![]() |
srptm funktioniert nicht mehr Hallo Leute ich bin neu im Forum und habe echt ein großes und sehr nerviges Problem und zwar wenn ich auf meinem Benutzer bekomme ich andauernd auf meinem Screen an ein Tab in dem drin steht srptm funktioniert nicht mehr und es ist echt sowas von nervig da es jede Sekunden auf meinem Screen erscheint.Ich würde mich auf Rückantwort freuen euer Sandro. Hier noch ein Screenshot wie es aussieht: hxxp://prntscr.com/4ax4oz |
:hallo: Mein Name ist Sandra und ich werde Dir bei Deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und bei einem Befall durch Malware immer der sicherste Weg. Adware lässt sich in den allermeisten Fällen problemlos entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Posten in Code Tags Bitte füge die Logs immer in Code-Tags ein. Wenn Du das nicht machst, erschwert es mir sehr das Auswerten. Danke. Dazu:
Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Logfiles [CODE][HiJackthis Logfile: Code: Logfile of Trend Micro HijackThis v2.0.4 /CODE] |
:wtf: Das ist ein HJT Log.... lies bitte nochmal meinen ersten Schritt :) |
FRST.txt an result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-08-2014 Ran by Melori Bigvava (administrator) on MELORI-PC on 08-08-2014 23:50:40 Running from C:\Users\Melori Bigvava\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\Program Files (x86)\LPT\srpts.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Sony Computer Entertainment Inc.) C:\Program Files (x86)\SCE\Common\File System Driver\bin\pfs_mounter.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe () C:\Program Files (x86)\LPT\srptsl.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Pokki) C:\Users\Melori Bigvava\AppData\Local\Pokki\Engine\pokki.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe (Skillbrains) C:\Users\Melori Bigvava\AppData\Local\Skillbrains\lightshot\5.1.3.0\Lightshot.exe (Smartbar) C:\Users\Melori Bigvava\AppData\Local\Smartbar\Application\Smartbar.exe (BitTorrent Inc.) C:\Users\Melori Bigvava\AppData\Roaming\uTorrent\uTorrent.exe (CyberGhost S.R.L.) C:\Program Files\CyberGhost 5\CyberGhost.exe () C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe (CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Aztec Media Inc) C:\Program Files (x86)\Settings Manager\systemk\systemku.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Pokki) C:\Users\Melori Bigvava\AppData\Local\Pokki\Engine\pokki.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\msconfig.exe () C:\Users\Melori Bigvava\Downloads\adwcleaner_3.304.exe () C:\Users\Melori Bigvava\AppData\Local\Smartbar\Application\Lrcnta.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Trend Micro Inc.) C:\Users\Melori Bigvava\Downloads\HiJackThis204 (1).exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6561384 2010-12-14] (Realtek Semiconductor) HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [608112 2011-03-29] (Alps Electric Co., Ltd.) HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation) HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2780776 2011-07-19] (CANON INC.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [439440 2011-09-27] (CANON INC.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe [559616 2011-10-10] (Dell) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21441152 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21441152 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [Facebook Update] => C:\Users\Melori Bigvava\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-21] (Facebook Inc.) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [LightShot] => C:\Users\Melori Bigvava\AppData\Local\Skillbrains\lightshot\Lightshot.exe [226592 2014-03-12] () HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [Browser Infrastructure Helper] => C:\Users\Melori Bigvava\AppData\Local\Smartbar\Application\Smartbar.exe [28952 2014-06-11] (Smartbar) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [uTorrent] => C:\Users\Melori Bigvava\AppData\Roaming\uTorrent\uTorrent.exe [1940560 2014-08-04] (BitTorrent Inc.) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [BRS] => C:\Program Files (x86)\WSE_Astromenda\BRS\brs.exe [1173504 2014-08-08] () HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\RunOnce: [Application Restart #2] => C:\Users\Melori Bigvava\AppData\Local\Pokki\Engine\pokki.exe [8252744 2013-11-01] (Pokki) HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Sandrtropez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-687521651-2007251113-3307527875-1004\User: Group Policy restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-687521651-2007251113-3307527875-1000\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: http=;ftp=;https=; HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8Gm8U-j3vncAmome-0puignRF83UyZ72jwm5RS-xt52-I5RlTFdjbbQA3aYnfED1UjICWo10sVRPrSJ76sn8SvRwaNPJboUQ,,&q={searchTerms} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://astromenda.com/?f=1&a=ast_aw_14_49_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzyyDtCtN1L2XzutAtFtDtFtCtDtFtBtN1L1Czu0S0P0D0YtN1L1G1B1V1N2Y1L1Qzu 2StAyDyC0BtAyEyEtBtGtCtDtA0CtGyDyB0CyCtGtAtCyB0DtGtDtDyCtCyE0A0Azzzz0ByDtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0CtCzytGzztBzy0EtGyDzz0AyEtG0ByDzz0EtGtB 0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=2027640209&ir= HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8Gm8U-j3vncAmome-0puignRF83UyZ72jwm5RS-xt52-I5RlTFdjbbQA3aYnfED1UjICWo10sVRPrSJ76sn8SvRwaNPJboUQ,,&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = SearchScopes: HKLM - {31090377-0740-419E-BEFC-A56E50500D5B} URL = hxxp://speedial.com/results.php?f=4&q={searchTerms}&a=spd_frg_14_23_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzzzzyBtN1L2XzutBtFtBtDtFtCzytFtDtN1L1C zutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StD0DzzyB0AyD0F0CtGzytByEtDtGtA0D0AtBtGzy0D0E0EtGtA0F0FyEtCtC0CtByByCtDtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0C tCzytGzztBzy0EtGyDzz0AyEtG0ByDzz0EtGtB0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=1993955427&ir= SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=113&itype=a&ver=13337&tm=402&src=ds&p={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8Gm8U-j3vncAmome-0puignRF83UyZ72jwm5RS-xt52-I5RlTFdjbbQA3aYnfED1UjICWo10sVRPrSJ76sn8SvRwaNPJboUQ,,&q={searchTerms} SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8Gm8U-j3vncAmome-0puignRF83UyZ72jwm5RS-xt52-I5RlTFdjbbQA3aYnfED1UjICWo10sVRPrSJ76sn8SvRwaNPJboUQ,,&q={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_aw_14_49_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzyyDtCtN1L2XzutAtFtDtFtCtDtFtBtN1L1Czu0 S0P0D0YtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0BtAyEyEtBtGtCtDtA0CtGyDyB0CyCtGtAtCyB0DtGtDtDyCtCyE0A0Azzzz0ByDtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0CtCzytGzztBz y0EtGyDzz0AyEtG0ByDzz0EtGtB0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=2027640209&ir= SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_aw_14_49_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzyyDtCtN1L2XzutAtFtDtFtCtDtFtBtN1L1Czu0 S0P0D0YtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0BtAyEyEtBtGtCtDtA0CtGyDyB0CyCtGtAtCyB0DtGtDtDyCtCyE0A0Azzzz0ByDtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0CtCzytGzztBz y0EtGyDzz0AyEtG0ByDzz0EtGtB0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=2027640209&ir= SearchScopes: HKCU - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8Gm8U-j3vncAmome-0puignRF83UyZ72jwm5RS-xt52-I5RlTFdjbbQA3aYnfED1UjICWo10sVRPrSJ76sn8SvRwaNPJboUQ,,&q={searchTerms} BHO: Yahoo Community Smartbar (by Linkury)Engine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: FRITZ!Box Addon BHO -> {C0C86BBE-9509-4296-8459-FDBFDAF4B673} -> C:\Program Files\FRITZ!Box\AddOn (IE)\FBoxIESplitButton.dll (AVM Berlin) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Yahoo Community Smartbar (by Linkury)Engine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Toolbar: HKLM-x32 - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Melori Bigvava\AppData\Roaming\Mozilla\Firefox\Profiles\70or7u3n.default FF NewTab: hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8MjsMRCzvPbiYAd9YbvI-PvEM5NR86MZMyA_Jc7BOyBkGlYLCiGx9LJ5ZPjRpqdFy5lQ1x4yCBA96KiKZICIGUHQsRTHmh3Q,, FF DefaultSearchEngine: FileConverter 1.3 Customized Web Search FF SearchEngineOrder.1: default-search.net FF SelectedSearchEngine: Astromenda FF Homepage: hxxp://astromenda.com/?f=1&a=ast_aw_14_49_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzyyDtCtN1L2XzutAtFtDtFtCtDtFtBtN1L1Czu0S0P0D0YtN1L1G1B1V1N2Y1L1Qzu 2StAyDyC0BtAyEyEtBtGtCtDtA0CtGyDyB0CyCtGtAtCyB0DtGtDtDyCtCyE0A0Azzzz0ByDtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0CtCzytGzztBzy0EtGyDzz0AyEtG0ByDzz0EtGtB 0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=2027640209&ir= FF Keyword.URL: hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb4GbRQI3s_sBdiUigfZ0fesrPPHX5sZ3yqY9zoqP4su4pA46Ll6Ax0ar4vVkxphN8Gm8U-j3vncAmome-0puignRF83UyZ72jwm5RS-xt52-I5RlTFdjbbQA3aYnfED1UjICWo10sVRPrSJ76sn8SvRwaNPJboUQ,,&q= FF NetworkProxy: "ftp", "212.26.2.90" FF NetworkProxy: "ftp_port", 80 FF NetworkProxy: "http", "212.26.2.90" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "212.26.2.90" FF NetworkProxy: "socks_port", 80 FF NetworkProxy: "ssl", "212.26.2.90" FF NetworkProxy: "ssl_port", 80 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @protectdisc.com/NPPDLicenseHelper -> C:\Program Files (x86)\ProtectDisc\License Helper\NPPDLicenseHelper.dll () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.updatepm.com/PriceMeterLiveUpdate Update;version=3 -> C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin-x32: @tools.updatepm.com/PriceMeterLiveUpdate Update;version=9 -> C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll No File FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Melori Bigvava\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPPDLicenseHelper.dll () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Users\Melori Bigvava\AppData\Roaming\Mozilla\Firefox\Profiles\70or7u3n.default\searchplugins\Astromenda.xml FF SearchPlugin: C:\Users\Melori Bigvava\AppData\Roaming\Mozilla\Firefox\Profiles\70or7u3n.