Code:
# AdwCleaner v3.305 - Bericht erstellt am 15/08/2014 um 11:33:41
# Aktualisiert 14/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : User - USER-PC
# Gestartet von : C:\Users\User\Downloads\adwcleaner_3.305.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Windows\System32\roboot64.exe
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\prefs.js ]
-\\ Google Chrome v36.0.1985.143
[ Datei : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=M08B9858D-D8A3-4271-B7F7-468961097011&SearchSource=58&CUI=&UM=6&UP=SP933714E8-184D-44EC-808D-571B33A3068E&q={searchTerms}&SSPV=
*************************
AdwCleaner[R0].txt - [1468 octets] - [15/08/2014 11:33:22]
AdwCleaner[S0].txt - [1343 octets] - [15/08/2014 11:33:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1403 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.08.2014
Suchlauf-Zeit: 11:17:08
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.15.09
Rootkit Datenbank: v2014.08.04.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: User
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 359316
Verstrichene Zeit: 13 Min, 7 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 1
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [3fa6a620f5867db96e7e12589c6625db],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 2
PUP.Optional.Trovi.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\searchplugins\trovi-search.xml, In Quarantäne, [4a9b477fafcc58dece820be94bb70af6],
PUP.Optional.Trovi, C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ({"apps":{"shortcuts_have_been_created":true},"browser":{"check_default_browser":true,"clear_data":{"content_licenses":true,"form_data":true,"hosted_apps_data":true,"passwords":true,"time_period":4},"clear_lso_data_enabled":true,"last_clear_browsing_data_time":"13050064345582708","last_known_google_url":"https://www.google.ch/","last_prompted_google_url":"https://www.google.ch/","pepper_flash_settings_enabled":true,"show_home_button":true,"window_placement":{"bottom":1089,"left":330,"maximized":true,"right":1275,"top":69,"work_area_bottom":1040,"work_area_left":0,"work_area_right":1920,"work_area_top":0}},"countryid_at_install":17477,"default_apps_install_state":3,"default_search_provider":{"enabled":true,"id":"1","suggest_url":"hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}","synced_guid":"D2B35E3E-83E2-4EF7-8FB0-3E2D596DD2C6"},"default_search_provider_data":{"template_url_data":{"alternate_urls":[],"created_by_policy":false,"date_created":"13051997891998208","favicon_url":"","id":"1","image_url":"","image_url_post_params":"","input_encodings":[],"instant_url":"","instant_url_post_params":"","keyword":"trovi.search","last_modified":"13051997891998208","new_tab_url":"","originating_url":"","prepopulate_id":0,"safe_for_autoreplace":false,"search_terms_replacement_key":"","search_url_post_params":"","short_name":"Trovi search","suggestions_url":"http:\/\/suggest.seccint.com\/CSuggestJson.ashx?prefix={searchTerms}","suggestions_url_post_params":"","synced_guid":"D2B35E3E-83E2-4EF7-8FB0-3E2D596DD2C6","url":"http:\/\/www.trovi.com\/Results.aspx?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=M08B9858D-D8A3-4271-B7F7-468961097011&SearchSource=58&CUI=&UM=6&UP=SP933714E8-184D-44EC-808D-571B33A3068E&q={searchTerms}&SSPV=","usage_count":0}},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"ping_delay":-60,"skip_first_run_ui":false,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["hxxp://admin.flightm.com/",["hxxp://www.flightm.com/",2.6037003999999997]],["hxxp://clkrev.com/",["hxxp://cdn1.clkrev.com/",3.1714050174239996,"hxxp://clkrev.com/",2.529573049612]],["hxxp://thepiratebay.ee/",["hxxp://clkrev.com/",3.4923210013299997,"hxxp://thepiratebay.ee/",4.775984936953999,"hxxp://www.google-analytics.com/",2.529573049612]],["hxxp://www.flightm.com/",["hxxp://ajax.googleapis.com/",1.2384095693862427,"hxxp://fonts.googleapis.com/",1.2384095693862427,"hxxp://themes.googleusercontent.com/",1.2384095693862427,"hxxp://www.flightm.com/",10.351761144700395,"https://www.flightm.com/",1.5687297693862425]],["hxxp://www.flightx.net/",["hxxp://flightx.net/",2.025335319191497]],["hxxp://www.trovi.com/",["hxxp://resources.trovi.com/",3.18201594682567,"hxxp://storage.stgbssint.com/",0.902812938141093]],["https://ch.search.yahoo.com/",["https://ad.yieldmanager.com/",2.084686339270529,"https://cdnk.interclick.com/",2.084686339270529,"https://csync.yahooapis.com/",2.084686339270529,"https://ec.yimg.com/",1.6396244539792004,"https://s.yimg.com/",5.507966632655697]]],"startup_list":[1,"hxxp://admin.flightm.com/","hxxp://resources.trovi.com/","hxxp://storage.stgbssint.com/","hxxp://suggest.seccint.com/","hxxp://www.flightm.com/","hxxp://www.trovi.com/","https://chrome.google.com/","https://clients2.google.com/","https://clients2.googleusercontent.com/","https://www.googleapis.com/"]},"download":{"directory_upgrade":true},"extensions":{"alerts":{"initialized":true},"autoupdate":{"last_check":"13049405996589757","next_check":"13051998936861208"},"blacklistupdate":{"lastpingday":"13044092393247248","version":"0.0.0.149"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"install_signature":{"expire_date":"2014-11-01","ids":["aohghmighlieiainnegkcijnfilokake","lifbcibllhkdhoafpjfnlhfpfgnpldfl","mkfokfffehpeedafpekjeddnmnjhmcmk"],"invalid_ids":[],"salt":"e3icY/bEPI4U0EgUwi9r3K7xJwq9LrJAWXhSqu6sB54=","signature":"BfGXw5jTjCR2aUKriYrgOBT+1mn9xq3kH7coTPXh/8D5UWpMtpVdBGr6R6ZvZQpBd8c0vaELDQT6niPyr7wQORjQJwtaye5P+IJHkA3tdjKgSE4/AicPAJJVl59rH7LydIG0RAjm3Tn6Sp2jyczhe9QC2ZcZAmYuhsA8C5ArXrN5V1yH/SsEu7ZYse+X49bfwGzZICBMi/P38w7c0stJhKf5t+K7iEhU3IvoY4vnaugUZBgDRGqQ90CsSbMYBJI5fW/e5v8bct15D4IqHOX2A4DAgkmYRc/eD5cSkv+ouMc/V1ddL0CZkd/U7YgJf72UJObBsN8lI724FOYwmYQBWg==","signature_format_version":2,"timestamp":"13051997901545329"},"known_disabled":["lifbcibllhkdhoafpjfnlhfpfgnpldfl","mkfokfffehpeedafpekjeddnmnjhmcmk"],"last_chrome_version":"36.0.1985.125","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","webstorePrivate"],"manifest_permissions":[]},"app_launcher_ordinal":"n","creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"install_time":"13044126764569239","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Chrome Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Store","permissions":["webstorePrivate","management"],"version":"0.2"},"page_ordinal":"n","path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\web_store","was_installed_by_default":false},"aohghmighlieiainnegkcijnfilokake":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"w","content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413825196199","lastpingday":"13051978741602329","location":1,"manifest":{"api_console_project_id":"619683526622","app":{"launch":{"local_path":"main.html"}},"container":"GOOGLE_DRIVE","current_locale":"de","default_locale":"en_US","description":"Dokumente erstellen und bearbeiten","icons":{"128":"icon_128.png","16":"icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJhLK6fk/BWTEvJhywpk7jDe4A2r0bGXGOLZW4/AdBp3IiD9o9nx4YjLAtv0tIPxi7MvFd/GUUbQBwHT5wQWONJj1z/0Rc2qBkiJA0yqXh42p0snuA8dCfdlhOLsp7/XTMEwAVasjV5hC4awl78eKfJYlZ+8fM/UldLWJ/51iBQwIDAQAB","manifest_version":2,"name":"Google Docs","offline_enabled":true,"update_url":"https://clients2.google.com/service/update2/crx","version":"0.7"},"page_ordinal":"n","path":"aohghmighlieiainnegkcijnfilokake\\0.7_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"apdfllckaahabafndbhieahigkjlhalf":{"ack_external":true,"active_permissions":{"api":["background","clipboardRead","clipboardWrite","notifications","unlimitedStorage"],"manifest_permissions":[]},"app_launcher_ordinal":"y","content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["background","clipboardRead","clipboardWrite","notifications","unlimitedStorage"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13049413824190199","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"web_url":"https://drive.google.com/?usp=chrome_app"},"urls":["hxxp://docs.google.com/","hxxp://drive.google.com/","https://docs.google.com/","https://drive.google.com/"]},"background":{"allow_js_access":false},"current_locale":"de","default_locale":"en_US","description":"Google Drive: Alle Inhalte an einem Ort erstellen, teilen und speichern.