 - 2014-05-17 13:33 - 00001164 _____ () C:\Windows\LkmdfCoInst.log
2014-05-17 20:12 - 2012-03-27 05:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-05-17 20:11 - 2012-04-18 20:23 - 00000000 ____D () C:\Users\alex\AppData\Local\CrashDumps
2014-05-17 20:07 - 2014-05-17 20:07 - 62122112 _____ (Logitech Inc.) C:\Users\alex\Downloads\LGS_8.53.154_x64_Logitech(1).exe
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Users\alex\Downloads\g19_VLC-200-i686-plugin
2014-05-17 14:17 - 2014-05-17 14:17 - 00049451 _____ () C:\Users\alex\Downloads\g19_VLC-200-i686-plugin.7z
2014-05-17 13:33 - 2014-05-17 13:33 - 00000000 ____D () C:\Users\alex\AppData\Local\Logitech
2014-05-17 13:31 - 2013-02-16 23:05 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-17 13:29 - 2014-05-17 13:29 - 00000000 ____D () C:\Users\alex\AppData\Roaming\Logitech
2014-05-17 13:29 - 2014-05-17 13:29 - 00000000 ____D () C:\Users\alex\AppData\Roaming\Logishrd
2014-05-17 13:29 - 2014-05-17 13:28 - 62122112 _____ (Logitech Inc.) C:\Users\alex\Downloads\LGS_8.53.154_x64_Logitech.exe
2014-05-14 03:22 - 2012-08-04 21:27 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 03:22 - 2012-04-06 23:01 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 03:22 - 2012-03-03 22:46 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part09.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part08.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part07.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part06.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part05.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part04.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part03.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part02.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 209715200 _____ () C:\Users\alex\Downloads\mp3dioef.part01.rar
2014-05-13 12:30 - 2014-05-13 12:23 - 186434075 _____ () C:\Users\alex\Downloads\mp3dioef.part10.rar
2014-05-13 12:02 - 2014-05-13 12:00 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part36.rar
2014-05-13 12:02 - 2014-05-13 12:00 - 108266536 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part37.rar
2014-05-13 12:02 - 2014-05-13 11:59 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part35.rar
2014-05-13 12:02 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part34.rar
2014-05-13 12:02 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part33.rar
2014-05-13 12:02 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part31.rar
2014-05-13 12:01 - 2014-05-13 11:58 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part32.rar
2014-05-13 12:01 - 2014-05-13 11:57 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part30.rar
2014-05-13 12:01 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part28.rar
2014-05-13 12:00 - 2014-05-13 11:56 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part29.rar
2014-05-13 12:00 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part26.rar
2014-05-13 12:00 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part25.rar
2014-05-13 11:59 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part27.rar
2014-05-13 11:58 - 2014-05-13 11:55 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part24.rar
2014-05-13 11:58 - 2014-05-13 11:54 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part23.rar
2014-05-13 11:58 - 2014-05-13 11:54 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part22.rar
2014-05-13 11:58 - 2014-05-13 11:54 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part21.rar
2014-05-13 11:57 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part18.rar
2014-05-13 11:56 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part15.rar
2014-05-13 11:55 - 2014-05-13 11:51 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part19.rar
2014-05-13 11:55 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part16.rar
2014-05-13 11:55 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part13.rar
2014-05-13 11:55 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part12.rar
2014-05-13 11:55 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part11.rar
2014-05-13 11:54 - 2014-05-13 11:51 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part20.rar
2014-05-13 11:54 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part17.rar
2014-05-13 11:54 - 2014-05-13 11:50 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part14.rar
2014-05-13 11:51 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part10.rar
2014-05-13 11:51 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part05.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part09.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part08.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part07.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part06.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part04.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part03.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part02.rar
2014-05-13 11:50 - 2014-05-13 11:46 - 111111111 _____ () C:\Users\alex\Downloads\BMNEU.PRO2014.BLI.DVD2.part01.rar
2014-05-12 07:26 - 2014-05-27 20:02 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-27 20:02 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-27 20:02 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-10 16:02 - 2014-05-10 16:02 - 00000000 ____D () C:\Users\alex\Documents\StreamTransport
2014-05-10 16:02 - 2014-05-10 14:02 - 720968130 _____ () C:\Users\alex\Documents\livestream2.flv
2014-05-10 14:01 - 2014-05-10 14:01 - 00001091 _____ () C:\Users\Public\Desktop\StreamTransport.lnk
2014-05-10 14:01 - 2014-05-10 14:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StreamTransport
2014-05-10 14:01 - 2014-05-10 14:01 - 00000000 ____D () C:\Program Files (x86)\StreamTransport
2014-05-10 14:00 - 2014-05-10 14:00 - 16038592 _____ () C:\Users\alex\Downloads\Streamtransport_1.1.4.0.zip
2014-05-10 13:55 - 2014-05-10 13:55 - 00629584 _____ (Chip Digital GmbH) C:\Users\alex\Downloads\StreamTransport - CHIP-Downloader.exe
2014-05-10 13:50 - 2014-05-10 13:50 - 00629584 _____ (Chip Digital GmbH) C:\Users\alex\Downloads\Screen Recorder - CHIP-Downloader.exe
2014-05-10 13:31 - 2014-03-13 12:18 - 00000000 ____D () C:\Users\MSSQLSERVER
2014-05-10 13:30 - 2012-05-06 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-10 13:23 - 2014-05-10 13:23 - 00629584 _____ (Chip Digital GmbH) C:\Users\alex\Downloads\Game Cam - CHIP-Downloader.exe
2014-05-09 19:40 - 2013-09-09 07:38 - 00000000 ____D () C:\Users\alex\Downloads\Musik
2014-05-08 11:41 - 2013-10-02 08:15 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-08 11:41 - 2013-10-02 08:15 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-02 20:51 - 2012-03-03 22:42 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-04-28 22:54 - 2014-01-16 10:50 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2014-04-27 10:00 - 2012-03-03 22:27 - 00000000 ____D () C:\Users\alex\AppData\Local\Adobe
ZeroAccess:
C:\Users\alex\AppData\Local\47dfe15c
C:\Users\alex\AppData\Local\47dfe15c\@
Some content of TEMP:
====================
C:\Users\alex\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-19 14:02
==================== End Of Log ============================ --- --- ---
--- --- --- |