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@OKitSpace.es] - C:\Users\Gast\AppData\Roaming\okitSpace\Firefox FF StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR HomePage: hxxp://astromenda.com/?f=1&a=ast_aw_14_49_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzyyDtCtN1L2XzutAtFtDtFtCtDtFtBtN1L1Czu0S0P0D0YtN1L1G1B1V1N2Y1L1Qzu 2StAyDyC0BtAyEyEtBtGtCtDtA0CtGyDyB0CyCtGtAtCyB0DtGtDtDyCtCyE0A0Azzzz0ByDtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0CtCzytGzztBzy0EtGyDzz0AyEtG0ByDzz0EtGtB 0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=2027640209&ir= CHR StartupUrls: "hxxp://astromenda.com/?f=7&a=ast_aw_14_49_ch&cd=2XzuyEtN2Y1L1Qzu0B0CyByBtAyBzzzytByD0DyByBtCyCzztN0D0Tzu0SzyyDtCtN1L2XzutAtFtDtFtCtDtFtBtN1L1Czu0S0P0D0YtN1L1G1B1V1N2Y1L1Qzu 2StAyDyC0BtAyEyEtBtGtCtDtA0CtGyDyB0CyCtGtAtCyB0DtGtDtDyCtCyE0A0Azzzz0ByDtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0A0EyD0F0CtCzytGzztBzy0EtGyDzz0AyEtG0ByDzz0EtGtB 0ByD0A0BtCtDtDyDtDtC0B2QtN1B1L1H1Ezu1O2U1M1B&cr=2027640209&ir=" CHR DefaultSearchKeyword: default-search.net CHR DefaultSearchProvider: default-search.net CHR DefaultSearchURL: hxxp://www.default-search.net/search?sid=476&aid=113&itype=a&ver=13337&tm=402&src=ds&p={searchTerms} CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\Melori Bigvava\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-21] CHR Extension: (Google Drive) - C:\Users\Melori Bigvava\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-26] CHR Extension: (YouTube) - C:\Users\Melori Bigvava\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-26] CHR Extension: (Google-Suche) - C:\Users\Melori Bigvava\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-26] CHR Extension: (Google Wallet) - C:\Users\Melori Bigvava\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-21] CHR Extension: (Google Mail) - C:\Users\Melori Bigvava\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-26] CHR HKLM-x32\...\Chrome\Extension: [clbfjfbnelcflpgpklppgplejolacbej] - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx [2012-11-26] CHR HKLM-x32\...\Chrome\Extension: [lbidgdoiglndbjlcnnifemecdhnpeabo] - C:\Users\Gast\AppData\Roaming\okitSpace\Chrome\OKitSpace.crx [2012-11-26] CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx [2012-11-26] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [901184 2010-12-14] (Intel Corporation) [File not signed] R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-12-14] (Intel Corporation) [File not signed] R2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [974912 2010-12-14] (Intel Corporation) [File not signed] R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L) R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [33560 2014-06-11] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] () R2 SCEFSMounter; C:\Program Files (x86)\SCE\Common\File System Driver\bin\pfs_mounter.exe [79872 2012-06-20] (Sony Computer Entertainment Inc.) [File not signed] S2 SearchAnonymizer; C:\Users\Melori\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [40960 2012-03-04] () [File not signed] R2 SystemkService; C:\Program Files (x86)\Settings Manager\systemk\SystemkService.exe [3572240 2014-07-09] (Aztec Media Inc) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2138936 2014-03-20] (TuneUp Software) S2 be0fb33b; "C:\Windows\system32\rundll32.exe" "c:\progra~2\suppor~1\SupporterSvc.dll",service ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 F06DEFF2-5B9C-490D-910F-35D3A91196222; C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc2.cfg [41872 2014-07-09] (Aztec Media Inc) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [615728 2012-03-28] (Kaspersky Lab) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [300320 2013-12-18] (NVIDIA Corporation) R1 pfs_dokan; C:\Windows\System32\DRIVERS\pfs_dokan.sys [56496 2012-06-20] (Sony Computer Entertainment Inc.) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-02-10] (TuneUp Software) S3 CtClsFlt; system32\DRIVERS\CtClsFlt.sys [X] S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-08 23:46 - 2014-08-08 23:46 - 00388608 _____ (Trend Micro Inc.) C:\Users\Melori Bigvava\Downloads\HiJackThis204 (1).exe 2014-08-08 23:46 - 2014-08-08 23:46 - 00017074 _____ () C:\Users\Melori Bigvava\Downloads\hijackthis.log 2014-08-08 23:45 - 2014-08-08 23:45 - 00388608 _____ (Trend Micro Inc.) C:\Users\Melori Bigvava\Downloads\HiJackThis204.exe 2014-08-08 23:27 - 2014-08-08 23:28 - 00147520 _____ () C:\Users\Melori Bigvava\Downloads\Addition.txt 2014-08-08 23:23 - 2014-08-08 23:51 - 00030909 _____ () C:\Users\Melori Bigvava\Downloads\FRST.txt 2014-08-08 23:22 - 2014-08-08 23:50 - 00000000 ____D () C:\FRST 2014-08-08 23:22 - 2014-08-08 23:22 - 02094080 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\FRST64.exe 2014-08-08 23:21 - 2014-08-08 23:21 - 01084928 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\FRST (1).exe 2014-08-08 23:20 - 2014-08-08 23:20 - 01084928 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\Nicht bestätigt 884755.crdownload 2014-08-08 23:19 - 2014-08-08 23:20 - 01084928 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\FRST.exe 2014-08-08 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-08-08 21:58 - 2014-08-08 21:59 - 01366203 _____ () C:\Users\Melori Bigvava\Downloads\adwcleaner_3.304.exe 2014-08-08 21:49 - 2014-08-08 23:50 - 00000316 _____ () C:\Windows\Tasks\WSE_Astromenda.job 2014-08-08 21:49 - 2014-08-08 23:07 - 00000000 ____D () C:\AdwCleaner 2014-08-08 21:49 - 2014-08-08 21:50 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Melori Bigvava\Downloads\mbam-setup-2.0.2.1012 (3).exe 2014-08-08 21:49 - 2014-08-08 21:50 - 00003276 _____ () C:\Windows\System32\Tasks\WSE_Astromenda 2014-08-08 21:49 - 2014-08-08 21:49 - 01475072 _____ () C:\Users\Melori Bigvava\Downloads\adwcleaner_3.303_CB-DL-Manager [1].exe 2014-08-08 21:49 - 2014-08-08 21:49 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\WSE_Astromenda 2014-08-08 21:49 - 2014-08-08 21:49 - 00000000 ____D () C:\Program Files (x86)\WSE_Astromenda 2014-08-08 21:48 - 2014-08-08 21:48 - 00787392 _____ ( ) C:\Users\Melori Bigvava\Downloads\adwcleaner_3.303_CB-DL-Manager.exe 2014-08-08 21:42 - 2014-08-08 21:42 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-08 21:42 - 2014-08-08 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-08 21:42 - 2014-08-08 21:42 - 00000000 ____D () C:\ProgramData\Avira 2014-08-08 21:42 - 2014-08-08 21:42 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-08 21:41 - 2014-08-08 21:41 - 04431200 _____ (Avira Operations GmbH & Co. KG) C:\Users\Melori Bigvava\Downloads\avira_de_av_ws2.exe 2014-08-08 21:37 - 2014-08-08 21:37 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-08-08 21:37 - 2014-08-08 21:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-08-08 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-08 21:37 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-08 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-08 21:35 - 2014-08-08 21:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-08-08 21:34 - 2014-08-08 21:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Melori Bigvava\Downloads\mbam-setup-2.0.2.1012 (2).exe 2014-08-07 00:29 - 2014-08-07 00:29 - 00000000 ____D () C:\ProgramData\VS 2014-08-07 00:28 - 2014-08-07 00:28 - 00000000 ____D () C:\40bfc9f03b46cc6a41 2014-08-06 23:07 - 2014-08-06 23:07 - 01526490 _____ () C:\Users\Melori Bigvava\Downloads\Gta tool 1.15 anti freezer.rar 2014-08-06 22:54 - 2014-08-06 22:55 - 56663391 _____ () C:\Users\Melori Bigvava\Downloads\AllBypassEboots.rar 2014-08-06 22:54 - 2014-08-06 22:55 - 06004615 _____ (Tim Kosse) C:\Users\Melori