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIl5KlKwL2TSkntkpY3naLLz5jsN0YwjhZyObcTOK6Nda4Ie21KRqZau9lx5SHcLh7pE2/S9OiArb+na2dn7YK5EvH+aRXS1ec3uxVlBhqLdnleVgwgwlg5fH95I52IeHcoeK6pR4hW/Nv39GNlI/Uqk6O6GBCCsAxYrdxww9BiQIDAQAB","manifest_version":2,"name":"Google Drive","offline_enabled":true,"options_page":"https://drive.google.com/settings","permissions":["background","clipboardRead","clipboardWrite","notifications","unlimitedStorage"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"6.3"},"page_ordinal":"n","path":"apdfllckaahabafndbhieahigkjlhalf\\6.3_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"z","creation_flags":153,"events":[],"from_bookmark":true,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"install_time":"13044126767875248","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"hxxp://www.youtube.com/?feature=ytca"},"web_content":{"enabled":true,"origin":"hxxp://www.youtube.com"}},"current_locale":"de","default_locale":"en","description":"Die beliebteste Online-Video-Community der Welt","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC/HotmFlyuz5FaHaIbVBhhL4BwbcUtsfWwzgUMpZt5ZsLB2nW/Y5xwNkkPANYGdVsJkT2GPpRRIKBO5QiJ7jPMa3EZtcZHpkygBlQLSjMhdrAKevpKgIl6YTkwzNvExY6rzVDzeE9zqnIs33eppY4S5QcoALMxuSWlMKqgFQjHQIDAQAB","manifest_version":2,"name":"YouTube","permissions":["appNotifications"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"4.2.6"},"page_ordinal":"n","path":"blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0","state":1,"was_installed_by_default":true},"booedmolknjekdopkepjjeckmjkdpfgl":{"active_permissions":{"api":["tabs","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["chrome://newtab/*","chrome://settings-frame/*","hxxp://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["chrome://settings-frame/*"]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811973196","location":5,"manifest":{"background":{"persistent":true,"scripts":["bk.js"]},"content_scripts":[{"js":["cs.js"],"matches":["chrome://settings-frame/*"]}],"content_security_policy":"default-src 'self'; script-src chrome://resources 'self' chrome://settings-frame 'unsafe-eval'; frame-src 'self' chrome://settings-frame; style-src 'self' 'unsafe-inline';object-src 'self';","description":"Extutil","incognito":"spanning","key":"MIAfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+ea9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Extutil","permissions":["chrome://newtab/","tabs","webNavigation","webRequest","webRequestBlocking","hxxp://*/*","https://*/*","chrome://settings-frame/"],"version":"0.1"},"path":"C:\\Users\\User\\AppData\\Local\\Temp\\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"yn","content_settings":[],"creation_flags":153,"events":[],"from_bookmark":true,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13049413823380199","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"web_url":"hxxp://www.google.com/webhp?source=search_app"},"urls":["*://www.google.com/search","*://www.google.com/webhp","*://www.google.com/imgres"]},"current_locale":"de","default_locale":"en","description":"Die schnellste Suche im Web.","icons":{"128":"128.png","16":"16.png","32":"32.png","48":"48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIiso3Loy5VJHL40shGhUl6it5ZG55XB9q/2EX6aa88jAxwPutbCgy5d9bm1YmBzLfSgpX4xcpgTU08ydWbd7b50fbkLsqWl1mRhxoqnN01kuNfv9Hbz9dWWYd+O4ZfD3L2XZs0wQqo0y6k64n+qeLkUMd1MIhf6MR8Xz1SOA8pwIDAQAB","manifest_version":2,"name":"Google-Suche","permissions":[],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"0.0.0.20"},"page_ordinal":"n","path":"coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","metricsPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"],"manifest_permissions":[]},"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"initial_keybindings_set":true,"install_time":"13044126764568239","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","metricsPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\bookmark_manager","was_installed_by_default":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":[],"explicit_host":["chrome://settings-frame/*"],"manifest_permissions":[]},"creation_flags":1,"events":["app.runtime.onLaunched"],"from_bookmark":false,"from_webstore":false,"initial_keybindings_set":true,"install_time":"13044126764569239","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.2"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\settings_app","running":false,"was_installed_by_default":false},"flpcjncodpafbgdpnkljologafpionhb":{"active_permissions":{"api":["tabs","webNavigation"],"explicit_host":["chrome://favicon/*","chrome://resources/*","chrome://settings-frame/*","hxxp://*.conduit.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qasite.com/*","hxxp://*.qatrovi.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.search.site.com/*","hxxp://*.trovi.com/*","hxxp://*.trovigo.com/*","hxxp://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["chrome://settings-frame/*","hxxp://*.conduit.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qasite.com/*","hxxp://*.qatrovi.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.search.site.com/*","hxxp://*.trovi.com/*","hxxp://*.trovigo.com/*"]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811983196","location":5,"manifest":{"background":{"page":"background___background.html","persistent":true},"content_scripts":[{"js":["cs.js"],"matches":["hxxp://*.conduit.com/*","hxxp://*.qasite.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qatrovi.com/*","hxxp://*.trovi.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.trovigo.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.search.site.com/*","chrome://settings-frame/*"]}],"content_security_policy":"default-src 'self'; script-src chrome://resources 'self' chrome://settings-frame 'unsafe-eval'; frame-src 'self' chrome://settings-frame; style-src 'self' 'unsafe-inline';object-src 'self';","description":"Managera","incognito":"spanning","key":"MIAfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Managera","permissions":["tabs","webNavigation","hxxp://*.conduit.com/*","hxxp://*.qasite.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qatrovi.com/*","hxxp://*.trovi.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.trovigo.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.search.site.com/*","chrome://favicon/","chrome://resources/","chrome://settings-frame/","chrome://resources/","hxxp://*/*","https://*/*"],"version":"0.1"},"path":"C:\\Users\\User\\AppData\\Local\\Temp\\38fdaae5-8e0e-493c-88ec-e05c3be06e42","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"gfdkimpbcpahaombhbimeihdjnejgicl":{"active_permissions":{"api":["feedbackPrivate"],"explicit_host":["chrome://resources/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":["feedbackPrivate.onFeedbackRequested"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811063196","location":5,"manifest":{"app":{"background":{"scripts":["js/event_handler.js"]},"content_security_policy":"default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"},"description":"User feedback extension","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"32":"http://www.trojaner-board.de/images/...":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\feedback","preferences":{},"regular_only_preferences":{},"running":false,"was_installed_by_default":false,"was_installed_by_oem":false},"kmendfapggjehodndflmmgagdbamhnfd":{"active_permissions":{"api":["hid","usb",{"usbDevices":[{"interfaceId":-1,"productId":512,"vendorId":4176},{"interfaceId":-1,"productId":529,"vendorId":4176}]},"webConnectable"],"explicit_host":["https://www.gstatic.com/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13051997892617208","location":5,"manifest":{"background":{"persistent":false,"scripts":["util.js","b64.js","closeable.js","countdown.js","sha256.js","llgnubby.js","llhidgnubby.js","llusbgnubby.js","gnubbies.js","gnubby.js","gnubby-u2f.js","gnubbycodetypes.js","gnubbyfactory.js","gnubbymsgtypes.js","usbgnubbyfactory.js","devicestatuscodes.js","enroller.js","enrollhelper.js","usbenrollhelper.js","requestqueue.js","signer.js","signhelper.js","singlesigner.js","multiplesigner.js","usbsignhelper.js","webrequest.js","background.js"]},"description":"CryptoToken Component Extension","externally_connectable":{"accepts_tls_channel_id":true,"matches":["https://login.corp.google.com/*","https://accounts.google.com/*","https://security.google.com/*"]},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7zRobvA+AVlvNqkHSSVhh1sEWsHSqz4oR/XptkDe/Cz3+gW9ZGumZ20NCHjaac8j1iiesdigp8B1LJsd/2WWv2Dbnto4f8GrQ5MVphKyQ9WJHwejEHN2K4vzrTcwaXqv5BSTXwxlxS/mXCmXskTfryKTLuYrcHEWK8fCHb+0gvr8b/kvsi75A1aMmb6nUnFJvETmCkOCPNX5CHTdy634Ts/x0fLhRuPlahk63rdf7agxQv5viVjQFk+tbgv6aa9kdSd11Js/RZ9yZjrFgHOBWgP4jTBqud4+HUglrzu8qynFipyNRLCZsaxhm+NItTyNgesxLdxZcwOz56KD1Q4IQIDAQAB","manifest_version":2,"name":"CryptoTokenExtension","permissions":["hid","usb",{"usbDevices":[{"productId":512,"vendorId":4176},{"productId":529,"vendorId":4176}]},"https://www.gstatic.com/"],"version":"0.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\36.0.1985.125\\resources\\cryptotoken","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"lifbcibllhkdhoafpjfnlhfpfgnpldfl":{"ack_prompt_count":1,"active_permissions":{"api":["tabs"],"explicit_host":["https://localhost:26143/*","https://pnrws.skype.com/*"],"manifest_permissions":[],"scriptable_host":["file:///*","hxxp://*/*","https://*/*"]},"content_settings":[],"creation_flags":9,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13051997901545329","lastpingday":"13051978741602329","location":6,"manifest":{"background":{"page":"background.html"},"browser_action":{"default_icon":{"19":"c2c_48x48.png"},"default_popup":"c2c_options_menu.html","default_title":"Skype Click to Call"},"content_scripts":[{"all_frames":true,"css":["number_highlighting.css","number_highlighting_ui1.css","number_highlighting_chrome.css","number_highlighting_chrome_ui1.css"],"js":["jquery-2.1.0.min.js","mutation-summary.js","localization.js","browserSpecificScript.js","number_highlighting_builder.js","pnr.js","fpnr.js","contentscript.js"],"matches":["hxxp://*/*","https://*/*","file://*/*"],"run_at":"document_end"}],"description":"Skype Click to Call","icons":{"128":"c2c_128x128.png","16":"c2c_16x16.png","48":"c2c_48x48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMxFysW3wPKWRPPe3xuJQz3m1ZDLX1hN8EYdP37tRPf7lp8vIhG4xirlXHGK748qcLPc4Lm8WsHDhvS5okN54Kwcnw4T2tBXSCZJxMmlu14HZ5yc/t969QLTPLIbAsasq4NVo40YuP2B7umxV9BlcxZEB9TEKPEQq8DRoKhj9jBQIDAQAB","manifest_version":2,"name":"Skype Click to Call","permissions":["tabs","https://pnrws.skype.com/","https://localhost:26143/"],"update_url":"https://clients2.google.com/service/update2/crx","version":"7.3.16540.9015","web_accessible_resources":["call_skype_logo.png","call_skype_logo_ui1.png","call_icon.png","call_icon_ui1.png","plus_icon_ui1.png","gift_icon_ui1.png","skype_icon_ui1.png","skypecredit_icon_ui1.png","learnmore_icon_ui1.png","menu_handler.js","telemetry.js"]},"path":"lifbcibllhkdhoafpjfnlhfpfgnpldfl\\7.3.16540.9015_0","preferences":{},"regular_only_preferences":{},"state":0,"was_installed_by_default":false,"was_installed_by_oem":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"],"manifest_permissions":[]},"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"install_time":"13044126764568239","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\cloud_print","was_installed_by_default":false},"mgndgikekgjfcpckkfioiadnlibdjbkf":{"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"t","creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"install_time":"13044126764569239","location":5,"manifest":{"app":{"launch":{"web_url":"hxxp://THIS-WILL-BE-REPLACED"}},"description":"Chrome as an app","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"product_logo_128.png","16":"product_logo_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB","name":"Chrome","version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\chrome_app","was_installed_by_default":false},"mkfokfffehpeedafpekjeddnmnjhmcmk":{"ack_external":true,"active_permissions":{"api":["history","management","plugin","tabs","webNavigation"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"content_settings":[],"creation_flags":9,"disable_reasons":1,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13051997903177329","lastpingday":"13051978741602329","location":3,"manifest":{"background":{"scripts":["background.js"]},"browser_action":{"default_icon":"http://www.trojaner-board.de/images/...title":"Norton Toolbar"},"content_scripts":[{"all_frames":true,"js":["docstart.js","wcid.js","wax.js"],"matches":["\u003Call_urls>"],"run_at":"document_start"}],"current_locale":"de","default_locale":"en","description":"Norton Safe Search and Safe Web warn you of dangerous sites when you search, shop or browse online.","icons":{"48":"http://www.trojaner-board.de/images/..."name":"Norton Security Toolbar","permissions":["tabs","history","webNavigation","management","\u003Call_urls>"],"plugins":[{"path":"npcoplgn.dll","public":true}],"requirements":{"plugins":{"npapi":false}},"update_url":"https://clients2.google.com/service/update2/crx","version":"2014.7.6.17","web_accessible_resources":["http://www.trojaner-board.de/images/...on":"Component extension providing speech via the Google network text-to-speech service.","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB","manifest_version":2,"name":"Google Network Speech","permissions":["systemPrivate","ttsEngine","https://www.google.com/"],"tts_engine":{"voices":[{"event_types":["start","end","error"],"gender":"female","lang":"en-US","remote":true,"voice_name":"Google US English"},{"event_types":["start","end","error"],"gender":"male","lang":"en-GB","remote":true,"voice_name":"Google UK English Male"},{"event_types":["start","end","error"],"gender":"female","lang":"en-GB","remote":true,"voice_name":"Google UK English Female"},{"event_types":["start","end","error"],"gender":"female","lang":"es-ES","remote":true,"voice_name":"Google Español"},{"event_types":["start","end","error"],"gender":"female","lang":"fr-FR","remote":true,"voice_name":"Google Français"},{"event_types":["start","end","error"],"gender":"female","lang":"it-IT","remote":true,"voice_name":"Google Italiano"},{"event_types":["start","end","error"],"gender":"female","lang":"de-DE","remote":true,"voice_name":"Google Deutsch"},{"event_types":["start","end","error"],"gender":"female","lang":"ja-JP","remote":true,"voice_name":"Google æ?¥æ?¬äºº"},{"event_types":["start","end","error"],"gender":"female","lang":"ko-KR","remote":true,"voice_name":"Google í??êµ*ì?"},{"event_types":["start","end","error"],"gender":"female","lang":"zh-CN","remote":true,"voice_name":"Google ä¸*å?½ç??"}]},"version":"1.0"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\network_speech_synthesis","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nkeimhogjdpnpccoofpliimaahmaaome":{"active_permissions":{"api":["alarms","desktopCapture","processes","webConnectable","webrtcAudioPrivate","webrtcLoggingPrivate","system.cpu"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811063196","location":5,"manifest":{"background":{"page":"background.html","persistent":false},"externally_connectable":{"matches":["https://*.google.com/hangouts*","*://localhost/*"]},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB","manifest_version":2,"name":"Google+ Hangouts","permissions":["alarms","desktopCapture","system.cpu","webrtcAudioPrivate","webrtcLoggingPrivate"],"version":"1.0"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\hangout_services","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nmmhkkegccagdldgiimedpiccmgmieda":{"ack_external":true,"active_permissions":{"api":["identity","webview"],"explicit_host":["https://checkout.google.com/*","https://sandbox.google.com/*","https://www.google.com/*","https://www.googleapis.com/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":137,"events":["app.runtime.onLaunched"],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413840238199","lastpingday":"13051978741602329","location":10,"manifest":{"app":{"background":{"scripts":["craw_background.js"]}},"current_locale":"de","default_locale":"en","description":"Google Wallet für digitale Produkte","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"128":"http://www.trojaner-board.de/images/..."name":"Google Wallet","oauth2":{"auto_approve":true,"client_id":"203784468217.apps.googleusercontent.com","scopes":["https://www.googleapis.com/auth/sierra","https://www.googleapis.com/auth/sierrasandbox","https://www.googleapis.com/auth/chromewebstore","https://www.googleapis.com/auth/chromewebstore.readonly"]},"permissions":["identity","webview","https://checkout.google.com/","https://sandbox.google.com/checkout/","https://www.google.com/","https://www.googleapis.com/*"],"update_url":"https://clients2.google.com/service/update2/crx","version":"0.0.6.1"},"path":"nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.1_1","preferences":{},"regular_only_preferences":{},"running":false,"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"pafkbggdmjlpgkdkcbjmhmfcdpncadgh":{"active_permissions":{"api":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":["alarms.onAlarm","identity.onSignInChanged","notifications.onButtonClicked","notifications.onClicked","notifications.onClosed","notifications.onPermissionLevelChanged","notifications.onShowSettings","pushMessaging.onMessage","runtime.onInstalled","runtime.onStartup","runtime.onSuspend","storage.onChanged"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049405312691241","location":5,"manifest":{"background":{"persistent":false,"scripts":["utility.js","cards.js","background.js"]},"description":"Integrates Google Now into Chrome.","icons":{"128":"http://www.trojaner-board.de/images/..."name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","\u003Call_urls>"],"version":"1.2.