Bigvava\Downloads\FileZilla_3.9.0.2_win32-setup.exe 2014-08-06 22:52 - 2014-08-06 22:52 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\h4MGCY7S (2) 2014-08-06 22:51 - 2014-08-06 22:51 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\h4MGCY7S (1) 2014-08-06 22:51 - 2014-08-06 22:51 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\h4MGCY7S 2014-08-06 21:46 - 2014-08-06 21:46 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\AllBypassEboots.rar.crdownload 2014-08-06 21:43 - 2014-08-06 21:46 - 23697760 _____ () C:\Users\Melori Bigvava\Downloads\DLCFullyModded.edat 2014-08-06 09:32 - 2014-08-06 09:32 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010 2014-08-06 09:32 - 2014-08-06 09:32 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010 2014-08-06 06:08 - 2014-08-06 06:08 - 00000000 __SHD () C:\found.001 2014-08-05 19:08 - 2014-08-06 05:58 - 00000000 ____D () C:\93ddace8022a23aab77f13fc 2014-08-05 11:21 - 2014-08-05 11:21 - 03233643 _____ () C:\Users\Melori Bigvava\Downloads\K&KTool (3).rar 2014-08-05 10:38 - 2014-08-06 06:31 - 00000000 ____D () C:\887c6e35b091418ace 2014-08-04 21:30 - 2014-08-04 21:30 - 00000032 _____ () C:\Users\Melori Bigvava\Desktop\Meine Id.txt 2014-08-04 17:23 - 2014-08-04 17:37 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Temporary Projects 2014-08-04 17:22 - 2014-08-04 17:23 - 00211852 _____ () C:\Users\Melori Bigvava\AppData\Local\debuggee.mdmp 2014-08-04 17:21 - 2014-08-04 17:21 - 00002158 _____ () C:\Users\Melori Bigvava\Downloads\1407183683_06_Pool.svg 2014-08-04 16:57 - 2014-08-04 16:57 - 00000278 _____ () C:\Users\Melori Bigvava\advanced_ip_scanner_MAC.bin 2014-08-04 16:30 - 2014-08-04 16:30 - 00147474 _____ () C:\Users\Melori Bigvava\Downloads\[kickass.to]ps3.watch.dogs.duplex (1).torrent 2014-08-04 16:29 - 2014-08-04 16:29 - 00000824 _____ () C:\Users\Melori Bigvava\Desktop\µTorrent.lnk 2014-08-04 16:29 - 2014-08-04 16:29 - 00000804 _____ () C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-08-04 16:28 - 2014-08-04 16:28 - 01940560 _____ (BitTorrent Inc.) C:\Users\Melori Bigvava\Downloads\uTorrent.exe 2014-08-04 16:11 - 2014-08-04 16:11 - 00147474 _____ () C:\Users\Melori Bigvava\Downloads\[kickass.to]ps3.watch.dogs.duplex.torrent 2014-08-04 15:15 - 2014-08-06 06:31 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\iMCS Productions 2014-08-04 15:15 - 2014-08-06 06:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GTA Online - Recovery Tool 2014-08-04 15:15 - 2014-08-06 06:24 - 00000000 ____D () C:\Program Files (x86)\iMCS Productions 2014-08-04 15:15 - 2014-08-04 15:15 - 00001412 _____ () C:\Users\Public\Desktop\GTA Online Recovery Tool.lnk 2014-08-04 14:19 - 2014-07-05 05:05 - 06856704 _____ (BSMT (BulletsStorm Modding Team)) C:\Users\Melori Bigvava\Desktop\K&K Tool.exe 2014-08-04 14:15 - 2014-08-04 14:15 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-08-04 14:02 - 2014-08-06 06:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced IP Scanner v2 2014-08-04 14:02 - 2014-08-06 06:31 - 00000000 ____D () C:\Program Files (x86)\Advanced IP Scanner 2014-08-04 14:02 - 2014-08-04 14:02 - 00000983 _____ () C:\Users\Public\Desktop\Advanced IP Scanner.lnk 2014-08-04 14:01 - 2014-08-04 14:01 - 06596600 _____ ( ) C:\Users\Melori Bigvava\Downloads\ipscan_2.3.2161.exe 2014-08-04 13:40 - 2014-08-06 17:07 - 00000000 ____D () C:\Users\Melori Bigvava\Desktop\Urlaubs Bilder 2014-08-04 12:26 - 2014-08-04 12:26 - 00226146 _____ () C:\Users\Melori Bigvava\Downloads\Weapon And Callsign Unlocks.txt 2014-08-04 12:20 - 2014-08-06 06:31 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 10.0 2014-08-04 12:16 - 2014-08-04 12:16 - 03296584 _____ (Microsoft Corporation) C:\Users\Melori Bigvava\Downloads\vbasic_web.exe 2014-08-04 11:29 - 2014-08-04 11:29 - 00000000 __SHD () C:\found.000 2014-08-04 10:50 - 2014-08-04 10:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-03 21:45 - 2014-08-03 21:56 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temporary Projects 2014-08-03 21:27 - 2014-08-04 10:59 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-08-03 21:27 - 2014-08-03 21:27 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-08-03 21:26 - 2014-08-03 21:29 - 00000000 ____D () C:\Users\Gast\Documents\Visual Studio 2010 2014-08-03 21:22 - 2014-08-06 06:26 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\Visual Studio 2010 2014-08-03 21:22 - 2014-08-06 06:25 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services 2014-08-03 21:22 - 2014-08-06 06:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services 2014-08-03 21:21 - 2014-08-08 21:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express 2014-08-03 21:19 - 2014-08-06 06:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0 2014-08-03 21:19 - 2014-08-06 06:25 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer 2014-08-03 21:19 - 2014-08-03 21:19 - 00000000 ____D () C:\Windows\PCHEALTH 2014-08-03 21:11 - 2014-08-05 19:05 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-03 21:00 - 2014-08-03 21:00 - 00009800 ____N () C:\bootsqm.dat 2014-07-27 20:14 - 2014-08-06 06:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-07-27 20:13 - 2014-07-27 20:13 - 05618120 _____ (Speedchecker Limited ) C:\Users\Melori Bigvava\Documents\PCSUUpdate.exe 2014-07-27 20:13 - 2014-07-27 20:13 - 00057128 _____ () C:\Users\Melori Bigvava\Documents\PCSpeedUp-Silent-Update.exe 2014-07-26 21:31 - 2014-07-26 21:31 - 00000685 _____ () C:\Users\Melori Bigvava\Desktop\Sorce Code Passwort Stealer (1).txt 2014-07-26 21:19 - 2014-07-26 21:19 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler 2014-07-26 21:19 - 2014-07-26 21:19 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-07-26 18:44 - 2014-08-06 06:32 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2014-07-26 18:44 - 2014-08-06 06:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014 2014-07-26 18:44 - 2014-07-26 18:44 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\TuneUp Software 2014-07-26 18:44 - 2014-07-26 18:44 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\TuneUp Software 2014-07-26 18:44 - 2014-03-20 14:44 - 00040760 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe 2014-07-26 18:44 - 2014-03-20 14:44 - 00029496 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll 2014-07-26 18:44 - 2014-03-20 14:44 - 00025400 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll 2014-07-26 18:43 - 2014-07-26 21:18 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-07-26 18:41 - 2014-08-06 06:32 - 00000000 ____D () C:\Program Files (x86)\LPT 2014-07-26 18:41 - 2014-07-26 18:41 - 00002694 _____ () C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-07-26 18:41 - 2014-07-26 18:41 - 00002647 _____ () C:\Users\Melori Bigvava\Desktop\Search.lnk 2014-07-26 18:39 - 2014-08-06 06:32 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\LPT 2014-07-26 18:39 - 2014-08-06 06:25 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Smartbar 2014-07-26 18:37 - 2014-08-06 06:31 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\OpenCandy 2014-07-26 18:36 - 2014-08-06 06:31 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\DVDVideoSoft 2014-07-26 18:35 - 2014-07-26 18:36 - 29527272 _____ (DVDVideoSoft Ltd. ) C:\Users\Melori Bigvava\Downloads\FreeYouTubeToMP3Converter-3.12.42.716.exe 2014-07-26 15:21 - 2014-07-26 15:22 - 05006664 _____ () C:\Users\Melori Bigvava\Downloads\Black Ops 2 Tool 1.18 2.18 Cex Dex.zip 2014-07-26 15:10 - 2014-07-26 15:11 - 04979643 _____ () C:\Users\Melori Bigvava\Downloads\Black OPS II RTM Tool - 1.17 fix.rar 2014-07-24 17:27 - 2014-08-06 06:25 - 00000000 ____D () C:\Program Files (x86)\ProtectDisc 2014-07-24 17:27 - 2014-07-24 17:27 - 00335288 _____ (Protect Software GmbH) C:\Windows\system32\Drivers\acedrv11.sys 2014-07-24 17:15 - 2014-08-06 06:31 - 00000000 ___RD () C:\Users\Melori Bigvava\Desktop\Animieter 2014-07-24 17:14 - 2014-07-24 17:14 - 00826192 _____ (Chip Digital GmbH) C:\Users\Melori Bigvava\Downloads\CorelDraw Graphics Suite X7 - CHIP-Installer.exe 2014-07-24 16:54 - 2014-07-24 16:54 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Reallusion 2014-07-24 16:50 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-07-24 16:50 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-07-24 16:50 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-07-24 16:50 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll 2014-07-24 16:50 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-07-24 16:50 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll 2014-07-24 16:50 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-07-24 16:50 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll 2014-07-24 16:34 - 2014-08-03 20:43 - 00000000 ____D () C:\Users\Public\Documents\Reallusion 2014-07-24 16:33 - 2014-08-03 20:43 - 00000000 ____D () C:\Program Files (x86)\Reallusion 2014-07-23 18:23 - 2014-07-23 18:23 - 00001488 _____ () C:\Users\Melori Bigvava\Desktop\CINEMA 4D - Verknüpfung.lnk 2014-07-23 18:04 - 2014-08-06 06:31 - 00000000 ____D () C:\Users\Melori Bigvava\Desktop\CRACKbyActivity 2014-07-23 17:53 - 2014-07-23 17:54 - 14644733 _____ () C:\Users\Melori Bigvava\Downloads\Notrens Ex Materials.rar 2014-07-23 15:18 - 2014-07-23 15:18 - 00011233 _____ () C:\Users\Melori Bigvava\Documents\Theo.odt 2014-07-21 21:05 - 2014-07-21 21:05 - 18135006 _____ () C:\Users\Melori Bigvava\Downloads\intro.mp4 2014-07-21 17:41 - 2014-07-21 17:46 - 92312238 _____ () C:\Users\Melori Bigvava\Downloads\SEN Enabler v5.3.3 [CEX] [4.55] (1).rar 2014-07-21 17:39 - 2014-07-21 17:39 - 00116352 _____ () C:\Users\Melori Bigvava\Downloads\Chaos Air Bringer.pkg 2014-07-21 17:20 - 2014-07-21 17:23 - 35035136 _____ () C:\Users\Melori Bigvava\Downloads\Psych Project Beta1.8.exe 2014-07-20 18:31 - 2014-07-20 18:31 - 00000032 _____ () C:\Users\Melori Bigvava\Desktop\shutdown -s -t 20 -c.txt 2014-07-20 00:02 - 2014-07-20 00:02 - 00001386 _____ () C:\Users\Gast\Desktop\Playstaion Codes Gratis.lnk 2014-07-19 23:57 - 2014-07-19 23:57 - 18135006 _____ () C:\Users\Gast\Downloads\intro.mp4 2014-07-19 23:40 - 2014-07-19 23:40 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\TuneUp Software 2014-07-19 23:40 - 2014-07-19 23:40 - 00000000 ____D () C:\Users\Gast\AppData\Local\TuneUp Software 2014-07-19 22:27 - 2014-07-19 22:27 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\HideIPEasy 2014-07-19 22:27 - 2014-07-19 22:27 - 00000000 ____D () C:\ProgramData\HideIPEasy 2014-07-18 19:25 - 2014-07-18 19:25 - 00001690 _____ () C:\Users\Melori Bigvava\Desktop\CyberGhost 5.lnk 2014-07-18 19:23 - 2014-07-18 19:24 - 08646824 _____ (CyberGhost S.R.L. ) C:\Users\Melori Bigvava\Downloads\CG_5.0.13.17.exe 2014-07-18 18:56 - 2014-07-18 18:56 - 00002113 _____ () C:\Users\Melori Bigvava\Desktop\FunnyVoice - CHIP Downloader.lnk 2014-07-18 18:55 - 2014-07-18 18:56 - 00042496 _____ () C:\Users\Melori Bigvava\Downloads\funny-voice_6658.exe 2014-07-18 17:08 - 2014-07-18 17:09 - 02883585 _____ () C:\Users\Melori Bigvava\Downloads\CFW Info TooL by Modz Ko.rar 2014-07-15 21:40 - 2014-07-16 20:01 - 00000000 ____D () C:\Program Files (x86)\OkayFreedom 2014-07-15 21:40 - 2014-07-16 20:00 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Steganos 2014-07-15 21:40 - 2014-07-15 21:42 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Steganos VPN 2014-07-15 21:37 - 2014-07-15 21:37 - 00001809 _____ () C:\Users\Melori Bigvava\Downloads\ProxyList-2014-07-15.tsv 2014-07-15 21:37 - 2014-07-15 21:37 - 00001809 _____ () C:\Users\Melori Bigvava\Documents\ProxyList-2014-07-15.txt 2014-07-15 21:27 - 2014-07-27 20:25 - 00000000 ____D () C:\ProgramData\EPS 2014-07-15 21:26 - 2014-07-15 21:27 - 02503091 _____ (hxxp://www.didsoft.com ) C:\Users\Melori Bigvava\Downloads\EPS_setup.exe 2014-07-15 14:03 - 2014-07-15 14:03 - 00000000 ____D () C:\ProgramData\APN 2014-07-15 14:01 - 2014-07-15 14:01 - 00000000 ____D () C:\ProgramData\Oracle 2014-07-15 14:01 - 2014-07-15 14:00 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-07-15 14:00 - 2014-07-15 14:00 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-07-15 14:00 - 2014-07-15 14:00 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-07-15 14:00 - 2014-07-15 14:00 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-07-15 14:00 - 2014-07-15 14:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-15 14:00 - 2014-07-15 14:00 - 00000000 ____D () C:\Program Files (x86)\Java 2014-07-14 18:39 - 2014-07-14 18:40 - 00000926 _____ () C:\Users\Melori Bigvava\Desktop\sandropreisliste.txt 2014-07-13 15:07 - 2014-07-13 15:07 - 00569372 _____ (DotExE ) C:\Users\Melori Bigvava\Downloads\MoonTools.exe 2014-07-13 15:07 - 2014-07-13 15:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MoonTools 2014-07-13 15:07 - 2014-07-13 15:07 - 00000000 ____D () C:\Program Files (x86)\MoonTools 2014-07-12 20:37 - 2014-07-12 20:41 - 80561348 _____ () C:\Users\Melori Bigvava\Downloads\Modmenu (2).zip 2014-07-12 16:23 - 2014-07-12 16:23 - 00000032 _____ () C:\Users\Melori Bigvava\Documents\key_ps3.dat 2014-07-12 16:11 - 2014-07-12 16:11 - 00000276 _____ () C:\Users\Melori Bigvava\Downloads\ps3key.zip 2014-07-12 15:47 - 2014-07-12 15:47 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Mael 2014-07-12 15:20 - 2014-07-12 16:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor 2014-07-12 15:20 - 2014-07-12 16:26 - 00000000 ____D () C:\Program Files (x86)\HxD 2014-07-12 15:20 - 2014-07-12 15:20 - 00874674 _____ () C:\Users\Melori Bigvava\Downloads\HxDSetupDE.zip 2014-07-12 15:12 - 2014-07-12 16:23 - 00412996 _____ () C:\Users\Melori Bigvava\Downloads\LibertyV-r47.zip 2014-07-12 15:09 - 2014-07-12 15:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex-Editor MX 2014-07-12 15:09 - 2014-07-12 15:10 - 00000000 ____D () C:\Program Files (x86)\Hex-Editor MX 2014-07-12 15:08 - 2014-07-12 15:08 - 00860736 _____ () C:\Users\Melori Bigvava\Downloads\hexedit602.zip 2014-07-12 15:08 - 2014-07-12 15:08 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\DesktopIconAmazon 2014-07-12 15:07 - 2014-07-12 15:07 - 00961360 _____ (Chip Digital GmbH) C:\Users\Melori Bigvava\Downloads\Hex Editor MX - CHIP-Installer.exe 2014-07-12 13:56 - 2014-07-12 13:57 - 00266398 _____ () C:\Users\Melori Bigvava\Downloads\DHL.apk 2014-07-12 13:50 - 2014-08-08 23:51 - 00000000 ____D () C:\ProgramData\systemk 2014-07-12 13:50 - 2014-07-12 13:50 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Settings Manager 2014-07-11 20:02 - 2014-07-11 20:02 - 00780824 _____ (Elex do Brasil Participações Ltda) C:\Users\Melori Bigvava\Downloads\yet_another_cleaner_brob.exe 2014-07-11 13:42 - 2014-07-11 13:42 - 02427689 _____ () C:\Users\Melori Bigvava\Downloads\Mohanads Tool (1).rar 2014-07-11 13:38 - 2014-07-11 13:38 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Melori Bigvava\Downloads\mbam-setup-2.0.2.1012 (1).exe 2014-07-11 12:28 - 2014-07-11 12:29 - 01311951 _____ () C:\Users\Melori Bigvava\Downloads\Youbooster Pro Edition Updated.exe 2014-07-11 12:21 - 2014-07-11 12:21 - 00300586 _____ () C:\Users\Melori Bigvava\Downloads\Yotubube bot.zip 2014-07-10 17:41 - 2014-08-06 23:00 - 314306560 _____ () C:\Users\Melori Bigvava\Downloads\update.rpf 2014-07-10 17:41 - 2014-07-26 17:37 - 66311680 _____ () C:\Users\Melori Bigvava\Downloads\updateletze.rpf 2014-07-10 17:41 - 2014-07-19 18:34 - 66312704 _____ () C:\Users\Melori Bigvava\Downloads\update.rpf1 2014-07-10 17:41 - 2014-07-10 17:44 - 66003968 _____ () C:\Users\Melori Bigvava\Downloads\update.2rpf 2014-07-10 17:21 - 2014-07-10 17:21 - 00002016 _____ () C:\Users\Melori Bigvava\Downloads\C# WFApplication (For RTM).txt 2014-07-09 20:48 - 2014-07-09 20:53 - 105891762 _____ () C:\Users\Melori Bigvava\Downloads\MOD NO LIMIT V3 BY FRENCH TOUCH (CEX).rar 2014-07-09 20:17 - 2014-07-09 20:17 - 00005120 _____ () C:\Users\Melori Bigvava\Desktop\PS3LOGO.DAT 2014-07-09 19:46 - 2014-07-09 19:46 - 00001127 _____ () C:\Users\Public\Desktop\ControlConsole API.lnk 2014-07-09 19:46 - 2014-07-09 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ControlConsole API 2014-07-09 19:46 - 2014-07-09 19:46 - 00000000 ____D () C:\Program Files (x86)\ControlConsoleAPI 2014-07-09 19:40 - 2014-07-09 19:41 - 06040056 _____ () C:\Users\Melori Bigvava\Downloads\CcApi_package_2.50 (3).rar 2014-07-09 16:47 - 2014-07-09 16:47 - 00021215 _____ () C:\Users\Melori Bigvava\Downloads\vca122.zip 2014-07-09 16:35 - 2014-07-09 16:35 - 00509952 _____ () C:\Users\Melori Bigvava\Downloads\GUI Booter (2).exe 2014-07-09 16:35 - 2014-07-09 16:35 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Gui Booter 2014-07-09 15:04 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-09 15:04 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-09 15:04 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 15:04 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-09 15:04 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 15:04 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 15:04 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-09 15:04 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 15:04 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 15:04 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 15:04 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-09 15:04 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-09 15:04 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 15:04 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 15:04 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 15:04 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 15:04 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-09 15:04 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-09 15:04 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 15:04 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-09 15:04 