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\google_now","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"],"manifest_permissions":[]},"app_launcher_ordinal":"x","creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["notifications"],"manifest_permissions":[]},"install_time":"13044126766255248","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"de","default_locale":"en","description":"Schneller E-Mail-Dienst mit Suchfunktion und wenig Spam.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","name":"Google Mail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"7"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\7_0","state":1,"was_installed_by_default":true}}},"first_run_tabs":["hxxp://www.google.com/","hxxp://welcome_page"],"homepage":"http:\/\/www.google.com\/","homepage_is_newtabpage":false,"intl":{"accept_languages":"de-DE,de,en-US,en"},"invalidator":{"client_id":"xdVvvOQl5p3vhghiutFRVg=="},"media":{"device_id_salt":"NVqQsY+uH3966oeHliZMoA=="},"net":{"http_server_properties":{"servers":{"ajax.googleapis.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"chrome.google.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"}},"clients2.google.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"},"supports_spdy":true},"clients2.googleusercontent.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"},"supports_spdy":true},"fonts.googleapis.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"themes.googleusercontent.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"www.google-analytics.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"www.googleapis.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"},"supports_spdy":true}},"version":2}},"pinned_tabs":[],"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pattern_pairs":{},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"icon_version":2,"managed_user_id":"","name":"Erster Nutzer","per_host_zoom_levels":{"flightforum.ch":0.5227586988632231,"flightx.net":1.2239010857415449}},"savefile":{"default_directory":"C:\\Users\\User\\Downloads"},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":[""],"startup_urls_migration_time":"13049413810623196"},"sync_promo":{"show_on_first_run_allowed":false},"translate_accepted_count":{"en":0},"translate_blocked_languages":["de"],"translate_denied_count":{"en":4},"translate_site_blacklist":["thepiratebay.ee"],"translate_whitelists":{}}), Ersetzt,[a3426a5c700bb58120ea0200e91cec14]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by User on 15.08.2014 at 11:18:03,92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\l2fwmsro.default\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.08.2014 at 11:20:58,02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-08-2014
Ran by User (administrator) on USER-PC on 15-08-2014 11:26:11
Running from C:\Users\User\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
() C:\Windows\SysWOW64\ASGT.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Dropbox, Inc.) C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\User\Downloads\FRST64(2).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-11-29] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-11-29] (Atheros Commnucations)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-07-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-12-21] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694040 2014-07-22] (Adobe Systems Incorporated)
HKU\S-1-5-21-3873043628-1780199607-4098311539-1000\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [1400224 2013-09-03] (Adobe Systems Incorporated)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: localhost:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6DE76A2ECC72CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default
FF SelectedSearchEngine: Google
FF Homepage: www.google.ch
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DownThemAll! - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-07-17]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-09]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-09]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-09]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-09]
CHR Extension: (Skype Click to Call) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-08-08]
CHR Extension: (Norton Security Toolbar) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-07-09]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-09]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-09]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-03] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-21] (Avira Operations GmbH & Co. KG)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-17] ()
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed]
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327296 2012-11-29] (Atheros)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-05-17] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-07-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X]
S3 cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
R4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X]
S0 PxHlpa64; System32\drivers\PxHlpa64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-15 11:33 - 2014-08-15 11:33 - 00000000 ____D () C:\AdwCleaner
2014-08-15 11:32 - 2014-08-15 11:32 - 01356107 _____ () C:\Users\User\Downloads\adwcleaner_3.305.exe
2014-08-15 11:31 - 2014-08-15 11:31 - 00041069 _____ () C:\Users\User\Desktop\mbam.txt
2014-08-15 11:25 - 2014-08-15 11:25 - 02100224 _____ (Farbar) C:\Users\User\Downloads\FRST64(2).exe
2014-08-15 11:20 - 2014-08-15 11:21 - 00000824 _____ () C:\Users\User\Desktop\JRT.txt
2014-08-15 11:18 - 2014-08-15 11:18 - 00000000 ____D () C:\Windows\ERUNT
2014-08-15 11:16 - 2014-08-15 11:16 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
2014-08-15 11:16 - 2014-08-15 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-15 11:15 - 2014-08-15 11:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-15 11:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-15 11:15 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-15 11:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-15 11:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-15 11:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-15 11:04 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 11:04 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 11:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-15 11:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-15 11:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-15 11:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-14 15:30 - 2014-08-14 15:25 - 00000000 ____D () C:\Qoobox
2014-08-14 15:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-14 15:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-14 15:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-14 15:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-14 15:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-14 15:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-14 15:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-14 15:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-14 15:29 - 2014-08-14 15:28 - 00000000 ____D () C:\Windows\erdnt