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 15:04 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-09 15:04 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 15:04 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 15:04 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 15:04 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 15:04 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 15:04 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 15:04 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 15:04 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-09 15:04 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-09 15:04 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-09 15:04 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 15:04 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 15:04 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 15:04 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-09 15:04 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 15:04 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-09 15:04 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 15:04 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 15:04 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-09 15:04 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 15:04 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-09 15:04 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-09 15:04 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 15:04 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 15:04 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 15:04 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 15:04 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 15:04 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 15:04 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-09 15:04 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 15:04 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 15:04 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 15:04 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-09 15:04 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 15:04 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 15:04 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-09 15:04 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 15:04 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-09 15:04 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 15:04 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 15:04 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-07-09 15:04 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-07-09 15:04 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-07-09 15:04 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 15:00 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-09 15:00 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-07-09 15:00 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-08 23:51 - 2014-08-08 23:23 - 00030909 _____ () C:\Users\Melori Bigvava\Downloads\FRST.txt 2014-08-08 23:51 - 2014-07-12 13:50 - 00000000 ____D () C:\ProgramData\systemk 2014-08-08 23:51 - 2014-06-02 20:41 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\uTorrent 2014-08-08 23:50 - 2014-08-08 23:22 - 00000000 ____D () C:\FRST 2014-08-08 23:50 - 2014-08-08 21:49 - 00000316 _____ () C:\Windows\Tasks\WSE_Astromenda.job 2014-08-08 23:46 - 2014-08-08 23:46 - 00388608 _____ (Trend Micro Inc.) C:\Users\Melori Bigvava\Downloads\HiJackThis204 (1).exe 2014-08-08 23:46 - 2014-08-08 23:46 - 00017074 _____ () C:\Users\Melori Bigvava\Downloads\hijackthis.log 2014-08-08 23:45 - 2014-08-08 23:45 - 00388608 _____ (Trend Micro Inc.) C:\Users\Melori Bigvava\Downloads\HiJackThis204.exe 2014-08-08 23:28 - 2014-08-08 23:27 - 00147520 _____ () C:\Users\Melori Bigvava\Downloads\Addition.txt 2014-08-08 23:22 - 2014-08-08 23:22 - 02094080 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\FRST64.exe 2014-08-08 23:21 - 2014-08-08 23:21 - 01084928 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\FRST (1).exe 2014-08-08 23:20 - 2014-08-08 23:20 - 01084928 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\Nicht bestätigt 884755.crdownload 2014-08-08 23:20 - 2014-08-08 23:19 - 01084928 _____ (Farbar) C:\Users\Melori Bigvava\Downloads\FRST.exe 2014-08-08 23:14 - 2011-10-07 19:55 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-687521651-2007251113-3307527875-1001UA.job 2014-08-08 23:11 - 2012-05-27 17:03 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-08-08 23:07 - 2014-08-08 21:49 - 00000000 ____D () C:\AdwCleaner 2014-08-08 23:05 - 2014-04-13 17:10 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-08 23:02 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-08 23:02 - 2009-07-14 06:45 - 00021072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-08 22:59 - 2012-09-26 15:04 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\CrashDumps 2014-08-08 22:58 - 2011-06-08 08:27 - 01207366 _____ () C:\Windows\WindowsUpdate.log 2014-08-08 22:57 - 2010-11-21 08:50 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2014-08-08 22:57 - 2010-11-21 08:50 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2014-08-08 22:57 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-08-08 22:55 - 2012-09-03 13:27 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Skype 2014-08-08 22:54 - 2013-06-25 20:08 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Pokki 2014-08-08 22:52 - 2014-04-13 17:09 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-08 22:52 - 2011-07-05 16:16 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks 2014-08-08 22:52 - 2011-07-05 16:16 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks 2014-08-08 22:52 - 2011-06-08 16:02 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup 2014-08-08 22:51 - 2014-06-09 17:33 - 00000406 _____ () C:\Windows\Tasks\update-sys.job 2014-08-08 22:50 - 2014-04-21 19:01 - 00016229 _____ () C:\Windows\setupact.log 2014-08-08 22:50 - 2011-06-08 08:31 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-08 22:50 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-08 22:21 - 2012-02-12 12:31 - 00001162 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-687521651-2007251113-3307527875-1004UA.job 2014-08-08 21:59 - 2014-08-08 21:58 - 01366203 _____ () C:\Users\Melori Bigvava\Downloads\adwcleaner_3.304.exe 2014-08-08 21:54 - 2014-06-09 17:33 - 00000406 _____ () C:\Windows\Tasks\update-S-1-5-21-687521651-2007251113-3307527875-1006.job 2014-08-08 21:50 - 2014-08-08 21:49 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Melori Bigvava\Downloads\mbam-setup-2.0.2.1012 (3).exe 2014-08-08 21:50 - 2014-08-08 21:49 - 00003276 _____ () C:\Windows\System32\Tasks\WSE_Astromenda 2014-08-08 21:49 - 2014-08-08 21:49 - 01475072 _____ () C:\Users\Melori Bigvava\Downloads\adwcleaner_3.303_CB-DL-Manager [1].exe 2014-08-08 21:49 - 2014-08-08 21:49 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\WSE_Astromenda 2014-08-08 21:49 - 2014-08-08 21:49 - 00000000 ____D () C:\Program Files (x86)\WSE_Astromenda 2014-08-08 21:48 - 2014-08-08 21:48 - 00787392 _____ ( ) C:\Users\Melori Bigvava\Downloads\adwcleaner_3.303_CB-DL-Manager.exe 2014-08-08 21:47 - 2014-08-03 21:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010 Express 2014-08-08 21:42 - 2014-08-08 21:42 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-08-08 21:42 - 2014-08-08 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-08-08 21:42 - 2014-08-08 21:42 - 00000000 ____D () C:\ProgramData\Avira 2014-08-08 21:42 - 2014-08-08 21:42 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-08-08 21:42 - 2014-06-21 00:24 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-08 21:41 - 2014-08-08 21:41 - 04431200 _____ (Avira Operations GmbH & Co. KG) C:\Users\Melori Bigvava\Downloads\avira_de_av_ws2.exe 2014-08-08 21:37 - 2014-08-08 21:37 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-08-08 21:37 - 2014-08-08 21:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-08-08 21:37 - 2014-08-08 21:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-08-08 21:35 - 2014-08-08 21:34 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Melori Bigvava\Downloads\mbam-setup-2.0.2.1012 (2).exe 2014-08-07 00:29 - 2014-08-07 00:29 - 00000000 ____D () C:\ProgramData\VS 2014-08-07 00:28 - 2014-08-07 00:28 - 00000000 ____D () C:\40bfc9f03b46cc6a41 2014-08-07 00:09 - 2012-09-21 21:04 - 00000964 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-687521651-2007251113-3307527875-1006UA.job 2014-08-06 23:07 - 2014-08-06 23:07 - 01526490 _____ () C:\Users\Melori Bigvava\Downloads\Gta tool 1.15 anti freezer.rar 2014-08-06 23:07 - 2014-06-04 19:09 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\FileZilla 2014-08-06 23:00 - 2014-07-10 17:41 - 314306560 _____ () C:\Users\Melori Bigvava\Downloads\update.rpf 2014-08-06 22:55 - 2014-08-06 22:54 - 56663391 _____ () C:\Users\Melori Bigvava\Downloads\AllBypassEboots.rar 2014-08-06 22:55 - 2014-08-06 22:54 - 06004615 _____ (Tim Kosse) C:\Users\Melori Bigvava\Downloads\FileZilla_3.9.0.2_win32-setup.exe 2014-08-06 22:52 - 2014-08-06 22:52 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\h4MGCY7S (2) 2014-08-06 22:51 - 2014-08-06 22:51 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\h4MGCY7S (1) 2014-08-06 22:51 - 2014-08-06 22:51 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\h4MGCY7S 2014-08-06 21:46 - 2014-08-06 21:46 - 56663398 _____ () C:\Users\Melori Bigvava\Downloads\AllBypassEboots.rar.crdownload 2014-08-06 21:46 - 2014-08-06 21:43 - 23697760 _____ () C:\Users\Melori Bigvava\Downloads\DLCFullyModded.edat 2014-08-06 21:09 - 2012-09-21 21:04 - 00000942 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-687521651-2007251113-3307527875-1006Core.job 2014-08-06 17:07 - 2014-08-04 13:40 - 00000000 ____D () C:\Users\Melori Bigvava\Desktop\Urlaubs Bilder 2014-08-06 13:21 - 2012-02-12 12:31 - 00001140 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-687521651-2007251113-3307527875-1004Core.job 2014-08-06 09:32 - 2014-08-06 09:32 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010 2014-08-06 09:32 - 2014-08-06 09:32 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010 2014-08-06 06:32 - 2014-07-26 18:44 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014 2014-08-06 06:32 - 2014-07-26 18:41 - 00000000 ____D () C:\Program Files (x86)\LPT 2014-08-06 06:32 - 2014-07-26 18:39 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\LPT 2014-08-06 06:32 - 2012-03-14 21:33 - 00000000 ____D () C:\Users\Sandrtropez 2014-08-06 06:32 - 2011-11-21 19:23 - 00000000 ____D () C:\Users\Gast 2014-08-06 06:32 - 2011-07-05 16:13 - 00000000 ____D () C:\Users\Melori 2014-08-06 06:31 - 2014-08-05 10:38 - 00000000 ____D () C:\887c6e35b091418ace 2014-08-06 06:31 - 2014-08-04 15:15 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\iMCS Productions 2014-08-06 06:31 - 2014-08-04 15:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GTA Online - Recovery Tool 2014-08-06 06:31 - 2014-08-04 14:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced IP Scanner v2 2014-08-06 06:31 - 2014-08-04 14:02 - 00000000 ____D () C:\Program Files (x86)\Advanced IP Scanner 2014-08-06 06:31 - 2014-08-04 12:20 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 10.0 2014-08-06 06:31 - 2014-08-03 21:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0 2014-08-06 06:31 - 2014-07-26 18:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014 2014-08-06 06:31 - 2014-07-26 18:37 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\OpenCandy 2014-08-06 06:31 - 2014-07-26 18:36 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\DVDVideoSoft 2014-08-06 06:31 - 2014-07-24 17:15 - 00000000 ___RD () C:\Users\Melori Bigvava\Desktop\Animieter 2014-08-06 06:31 - 2014-07-23 18:04 - 00000000 ____D () C:\Users\Melori Bigvava\Desktop\CRACKbyActivity 2014-08-06 06:31 - 2014-06-23 17:11 - 00000000 ____D () C:\Program Files (x86)\Cain 2014-08-06 06:31 - 2014-06-23 17:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cain 2014-08-06 06:31 - 2014-06-11 15:03 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\PhotoScape 2014-08-06 06:31 - 2014-06-09 17:40 - 00000000 ____D () C:\Program Files (x86)\Cinema 4D R12 2014-08-06 06:31 - 2014-06-09 14:14 - 00000000 ____D () C:\Users\Melori Bigvava\Downloads\Call of Duty Modern Warfare 3 full multiplayer + SP ^^nosTEAM^^ 2014-08-06 06:31 - 2012-09-02 11:46 - 00000000 ___RD () C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-08-06 06:31 - 2012-08-21 16:08 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Skype 2014-08-06 06:31 - 2011-10-13 10:22 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-08-06 06:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-08-06 06:26 - 2014-08-03 21:22 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\Visual Studio 2010 2014-08-06 06:25 - 2014-08-03 21:22 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services 2014-08-06 06:25 - 2014-08-03 21:19 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer 2014-08-06 06:25 - 2014-07-26 18:39 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Smartbar 2014-08-06 06:25 - 2014-07-24 17:27 - 00000000 ____D () C:\Program Files (x86)\ProtectDisc 2014-08-06 06:25 - 2014-06-21 00:28 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition 2014-08-06 06:25 - 2012-03-07 19:35 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-08-06 06:24 - 2014-08-04 15:15 - 00000000 ____D () C:\Program Files (x86)\iMCS Productions 2014-08-06 06:24 - 2014-08-03 21:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services 2014-08-06 06:24 - 2014-07-27 20:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-06 06:24 - 2014-06-21 00:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server 2014-08-06 06:24 - 2011-06-08 16:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition 2014-08-06 06:08 - 2014-08-06 06:08 - 00000000 __SHD () C:\found.001 2014-08-06 05:58 - 2014-08-05 19:08 - 00000000 ____D () C:\93ddace8022a23aab77f13fc 2014-08-06 05:58 - 2014-06-05 17:16 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeter 2014-08-06 05:58 - 2012-03-07 19:35 - 00000000 __SHD () C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} 2014-08-06 05:53 - 2011-06-08 16:06 - 00000000 ____D () C:\ProgramData\Temp 2014-08-06 05:52 - 2012-12-25 19:16 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-08-06 05:52 - 2012-12-25 19:15 - 00000000 ____D () C:\ProgramData\Apple 2014-08-05 23:34 - 2012-09-02 11:46 - 00000000 ____D () C:\Users\Melori Bigvava 2014-08-05 19:05 - 2014-08-03 21:11 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-05 13:06 - 2013-03-08 17:19 - 00000000 ____D () C:\Users\Melori Bigvava\Downloads\test 2014-08-05 11:21 - 2014-08-05 11:21 - 03233643 _____ () C:\Users\Melori Bigvava\Downloads\K&KTool (3).rar 2014-08-05 10:32 - 2014-04-22 08:35 - 00838766 _____ () C:\Windows\PFRO.log 2014-08-04 21:30 - 2014-08-04 21:30 - 00000032 _____ () C:\Users\Melori Bigvava\Desktop\Meine Id.txt 2014-08-04 17:37 - 2014-08-04 17:23 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Temporary Projects 2014-08-04 17:23 - 2014-08-04 17:22 - 00211852 _____ () C:\Users\Melori Bigvava\AppData\Local\debuggee.mdmp 2014-08-04 17:21 - 2014-08-04 17:21 - 00002158 _____ () C:\Users\Melori Bigvava\Downloads\1407183683_06_Pool.svg 2014-08-04 16:57 - 2014-08-04 16:57 - 00000278 _____ () C:\Users\Melori Bigvava\advanced_ip_scanner_MAC.bin 2014-08-04 16:30 - 2014-08-04 16:30 - 00147474 _____ () C:\Users\Melori Bigvava\Downloads\[kickass.to]ps3.watch.dogs.duplex (1).torrent 2014-08-04 16:29 - 2014-08-04 16:29 - 00000824 _____ () C:\Users\Melori Bigvava\Desktop\µTorrent.lnk 2014-08-04 16:29 - 2014-08-04 16:29 - 00000804 _____ () C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-08-04 16:28 - 2014-08-04 16:28 - 01940560 _____ (BitTorrent Inc.) C:\Users\Melori Bigvava\Downloads\uTorrent.exe 2014-08-04 16:11 - 2014-08-04 16:11 - 00147474 _____ () C:\Users\Melori Bigvava\Downloads\[kickass.to]ps3.watch.dogs.duplex.torrent 2014-08-04 15:15 - 2014-08-04 15:15 - 00001412 _____ () C:\Users\Public\Desktop\GTA Online Recovery Tool.lnk 2014-08-04 14:15 - 2014-08-04 14:15 - 00002770 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-08-04 14:02 - 2014-08-04 14:02 - 00000983 _____ () C:\Users\Public\Desktop\Advanced IP Scanner.lnk 2014-08-04 14:01 - 2014-08-04 14:01 - 06596600 _____ ( ) C:\Users\Melori Bigvava\Downloads\ipscan_2.3.2161.exe 2014-08-04 12:26 - 2014-08-04 12:26 - 00226146 _____ () C:\Users\Melori Bigvava\Downloads\Weapon And Callsign Unlocks.txt 2014-08-04 12:16 - 2014-08-04 12:16 - 03296584 _____ (Microsoft Corporation) C:\Users\Melori Bigvava\Downloads\vbasic_web.exe 2014-08-04 11:29 - 2014-08-04 11:29 - 00000000 __SHD () C:\found.000 2014-08-04 10:59 - 2014-08-03 21:27 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-08-04 10:50 - 2014-08-04 10:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-08-03 21:56 - 2014-08-03 21:45 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temporary Projects 2014-08-03 21:56 - 2013-07-08 13:17 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-08-03 21:29 - 2014-08-03 21:26 - 00000000 ____D () C:\Users\Gast\Documents\Visual Studio 2010 2014-08-03 21:27 - 2014-08-03 21:27 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-08-03 21:19 - 2014-08-03 21:19 - 00000000 ____D () C:\Windows\PCHEALTH 2014-08-03 21:00 - 2014-08-03 21:00 - 00009800 ____N () C:\bootsqm.dat 2014-08-03 20:43 - 2014-07-24 16:34 - 00000000 ____D () C:\Users\Public\Documents\Reallusion 2014-08-03 20:43 - 2014-07-24 16:33 - 00000000 ____D () C:\Program Files (x86)\Reallusion 2014-08-03 20:43 - 2011-06-08 15:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-27 20:25 - 2014-07-15 21:27 - 00000000 ____D () C:\ProgramData\EPS 2014-07-27 