2014-08-14 15:29 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-14 15:29 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-14 15:29 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 15:29 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 15:29 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 15:29 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 15:29 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-14 15:29 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 15:29 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-14 15:29 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 15:29 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-14 15:29 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 15:29 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-14 15:29 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 15:29 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-14 15:29 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 15:29 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-14 15:29 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-14 15:29 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 15:29 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 15:29 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 15:29 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-14 15:29 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-14 15:29 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-14 15:29 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 15:29 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 15:29 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 15:29 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-14 15:29 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 15:29 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 15:29 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-14 15:29 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-14 15:29 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 15:29 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 15:29 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-14 15:29 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 15:29 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 15:29 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 15:29 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 15:29 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-14 15:29 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 15:29 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-14 15:29 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-14 15:29 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 15:29 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 15:29 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 15:29 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 15:29 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 15:29 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-14 15:29 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 15:29 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 15:29 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 15:29 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-14 15:29 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-14 15:29 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 15:29 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 15:29 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-14 15:29 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-14 15:29 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-14 15:29 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-14 15:29 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-14 15:29 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-14 15:29 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-14 15:29 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-14 15:29 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-14 15:29 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-14 15:29 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-14 15:29 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-14 15:29 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 15:29 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 15:29 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 15:29 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 15:29 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 15:29 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 15:29 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 15:29 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 15:28 - 2014-08-14 15:28 - 05571579 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe
2014-08-14 15:28 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 15:28 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 15:27 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 15:27 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-14 15:25 - 2014-08-14 15:34 - 00034163 _____ () C:\ComboFix.txt
2014-08-14 15:24 - 2014-08-14 15:25 - 00000000 ____D () C:\ComboFix
2014-08-11 13:41 - 2014-08-11 13:41 - 00000087 _____ () C:\Users\User\Desktop\Maxi N.txt
2014-08-11 13:37 - 2014-08-11 13:37 - 00000000 ____D () C:\Users\User\Desktop\Adobe
2014-08-11 13:35 - 2014-08-11 13:35 - 00125999 _____ () C:\Users\User\Desktop\GMER.log
2014-08-11 13:32 - 2014-08-11 13:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\PDAppFlex
2014-08-11 13:25 - 2014-08-11 13:25 - 00000000 ___RD () C:\Users\User\Creative Cloud Files
2014-08-11 13:24 - 2014-08-11 13:24 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-08-11 13:24 - 2014-08-11 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-08-11 13:23 - 2014-08-11 13:23 - 00895120 _____ (Google Inc.) C:\Users\User\Downloads\GoogleEarthSetup.exe
2014-08-11 13:23 - 2014-08-11 13:23 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-08-11 13:23 - 2014-08-11 13:23 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-08-11 13:18 - 2014-08-11 13:18 - 00614792 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\CreativeCloudSet-Up.exe
2014-08-11 13:17 - 2014-08-11 13:17 - 00000265 _____ () C:\Users\User\Desktop\tesr.txt
2014-08-11 13:11 - 2014-08-11 13:11 - 00000533 _____ () C:\Users\Public\Desktop\Maps2Bgl_X.lnk
2014-08-11 13:11 - 2014-08-11 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maps2Bgl_X
2014-08-11 13:11 - 2004-08-03 23:54 - 01712128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2014-08-11 13:00 - 2014-08-11 13:00 - 00380416 _____ () C:\Users\User\Downloads\wwmvbxht.exe
2014-08-11 13:00 - 2014-08-11 13:00 - 00056496 _____ (GMER) C:\kxldapob.sys
2014-08-11 12:50 - 2014-08-11 12:57 - 00050783 _____ () C:\Users\User\Desktop\FRST.txt
2014-08-11 12:49 - 2014-08-11 12:49 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64(1).exe
2014-08-11 12:48 - 2014-08-11 12:48 - 00808704 _____ () C:\Windows\Minidump\081114-81214-01.dmp
2014-08-11 12:48 - 2014-08-11 12:48 - 00043878 _____ () C:\Users\User\Desktop\Addition.txt
2014-08-10 22:47 - 2014-08-10 22:48 - 00043878 _____ () C:\Users\User\Downloads\Addition.txt
2014-08-10 22:44 - 2014-08-15 11:26 - 00019111 _____ () C:\Users\User\Downloads\FRST.txt
2014-08-10 22:44 - 2014-08-15 11:26 - 00000000 ____D () C:\FRST
2014-08-10 22:44 - 2014-08-15 11:10 - 00449794 _____ () C:\Windows\PFRO.log
2014-08-10 22:43 - 2014-08-10 22:44 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-08-09 15:19 - 2014-08-09 15:19 - 00069340 _____ () C:\Users\User\Documents\OS 737 land loww 29.frc
2014-08-09 15:14 - 2014-08-09 15:14 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-08-09 15:06 - 2014-08-14 16:08 - 00000000 ____D () C:\Users\User\Desktop\Unbenannter Export
2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Users\User\Documents\ProcAlyzer Dumps
2014-08-09 14:59 - 2014-08-09 14:59 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe
2014-08-09 14:59 - 2014-08-09 14:59 - 00192698 _____ () C:\Users\User\Documents\LX563 climbing.frc
2014-08-09 14:54 - 2014-08-10 22:44 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log
2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-08-09 14:52 - 2014-08-09 14:52 - 00050477 _____ () C:\Users\User\Downloads\Defogger.exe
2014-08-09 14:52 - 2014-08-09 14:52 - 00000470 _____ () C:\Users\User\Downloads\defogger_disable.log
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\AppData\Local\gtk-2.0
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\.thumbnails
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drzewiecki Design
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 _____ () C:\Users\User\defogger_reenable
2014-08-09 14:51 - 2014-08-11 13:20 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-09 14:51 - 2014-08-11 12:48 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-09 14:50 - 2014-08-11 12:51 - 00000000 ____D () C:\$AVG
2014-08-09 14:50 - 2014-08-11 12:47 - 00000000 ____D () C:\ProgramData\AVG2014
2014-08-09 14:50 - 2014-08-09 14:50 - 00051469 _____ () C:\Users\User\Documents\LX563 taxi to rwy.frc
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\Abelssoft
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Local\Abelssoft
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Users\User\AppData\Roaming\DesktopIconGoodgame
2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-08-09 14:48 - 2014-08-09 14:48 - 01101648 _____ () C:\Users\User\Downloads\SpyBot Search Destroy - CHIP-Installer.exe
2014-08-09 14:46 - 2014-08-11 13:14 - 00000000 ____D () C:\Users\User\.gimp-2.8
2014-08-09 14:46 - 2014-08-11 12:47 - 00000000 ____D () C:\ProgramData\MFAData
2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData
2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\gegl-0.2
2014-08-09 14:44 - 2014-08-09 14:45 - 168801544 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_x64_all_2014_4744a7830.exe
2014-08-09 14:44 - 2014-08-09 14:44 - 00000894 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-08-09 14:43 - 2014-08-11 12:48 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-08-09 14:43 - 2014-08-09 14:44 - 00000000 ____D () C:\Program Files\GIMP 2
2014-08-09 14:41 - 2014-08-09 14:43 - 201035376 _____ (Emsisoft GmbH ) C:\Users\User\Downloads\EmsisoftAntiMalwareSetup.exe
2014-08-09 14:41 - 2014-08-09 14:41 - 90396104 _____ (The GIMP Team ) C:\Users\User\Downloads\gimp-2.8.10-setup.exe
2014-08-09 14:31 - 2014-08-09 14:31 - 00001490 _____ () C:\Users\User\AppData\Local\recently-used.xbel
2014-08-09 14:28 - 2014-08-09 14:47 - 00019279 _____ () C:\Users\User\Documents\LX563 pushback.frc
2014-08-08 21:20 - 2014-08-08 20:39 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtuali
2014-08-08 20:59 - 2014-08-08 20:59 - 00000000 ____D () C:\Users\User\AppData\Local\World_of_AI
2014-08-08 20:54 - 2014-08-09 14:57 - 00000000 ____D () C:\Users\User\Desktop\IG
2014-08-08 20:48 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\Desktop\WoAI
2014-08-08 20:41 - 2014-08-08 20:42 - 00000000 ____D () C:\Gramblr
2014-08-08 20:41 - 2014-08-08 20:41 - 00000654 _____ () C:\Users\User\Desktop\Gramblr.lnk
2014-08-08 20:41 - 2014-08-08 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gramblr
2014-07-21 18:29 - 2014-07-21 18:29 - 00055761 _____ () C:\Users\User\Documents\ab 738 to 28.frc
2014-07-21 18:25 - 2014-07-21 18:25 - 00028159 _____ () C:\Users\User\Documents\ab 738.frc
2014-07-21 18:19 - 2014-07-21 18:19 - 00000000 ____D () C:\Program Files (x86)\PMDG Operations Center
2014-07-21 18:10 - 2014-07-21 18:10 - 00036780 _____ () C:\Users\User\Documents\AB 737 descent.frc
2014-07-21 18:00 - 2014-07-21 18:00 - 00000000 ____D () C:\Users\User\AppData\Local\DriverToolkit
2014-07-21 17:59 - 2014-07-21 18:05 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit
2014-07-21 17:59 - 2014-07-21 17:59 - 02395840 _____ (Megaify Software ) C:\Users\User\Downloads\driver_setup.exe
2014-07-21 17:59 - 2014-07-21 17:59 - 00061940 _____ () C:\Users\User\Documents\Ab 737 takeoff 28 lszh.frc
2014-07-21 17:57 - 2014-07-21 17:57 - 00000000 ____D () C:\Users\User\AppData\Local\Skype
2014-07-21 17:56 - 2014-08-09 15:15 - 00000000 ____D () C:\ProgramData\Skype
2014-07-21 17:56 - 2014-08-09 14:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2014-07-21 17:56 - 2014-07-21 17:56 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-07-21 17:55 - 2014-07-21 17:55 - 01677928 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe
2014-07-21 17:52 - 2014-07-21 17:52 - 00022720 _____ () C:\Users\User\Documents\AB 737 pushback.frc
2014-07-17 12:33 - 2014-07-17 12:33 - 00112593 _____ () C:\Users\User\Documents\frfghjj.frc
2014-07-17 12:27 - 2014-07-17 12:27 - 00091207 _____ () C:\Users\User\Documents\AB2876 takeoff muc.frc
2014-07-17 12:26 - 2014-07-17 12:26 - 00098607 _____ () C:\Users\User\Documents\AB2876 landing ltaiä.frc
2014-07-17 12:13 - 2014-07-17 12:13 - 02050655 _____ (Anthony Ribeiro ) C:\Users\User\Downloads\Boeing 747-8i Lufthansa v1.00.exe
2014-07-17 12:12 - 2014-07-17 12:12 - 46507041 _____ (SkySpirit2012 ) C:\Users\User\Downloads\Boeing 747-8i Basepack v1.40.exe
2014-07-17 11:49 - 2014-07-17 11:49 - 00000000 ____D () C:\found.000
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-15 11:33 - 2014-08-15 11:33 - 00000000 ____D () C:\AdwCleaner
2014-08-15 11:32 - 2014-08-15 11:32 - 01356107 _____ () C:\Users\User\Downloads\adwcleaner_3.305.exe
2014-08-15 11:31 - 2014-08-15 11:31 - 00041069 _____ () C:\Users\User\Desktop\mbam.txt
2014-08-15 11:26 - 2014-08-10 22:44 - 00019111 _____ () C:\Users\User\Downloads\FRST.txt
2014-08-15 11:26 - 2014-08-10 22:44 - 00000000 ____D () C:\FRST
2014-08-15 11:25 - 2014-08-15 11:25 - 02100224 _____ (Farbar) C:\Users\User\Downloads\FRST64(2).exe
2014-08-15 11:21 - 2014-08-15 11:20 - 00000824 _____ () C:\Users\User\Desktop\JRT.txt
2014-08-15 11:20 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-15 11:20 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-15 11:18 - 2014-08-15 11:18 - 00000000 ____D () C:\Windows\ERUNT
2014-08-15 11:16 - 2014-08-15 11:16 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
2014-08-15 11:16 - 2014-08-15 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-15 11:16 - 2014-05-19 20:36 - 01838166 _____ () C:\Windows\WindowsUpdate.log
2014-08-15 11:15 - 2014-08-15 11:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-15 11:14 - 2014-05-09 18:44 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-15 11:13 - 2014-05-01 21:00 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
2014-08-15 11:12 - 2014-07-09 20:59 - 00000000 ___RD () C:\Users\User\Dropbox
2014-08-15 11:12 - 2014-07-09 20:52 - 00000000 ____D () C:\Users\User\AppData\Roaming\Dropbox
2014-08-15 11:11 - 2014-05-19 20:33 - 00018268 _____ () C:\Windows\setupact.log
2014-08-15 11:11 - 2014-05-09 18:32 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-15 11:11 - 2014-04-25 12:56 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-15 11:11 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-15 11:11 - 2009-07-14 06:45 - 00628392 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-15 11:10 - 2014-08-10 22:44 - 00449794 _____ () C:\Windows\PFRO.log
2014-08-15 11:09 - 2014-03-13 13:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 11:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-15 11:08 - 2014-05-02 21:45 - 00000000 ____D () C:\Users\User\Documents\Flight Simulator X-Dateien
2014-08-15 11:08 - 2014-05-02 12:32 - 00000000 ____D () C:\Program Files (x86)\FS Recorder for FSX
2014-08-15 11:08 - 2014-03-13 13:01 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-15 11:04 - 2014-05-09 18:32 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-15 11:04 - 2014-04-25 14:20 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 16:23 - 2011-04-12 09:43 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI
2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing
2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-08-14 16:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-08-14 16:08 - 2014-08-09 15:06 - 00000000 ____D () C:\Users\User\Desktop\Unbenannter Export
2014-08-14 15:34 - 2014-08-14 15:25 - 00034163 _____ () C:\ComboFix.txt
2014-08-14 15:34 - 2014-05-01 10:01 - 00000000 ____D () C:\ProgramData\TEMP
2014-08-14 15:28 - 2014-08-14 15:29 - 00000000 ____D () C:\Windows\erdnt
2014-08-14 15:28 - 2014-08-14 15:28 - 05571579 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe
2014-08-14 15:25 - 2014-08-14 15:30 - 00000000 ____D () C:\Qoobox
2014-08-14 15:25 - 2014-08-14 15:24 - 00000000 ____D () C:\ComboFix
2014-08-14 15:23 - 2014-05-03 12:04 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
2014-08-14 15:22 - 2014-07-09 20:59 - 00000976 _____ () C:\Users\User\Desktop\Dropbox.lnk
2014-08-14 15:22 - 2014-07-09 20:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-14 15:21 - 2014-07-09 20:55 - 00000000 ____D () C:\Program Files\Adobe
2014-08-14 15:20 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-11 13:41 - 2014-08-11 13:41 - 00000087 _____ () C:\Users\User\Desktop\Maxi N.txt