20:13 - 2014-07-27 20:13 - 05618120 _____ (Speedchecker Limited ) C:\Users\Melori Bigvava\Documents\PCSUUpdate.exe 2014-07-27 20:13 - 2014-07-27 20:13 - 00057128 _____ () C:\Users\Melori Bigvava\Documents\PCSpeedUp-Silent-Update.exe 2014-07-26 21:31 - 2014-07-26 21:31 - 00000685 _____ () C:\Users\Melori Bigvava\Desktop\Sorce Code Passwort Stealer (1).txt 2014-07-26 21:19 - 2014-07-26 21:19 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler 2014-07-26 21:19 - 2014-07-26 21:19 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2014-07-26 21:18 - 2014-07-26 18:43 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-07-26 21:18 - 2013-06-25 19:24 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Sony 2014-07-26 18:44 - 2014-07-26 18:44 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\TuneUp Software 2014-07-26 18:44 - 2014-07-26 18:44 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\TuneUp Software 2014-07-26 18:44 - 2014-07-08 20:22 - 00000015 _____ () C:\trace.txt 2014-07-26 18:41 - 2014-07-26 18:41 - 00002694 _____ () C:\Users\Melori Bigvava\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-07-26 18:41 - 2014-07-26 18:41 - 00002647 _____ () C:\Users\Melori Bigvava\Desktop\Search.lnk 2014-07-26 18:36 - 2014-07-26 18:35 - 29527272 _____ (DVDVideoSoft Ltd. ) C:\Users\Melori Bigvava\Downloads\FreeYouTubeToMP3Converter-3.12.42.716.exe 2014-07-26 17:37 - 2014-07-10 17:41 - 66311680 _____ () C:\Users\Melori Bigvava\Downloads\updateletze.rpf 2014-07-26 15:22 - 2014-07-26 15:21 - 05006664 _____ () C:\Users\Melori Bigvava\Downloads\Black Ops 2 Tool 1.18 2.18 Cex Dex.zip 2014-07-26 15:11 - 2014-07-26 15:10 - 04979643 _____ () C:\Users\Melori Bigvava\Downloads\Black OPS II RTM Tool - 1.17 fix.rar 2014-07-24 17:27 - 2014-07-24 17:27 - 00335288 _____ (Protect Software GmbH) C:\Windows\system32\Drivers\acedrv11.sys 2014-07-24 17:14 - 2014-07-24 17:14 - 00826192 _____ (Chip Digital GmbH) C:\Users\Melori Bigvava\Downloads\CorelDraw Graphics Suite X7 - CHIP-Installer.exe 2014-07-24 16:54 - 2014-07-24 16:54 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Local\Reallusion 2014-07-23 18:23 - 2014-07-23 18:23 - 00001488 _____ () C:\Users\Melori Bigvava\Desktop\CINEMA 4D - Verknüpfung.lnk 2014-07-23 17:54 - 2014-07-23 17:53 - 14644733 _____ () C:\Users\Melori Bigvava\Downloads\Notrens Ex Materials.rar 2014-07-23 15:19 - 2014-06-15 19:36 - 00054784 ___SH () C:\Users\Melori Bigvava\Documents\Thumbs.db 2014-07-23 15:18 - 2014-07-23 15:18 - 00011233 _____ () C:\Users\Melori Bigvava\Documents\Theo.odt 2014-07-21 21:05 - 2014-07-21 21:05 - 18135006 _____ () C:\Users\Melori Bigvava\Downloads\intro.mp4 2014-07-21 17:46 - 2014-07-21 17:41 - 92312238 _____ () C:\Users\Melori Bigvava\Downloads\SEN Enabler v5.3.3 [CEX] [4.55] (1).rar 2014-07-21 17:39 - 2014-07-21 17:39 - 00116352 _____ () C:\Users\Melori Bigvava\Downloads\Chaos Air Bringer.pkg 2014-07-21 17:23 - 2014-07-21 17:20 - 35035136 _____ () C:\Users\Melori Bigvava\Downloads\Psych Project Beta1.8.exe 2014-07-20 18:31 - 2014-07-20 18:31 - 00000032 _____ () C:\Users\Melori Bigvava\Desktop\shutdown -s -t 20 -c.txt 2014-07-20 00:18 - 2014-02-24 18:26 - 00000000 ____D () C:\Users\Gast\Documents\Camtasia Studio 2014-07-20 00:03 - 2012-10-29 01:02 - 00015872 _____ () C:\Users\Gast\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-07-20 00:02 - 2014-07-20 00:02 - 00001386 _____ () C:\Users\Gast\Desktop\Playstaion Codes Gratis.lnk 2014-07-19 23:57 - 2014-07-19 23:57 - 18135006 _____ () C:\Users\Gast\Downloads\intro.mp4 2014-07-19 23:40 - 2014-07-19 23:40 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\TuneUp Software 2014-07-19 23:40 - 2014-07-19 23:40 - 00000000 ____D () C:\Users\Gast\AppData\Local\TuneUp Software 2014-07-19 23:38 - 2011-11-22 17:32 - 00064416 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-19 22:27 - 2014-07-19 22:27 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\HideIPEasy 2014-07-19 22:27 - 2014-07-19 22:27 - 00000000 ____D () C:\ProgramData\HideIPEasy 2014-07-19 18:54 - 2014-07-06 15:31 - 04757934 _____ () C:\Users\Melori Bigvava\Downloads\Call of Duty BO II Zm + Mp + League RTM Tool Ver 9.0.0.4 (CCAPI 2.50).rar 2014-07-19 18:34 - 2014-07-10 17:41 - 66312704 _____ () C:\Users\Melori Bigvava\Downloads\update.rpf1 2014-07-18 20:56 - 2012-03-08 21:48 - 00000000 ____D () C:\output 2014-07-18 20:55 - 2014-06-11 15:03 - 00030720 ____H () C:\Users\Melori Bigvava\Downloads\photothumb.db 2014-07-18 19:25 - 2014-07-18 19:25 - 00001690 _____ () C:\Users\Melori Bigvava\Desktop\CyberGhost 5.lnk 2014-07-18 19:25 - 2014-06-20 23:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5 2014-07-18 19:25 - 2014-06-20 23:37 - 00000000 ____D () C:\Program Files\CyberGhost 5 2014-07-18 19:24 - 2014-07-18 19:23 - 08646824 _____ (CyberGhost S.R.L. ) C:\Users\Melori Bigvava\Downloads\CG_5.0.13.17.exe 2014-07-18 18:56 - 2014-07-18 18:56 - 00002113 _____ () C:\Users\Melori Bigvava\Desktop\FunnyVoice - CHIP Downloader.lnk 2014-07-18 18:56 - 2014-07-18 18:55 - 00042496 _____ () C:\Users\Melori Bigvava\Downloads\funny-voice_6658.exe 2014-07-18 17:09 - 2014-07-18 17:08 - 02883585 _____ () C:\Users\Melori Bigvava\Downloads\CFW Info TooL by Modz Ko.rar 2014-07-16 20:01 - 2014-07-15 21:40 - 00000000 ____D () C:\Program Files (x86)\OkayFreedom 2014-07-16 20:00 - 2014-07-15 21:40 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Steganos 2014-07-15 21:42 - 2014-07-15 21:40 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Steganos VPN 2014-07-15 21:37 - 2014-07-15 21:37 - 00001809 _____ () C:\Users\Melori Bigvava\Downloads\ProxyList-2014-07-15.tsv 2014-07-15 21:37 - 2014-07-15 21:37 - 00001809 _____ () C:\Users\Melori Bigvava\Documents\ProxyList-2014-07-15.txt 2014-07-15 21:34 - 2014-06-18 20:58 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\Action! 2014-07-15 21:30 - 2014-06-23 17:36 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\Boot usw 2014-07-15 21:30 - 2014-05-25 18:59 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\Camtasia Studio 2014-07-15 21:27 - 2014-07-15 21:26 - 02503091 _____ (hxxp://www.didsoft.com ) C:\Users\Melori Bigvava\Downloads\EPS_setup.exe 2014-07-15 21:01 - 2014-06-21 13:15 - 00000000 ____D () C:\Users\Melori Bigvava\Documents\Visual Studio 2012 2014-07-15 14:03 - 2014-07-15 14:03 - 00000000 ____D () C:\ProgramData\APN 2014-07-15 14:01 - 2014-07-15 14:01 - 00000000 ____D () C:\ProgramData\Oracle 2014-07-15 14:00 - 2014-07-15 14:01 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-07-15 14:00 - 2014-07-15 14:00 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-07-15 14:00 - 2014-07-15 14:00 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-07-15 14:00 - 2014-07-15 14:00 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-07-15 14:00 - 2014-07-15 14:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-15 14:00 - 2014-07-15 14:00 - 00000000 ____D () C:\Program Files (x86)\Java 2014-07-14 22:26 - 2012-02-12 15:12 - 00000000 ____D () C:\Users\Sandrtropez\AppData\Roaming\Skype 2014-07-14 18:40 - 2014-07-14 18:39 - 00000926 _____ () C:\Users\Melori Bigvava\Desktop\sandropreisliste.txt 2014-07-13 20:38 - 2014-06-25 14:49 - 00000000 ____D () C:\Users\Melori Bigvava\Desktop\mw3 2014-07-13 15:21 - 2012-12-25 22:44 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Apple Computer 2014-07-13 15:07 - 2014-07-13 15:07 - 00569372 _____ (DotExE ) C:\Users\Melori Bigvava\Downloads\MoonTools.exe 2014-07-13 15:07 - 2014-07-13 15:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MoonTools 2014-07-13 15:07 - 2014-07-13 15:07 - 00000000 ____D () C:\Program Files (x86)\MoonTools 2014-07-13 14:12 - 2014-06-05 17:46 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Wireshark 2014-07-12 20:41 - 2014-07-12 20:37 - 80561348 _____ () C:\Users\Melori Bigvava\Downloads\Modmenu (2).zip 2014-07-12 17:06 - 2014-07-06 17:51 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\TeamViewer 2014-07-12 16:26 - 2014-07-12 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor 2014-07-12 16:26 - 2014-07-12 15:20 - 00000000 ____D () C:\Program Files (x86)\HxD 2014-07-12 16:23 - 2014-07-12 16:23 - 00000032 _____ () C:\Users\Melori Bigvava\Documents\key_ps3.dat 2014-07-12 16:23 - 2014-07-12 15:12 - 00412996 _____ () C:\Users\Melori Bigvava\Downloads\LibertyV-r47.zip 2014-07-12 16:23 - 2014-06-26 01:08 - 00000032 _____ () C:\Users\Melori Bigvava\Desktop\key_ps3.dat 2014-07-12 16:11 - 2014-07-12 16:11 - 00000276 _____ () C:\Users\Melori Bigvava\Downloads\ps3key.zip 2014-07-12 15:47 - 2014-07-12 15:47 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Mael 2014-07-12 15:20 - 2014-07-12 15:20 - 00874674 _____ () C:\Users\Melori Bigvava\Downloads\HxDSetupDE.zip 2014-07-12 15:10 - 2014-07-12 15:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex-Editor MX 2014-07-12 15:10 - 2014-07-12 15:09 - 00000000 ____D () C:\Program Files (x86)\Hex-Editor MX 2014-07-12 15:08 - 2014-07-12 