2014-08-11 13:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-11 13:37 - 2014-08-11 13:37 - 00000000 ____D () C:\Users\User\Desktop\Adobe
2014-08-11 13:35 - 2014-08-11 13:35 - 00125999 _____ () C:\Users\User\Desktop\GMER.log
2014-08-11 13:32 - 2014-08-11 13:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\PDAppFlex
2014-08-11 13:31 - 2014-05-01 21:00 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-11 13:25 - 2014-08-11 13:25 - 00000000 ___RD () C:\Users\User\Creative Cloud Files
2014-08-11 13:25 - 2014-04-25 11:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe
2014-08-11 13:24 - 2014-08-11 13:24 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk
2014-08-11 13:24 - 2014-08-11 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2014-08-11 13:24 - 2014-05-09 18:32 - 00000000 ____D () C:\Users\User\AppData\Local\Google
2014-08-11 13:24 - 2014-05-09 18:32 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-11 13:23 - 2014-08-11 13:23 - 00895120 _____ (Google Inc.) C:\Users\User\Downloads\GoogleEarthSetup.exe
2014-08-11 13:23 - 2014-08-11 13:23 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-08-11 13:23 - 2014-08-11 13:23 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-08-11 13:22 - 2014-05-02 17:56 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-11 13:20 - 2014-08-09 14:51 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-11 13:20 - 2014-05-01 21:00 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-11 13:18 - 2014-08-11 13:18 - 00614792 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\CreativeCloudSet-Up.exe
2014-08-11 13:17 - 2014-08-11 13:17 - 00000265 _____ () C:\Users\User\Desktop\tesr.txt
2014-08-11 13:14 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\.gimp-2.8
2014-08-11 13:11 - 2014-08-11 13:11 - 00000533 _____ () C:\Users\Public\Desktop\Maps2Bgl_X.lnk
2014-08-11 13:11 - 2014-08-11 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maps2Bgl_X
2014-08-11 13:00 - 2014-08-11 13:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-08-11 13:00 - 2014-08-11 13:00 - 00380416 _____ () C:\Users\User\Downloads\wwmvbxht.exe
2014-08-11 13:00 - 2014-08-11 13:00 - 00056496 _____ (GMER) C:\kxldapob.sys
2014-08-11 12:57 - 2014-08-11 12:50 - 00050783 _____ () C:\Users\User\Desktop\FRST.txt
2014-08-11 12:51 - 2014-08-09 14:50 - 00000000 ____D () C:\$AVG
2014-08-11 12:49 - 2014-08-11 12:49 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64(1).exe
2014-08-11 12:48 - 2014-08-11 12:48 - 00808704 _____ () C:\Windows\Minidump\081114-81214-01.dmp
2014-08-11 12:48 - 2014-08-11 12:48 - 00043878 _____ () C:\Users\User\Desktop\Addition.txt
2014-08-11 12:48 - 2014-08-09 14:51 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-11 12:48 - 2014-08-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-08-11 12:48 - 2014-05-19 20:33 - 1290543419 _____ () C:\Windows\MEMORY.DMP
2014-08-11 12:48 - 2014-05-17 17:07 - 00000000 ____D () C:\Windows\Minidump
2014-08-11 12:47 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\AVG2014
2014-08-11 12:47 - 2014-08-09 14:46 - 00000000 ____D () C:\ProgramData\MFAData
2014-08-11 12:47 - 2014-05-18 10:47 - 00000000 ____D () C:\ProgramData\Norton
2014-08-10 22:48 - 2014-08-10 22:47 - 00043878 _____ () C:\Users\User\Downloads\Addition.txt
2014-08-10 22:44 - 2014-08-10 22:43 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-08-10 22:44 - 2014-08-09 14:54 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log
2014-08-09 15:22 - 2014-07-09 23:51 - 00000472 _____ () C:\Windows\Pitch Target
2014-08-09 15:22 - 2014-07-09 23:51 - 00000466 _____ () C:\Windows\Roll Target
2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Roll Error
2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Pitch Error
2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Gyro Speed
2014-08-09 15:22 - 2014-07-09 23:51 - 00000423 _____ () C:\Windows\Mode2BTimer
2014-08-09 15:22 - 2014-07-09 23:51 - 00000423 _____ () C:\Windows\Mode2_AltGain_timer
2014-08-09 15:22 - 2014-07-09 23:51 - 00000419 _____ () C:\Windows\Mode2ATimer
2014-08-09 15:22 - 2014-07-09 23:51 - 00000271 _____ () C:\Windows\CDU.1
2014-08-09 15:22 - 2014-07-09 23:51 - 00000271 _____ () C:\Windows\CDU.0
2014-08-09 15:20 - 2014-05-01 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft
2014-08-09 15:19 - 2014-08-09 15:19 - 00069340 _____ () C:\Users\User\Documents\OS 737 land loww 29.frc
2014-08-09 15:16 - 2014-05-03 12:33 - 00024400 _____ () C:\Users\User\AppData\Roaming\Notepad2.ini
2014-08-09 15:15 - 2014-07-21 17:56 - 00000000 ____D () C:\ProgramData\Skype
2014-08-09 15:15 - 2014-04-25 11:27 - 00167000 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-09 15:14 - 2014-08-09 15:14 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Users\User\Documents\ProcAlyzer Dumps
2014-08-09 14:59 - 2014-08-09 14:59 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe
2014-08-09 14:59 - 2014-08-09 14:59 - 00192698 _____ () C:\Users\User\Documents\LX563 climbing.frc
2014-08-09 14:57 - 2014-08-08 20:54 - 00000000 ____D () C:\Users\User\Desktop\IG
2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-08-09 14:52 - 2014-08-09 14:52 - 00050477 _____ () C:\Users\User\Downloads\Defogger.exe
2014-08-09 14:52 - 2014-08-09 14:52 - 00000470 _____ () C:\Users\User\Downloads\defogger_disable.log
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\AppData\Local\gtk-2.0
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\.thumbnails
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drzewiecki Design
2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 _____ () C:\Users\User\defogger_reenable
2014-08-09 14:52 - 2014-08-08 20:48 - 00000000 ____D () C:\Users\User\Desktop\WoAI
2014-08-09 14:50 - 2014-08-09 14:50 - 00051469 _____ () C:\Users\User\Documents\LX563 taxi to rwy.frc
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\Abelssoft
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Local\Abelssoft
2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\XDMessagingv4
2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Users\User\AppData\Roaming\DesktopIconGoodgame
2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater
2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater
2014-08-09 14:48 - 2014-08-09 14:48 - 01101648 _____ () C:\Users\User\Downloads\SpyBot Search Destroy - CHIP-Installer.exe
2014-08-09 14:47 - 2014-08-09 14:28 - 00019279 _____ () C:\Users\User\Documents\LX563 pushback.frc
2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData
2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\gegl-0.2
2014-08-09 14:45 - 2014-08-09 14:44 - 168801544 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_x64_all_2014_4744a7830.exe
2014-08-09 14:45 - 2014-07-09 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations
2014-08-09 14:45 - 2014-04-25 11:15 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-09 14:44 - 2014-08-09 14:44 - 00000894 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-08-09 14:44 - 2014-08-09 14:43 - 00000000 ____D () C:\Program Files\GIMP 2
2014-08-09 14:43 - 2014-08-09 14:41 - 201035376 _____ (Emsisoft GmbH ) C:\Users\User\Downloads\EmsisoftAntiMalwareSetup.exe
2014-08-09 14:41 - 2014-08-09 14:41 - 90396104 _____ (The GIMP Team ) C:\Users\User\Downloads\gimp-2.8.10-setup.exe
2014-08-09 14:39 - 2014-05-01 20:01 - 00000000 ____D () C:\Users\User\AppData\Roaming\uTorrent
2014-08-09 14:34 - 2014-07-09 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Sony
2014-08-09 14:34 - 2014-07-09 16:47 - 00000000 ____D () C:\Program Files\Sony
2014-08-09 14:34 - 2014-07-09 16:46 - 00000000 ____D () C:\ProgramData\Sony
2014-08-09 14:33 - 2014-05-18 19:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-08-09 14:32 - 2014-07-21 17:56 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2014-08-09 14:31 - 2014-08-09 14:31 - 00001490 _____ () C:\Users\User\AppData\Local\recently-used.xbel
2014-08-09 14:28 - 2014-05-18 19:41 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-09 14:28 - 2014-05-18 19:41 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-08 21:18 - 2014-08-08 21:17 - 18205840 _____ (VIRTUALI Sagl ) C:\Users\User\Downloads\setup_addonmanagerX.exe
2014-08-08 21:18 - 2014-08-08 21:15 - 247433295 ____R () C:\Users\User\Downloads\FSX - Aerosoft Nice-Cote d'Azur.zip
2014-08-08 21:18 - 2014-05-01 09:54 - 00000000 ____D () C:\ProgramData\Esellerate
2014-08-08 20:59 - 2014-08-08 20:59 - 00000000 ____D () C:\Users\User\AppData\Local\World_of_AI