15:08 - 00860736 _____ () C:\Users\Melori Bigvava\Downloads\hexedit602.zip 2014-07-12 15:08 - 2014-07-12 15:08 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\DesktopIconAmazon 2014-07-12 15:07 - 2014-07-12 15:07 - 00961360 _____ (Chip Digital GmbH) C:\Users\Melori Bigvava\Downloads\Hex Editor MX - CHIP-Installer.exe 2014-07-12 13:57 - 2014-07-12 13:56 - 00266398 _____ () C:\Users\Melori Bigvava\Downloads\DHL.apk 2014-07-12 13:50 - 2014-07-12 13:50 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Settings Manager 2014-07-11 22:45 - 2014-07-05 20:12 - 02954505 _____ () C:\Users\Melori Bigvava\Desktop\K&KTool (2).rar 2014-07-11 20:02 - 2014-07-11 20:02 - 00780824 _____ (Elex do Brasil Participações Ltda) C:\Users\Melori Bigvava\Downloads\yet_another_cleaner_brob.exe 2014-07-11 18:12 - 2014-06-08 20:33 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\TS3Client 2014-07-11 17:07 - 2014-06-23 17:11 - 00001781 _____ () C:\Users\UpdatusUser\Desktop\Cain.lnk 2014-07-11 17:07 - 2014-06-23 17:11 - 00001781 _____ () C:\Users\Sandrtropez\Desktop\Cain.lnk 2014-07-11 17:07 - 2014-06-23 17:11 - 00001781 _____ () C:\Users\Gast\Desktop\Cain.lnk 2014-07-11 15:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-07-11 13:42 - 2014-07-11 13:42 - 02427689 _____ () C:\Users\Melori Bigvava\Downloads\Mohanads Tool (1).rar 2014-07-11 13:38 - 2014-07-11 13:38 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Melori Bigvava\Downloads\mbam-setup-2.0.2.1012 (1).exe 2014-07-11 12:29 - 2014-07-11 12:28 - 01311951 _____ () C:\Users\Melori Bigvava\Downloads\Youbooster Pro Edition Updated.exe 2014-07-11 12:21 - 2014-07-11 12:21 - 00300586 _____ () C:\Users\Melori Bigvava\Downloads\Yotubube bot.zip 2014-07-10 17:44 - 2014-07-10 17:41 - 66003968 _____ () C:\Users\Melori Bigvava\Downloads\update.2rpf 2014-07-10 17:21 - 2014-07-10 17:21 - 00002016 _____ () C:\Users\Melori Bigvava\Downloads\C# WFApplication (For RTM).txt 2014-07-10 14:53 - 2009-07-14 06:45 - 00295632 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 14:51 - 2014-05-06 12:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 14:51 - 2010-11-21 09:00 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 14:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-07-10 14:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-07-09 22:41 - 2013-08-14 22:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 22:37 - 2011-09-07 22:40 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-09 20:53 - 2014-07-09 20:48 - 105891762 _____ () C:\Users\Melori Bigvava\Downloads\MOD NO LIMIT V3 BY FRENCH TOUCH (CEX).rar 2014-07-09 20:17 - 2014-07-09 20:17 - 00005120 _____ () C:\Users\Melori Bigvava\Desktop\PS3LOGO.DAT 2014-07-09 20:15 - 2014-06-04 21:24 - 66003968 _____ () C:\Users\Melori Bigvava\Downloads\d.rpf 2014-07-09 20:12 - 2014-06-09 13:25 - 14894400 _____ () C:\Users\Melori Bigvava\Downloads\EBOOT.BIN 2014-07-09 19:46 - 2014-07-09 19:46 - 00001127 _____ () C:\Users\Public\Desktop\ControlConsole API.lnk 2014-07-09 19:46 - 2014-07-09 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ControlConsole API 2014-07-09 19:46 - 2014-07-09 19:46 - 00000000 ____D () C:\Program Files (x86)\ControlConsoleAPI 2014-07-09 19:43 - 2014-07-08 20:26 - 00000000 ____D () C:\Users\Melori Bigvava\Desktop\Hackzz 2014-07-09 19:41 - 2014-07-09 19:40 - 06040056 _____ () C:\Users\Melori Bigvava\Downloads\CcApi_package_2.50 (3).rar 2014-07-09 16:47 - 2014-07-09 16:47 - 00021215 _____ () C:\Users\Melori Bigvava\Downloads\vca122.zip 2014-07-09 16:35 - 2014-07-09 16:35 - 00509952 _____ () C:\Users\Melori Bigvava\Downloads\GUI Booter (2).exe 2014-07-09 16:35 - 2014-07-09 16:35 - 00000000 ____D () C:\Users\Melori Bigvava\AppData\Roaming\Gui Booter 2014-07-09 15:11 - 2012-05-27 17:03 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-07-09 15:11 - 2012-05-27 17:03 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-09 15:11 - 2011-07-06 15:12 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-07-09 14:41 - 2014-07-02 21:34 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP Files to move or delete: ==================== C:\ProgramData\ism_0_llatsni.pad Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\avgnt.exe C:\Users\Gast\AppData\Local\Temp\banner.exe C:\Users\Melori\AppData\Local\Temp\36808-93901-counter-strike.exe C:\Users\Melori\AppData\Local\Temp\coupish-babylon.exe C:\Users\Melori\AppData\Local\Temp\install_flashplayer11x64_mssa_aih(1).exe C:\Users\Melori\AppData\Local\Temp\install_flashplayer11x64_mssa_aih.exe C:\Users\Melori\AppData\Local\Temp\instloffer.exe C:\Users\Melori\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Melori\AppData\Local\Temp\SkypeSetup.exe C:\Users\Melori\AppData\Local\Temp\sqlite3.dll C:\Users\Melori\AppData\Local\Temp\sqlite3.exe C:\Users\Melori\AppData\Local\Temp\YontooIEClient.dll C:\Users\Melori Bigvava\AppData\Local\Temp\avgnt.exe C:\Users\Melori Bigvava\AppData\Local\Temp\Quarantine.exe C:\Users\Melori Bigvava\AppData\Local\Temp\Uninstall.exe C:\Users\Sandrtropez\AppData\Local\Temp\avgnt.exe C:\Users\Sandrtropez\AppData\Local\Temp\setup{91919419-D9D9-4314-BA09-25D846D4A0E6}.exe C:\Users\Sandrtropez\AppData\Local\Temp\SpotifyUninstall.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-10 23:12 ==================== End Of Log ============================ Es tut mir leid ich verstehe dies nicht richtig also soll ich jetzt die Frst.txt in die reinkopieren ? :) Mfg Sandro |
Ja, ich poste dir nochmal eine detaillierte Anleitung, ich brauch auch noch die addition.txt Danke :)
|
Addition.txt sorry es passt nicht alles rein aber erster teil Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-08-2014 |
Addition.txt 2ter Teil :) Code: ==================== Hosts content: ========================== Code: ==================== Loaded Modules (whitelisted) ============= |
Hallo Sandro, hui, jede Menge Adware :) Schritt 1 Bitte deinstalliere folgende Programme (falls vorhanden) : FileParade Bundle Google Update Helper Installer Java(TM) 6 Update 24 Java 7 Update 60 Price Meter Skype Toolbars Update for Codec Pack Update for PriceMeter Updater Yahoo Community Smartbar Yahoo Community Smartbar Yontoo WSE_Astromenda Dazu gehe auf: den Windowsbutton in der Taskleiste --> Systemsteuerung --> Programme (Unterpunkt Programme deinstallieren) --> Programm auswählen --> entfernen Falls du ein Programm nicht deinstallieren kannst, lade dir von hier den Revo-uninstaller herunter und deinstalliere es damit, wähle dabei den moderaten Modus. Schritt 2 Lasse den Adwarecleaner laufen, brauchts nicht extra runterladen ist ja schon drauf ;) Downloade Dir bitte ![]()
Schritt 3 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 4 Starte noch einmal FRST.
|
Hallo Sandra, Leider habe ich es mit Schritt 2 und 3 Aufgeben müssen da adwcleaner immer stehen bleibt also immer wenn es denn Browser Analyziert obwohl ich alles beachtet habe wie sie es mir gesagt haben ausserdem öffnet sich Anti Malware bei mir nicht auch nachdem ich es deinstalliert und danach Installiert habe funkt. es nicht aber wir haben ein fortschritt hinbekommen und zwar zeigt es auf meinem Screen kein srptm mehr an und deswegen bin ich ihnen sehr dankbar :) Mfg Sandro |
Hallo Sandro, das freut mich sehr, dass diese Fehlermeldung nicht mehr vorhanden ist, dennoch sind wir mit dem Rechner noch lange nicht fertig. Lasse bitte die Schritte mit dem adwarecleaner und Malwarebytes weg, lösche FRST, lade es erneut herunter, mache einen neuen Scan, hake dabei addition.txt an und poste mir dann FRST.txt und addition.txt |
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 01 --- --- --- Da der addition.txt nicht ganz reinpasst poste ich es nochmal in schritten :) Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-08-2014 01 |
Code: (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) Code: ==================== Loaded Modules (whitelisted) ============= |
Hallo Sandro, danke :) Schritt 1 Gab es Probleme mit dem deinstallieren? Ich seh da im Log noch: Google Update Helper Price Meter Settings Manager Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKU\S-1-5-21-687521651-2007251113-3307527875-1006\...\Run: [Browser Infrastructure Helper] => C:\Users\Melori Bigvava\AppData\Local\Smartbar\Application\Smartbar.exe [28952 2014-06-11] (Smartbar) Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Starte noch einmal FRST
Schritt 3 In deinem Chrome Browser ist astromenda.com als Startseite eingetragen Stelle nach dieser Anleitung deine Startseite neu ein. Schritt 4
Schritt 5
Schritt 6 Lösche Malwarebytes, lade es erneut herunter und starte es. Schritt 7 Starte noch einmal FRST.
|
Schritt 1 Bei Schritt eins hat es Google Update Helper bei Revon Uninstaller und auch bei Programme Deinstallieren nicht gefunden :) Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-08-2014 01 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:20 Uhr. |
Copyright ©2000-2025, Trojaner-Board