2014-08-08 20:42 - 2014-08-08 20:41 - 00000000 ____D () C:\Gramblr
2014-08-08 20:41 - 2014-08-08 20:41 - 00000654 _____ () C:\Users\User\Desktop\Gramblr.lnk
2014-08-08 20:41 - 2014-08-08 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gramblr
2014-08-08 20:39 - 2014-08-08 21:20 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtuali
2014-08-08 20:32 - 2014-04-30 21:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-07 04:06 - 2014-08-14 15:27 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-14 15:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-01 01:41 - 2014-08-14 15:29 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-01 01:16 - 2014-08-14 15:29 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-25 16:52 - 2014-08-14 15:29 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-25 16:02 - 2014-08-14 15:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-25 16:01 - 2014-08-14 15:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-25 15:51 - 2014-08-14 15:29 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-25 15:30 - 2014-08-14 15:29 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-25 15:28 - 2014-08-14 15:29 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-25 15:28 - 2014-08-14 15:29 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-25 15:25 - 2014-08-14 15:29 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-25 15:25 - 2014-08-14 15:29 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-25 15:11 - 2014-08-14 15:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-25 15:10 - 2014-08-14 15:29 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-25 15:04 - 2014-08-14 15:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-25 15:03 - 2014-08-14 15:29 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-25 15:00 - 2014-08-14 15:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-25 15:00 - 2014-08-14 15:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-25 14:59 - 2014-08-14 15:29 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-25 14:47 - 2014-08-14 15:29 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-25 14:40 - 2014-08-14 15:29 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-25 14:34 - 2014-08-14 15:29 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-25 14:34 - 2014-08-14 15:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-25 14:33 - 2014-08-14 15:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-25 14:30 - 2014-08-14 15:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-25 14:28 - 2014-08-14 15:29 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-25 14:28 - 2014-08-14 15:29 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 14:21 - 2014-08-14 15:29 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-25 14:19 - 2014-08-14 15:29 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-25 14:18 - 2014-08-14 15:29 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-25 14:17 - 2014-08-14 15:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-25 14:17 - 2014-08-14 15:29 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-25 14:12 - 2014-08-14 15:29 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-25 14:10 - 2014-08-14 15:29 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-25 14:10 - 2014-08-14 15:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-25 14:08 - 2014-08-14 15:29 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-25 14:06 - 2014-08-14 15:29 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-25 13:52 - 2014-08-14 15:29 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-25 13:47 - 2014-08-14 15:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-25 13:43 - 2014-08-14 15:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-25 13:42 - 2014-08-14 15:29 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-25 13:39 - 2014-08-14 15:29 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-25 13:39 - 2014-08-14 15:29 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-25 13:36 - 2014-08-14 15:29 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-25 13:34 - 2014-08-14 15:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-25 13:29 - 2014-08-14 15:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-25 13:23 - 2014-08-14 15:29 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-25 13:13 - 2014-08-14 15:29 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-25 13:07 - 2014-08-14 15:29 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-25 13:07 - 2014-08-14 15:29 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-25 13:03 - 2014-08-14 15:29 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-25 12:52 - 2014-08-14 15:29 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-25 12:26 - 2014-08-14 15:29 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-25 12:17 - 2014-08-14 15:29 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-25 12:09 - 2014-08-14 15:29 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-25 12:05 - 2014-08-14 15:29 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-25 12:00 - 2014-08-14 15:29 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-21 18:40 - 2014-05-02 13:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2014-07-21 18:39 - 2014-05-04 19:56 - 00000000 ____D () C:\Users\User\Desktop\Addons
2014-07-21 18:29 - 2014-07-21 18:29 - 00055761 _____ () C:\Users\User\Documents\ab 738 to 28.frc
2014-07-21 18:25 - 2014-07-21 18:25 - 00028159 _____ () C:\Users\User\Documents\ab 738.frc
2014-07-21 18:23 - 2014-07-09 22:00 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-07-21 18:23 - 2014-07-09 22:00 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-07-21 18:19 - 2014-07-21 18:19 - 00000000 ____D () C:\Program Files (x86)\PMDG Operations Center
2014-07-21 18:10 - 2014-07-21 18:10 - 00036780 _____ () C:\Users\User\Documents\AB 737 descent.frc
2014-07-21 18:05 - 2014-07-21 17:59 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit
2014-07-21 18:00 - 2014-07-21 18:00 - 00000000 ____D () C:\Users\User\AppData\Local\DriverToolkit
2014-07-21 17:59 - 2014-07-21 17:59 - 02395840 _____ (Megaify Software ) C:\Users\User\Downloads\driver_setup.exe
2014-07-21 17:59 - 2014-07-21 17:59 - 00061940 _____ () C:\Users\User\Documents\Ab 737 takeoff 28 lszh.frc
2014-07-21 17:57 - 2014-07-21 17:57 - 00000000 ____D () C:\Users\User\AppData\Local\Skype
2014-07-21 17:56 - 2014-07-21 17:56 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-07-21 17:56 - 2014-05-02 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-07-21 17:56 - 2014-05-02 17:56 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-07-21 17:55 - 2014-07-21 17:55 - 01677928 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe
2014-07-21 17:52 - 2014-07-21 17:52 - 00022720 _____ () C:\Users\User\Documents\AB 737 pushback.frc
2014-07-21 17:49 - 2014-07-09 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-17 12:33 - 2014-07-17 12:33 - 00112593 _____ () C:\Users\User\Documents\frfghjj.frc
2014-07-17 12:27 - 2014-07-17 12:27 - 00091207 _____ () C:\Users\User\Documents\AB2876 takeoff muc.frc
2014-07-17 12:26 - 2014-07-17 12:26 - 00098607 _____ () C:\Users\User\Documents\AB2876 landing ltaiä.frc
2014-07-17 12:16 - 2014-07-09 20:59 - 00000000 ____D () C:\Lightroom 5
2014-07-17 12:13 - 2014-07-17 12:13 - 02050655 _____ (Anthony Ribeiro ) C:\Users\User\Downloads\Boeing 747-8i Lufthansa v1.00.exe
2014-07-17 12:12 - 2014-07-17 12:12 - 46507041 _____ (SkySpirit2012 ) C:\Users\User\Downloads\Boeing 747-8i Basepack v1.40.exe
2014-07-17 12:03 - 2014-07-09 21:00 - 00000000 ____D () C:\Users\User\Documents\Adobe
2014-07-17 11:58 - 2014-07-09 20:56 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-07-17 11:50 - 2014-05-03 09:14 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-07-17 11:49 - 2014-07-17 11:49 - 00000000 ____D () C:\found.000
2014-07-16 05:25 - 2014-08-14 15:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-07-16 05:23 - 2014-08-14 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-07-16 04:46 - 2014-08-14 15:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-07-16 04:46 - 2014-08-14 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-07-16 04:12 - 2014-08-14 15:29 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\avgnt.exe
C:\Users\User\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp31exai.dll
C:\Users\User\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-09 15:26
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- |