powerheinz | 13.11.2014 16:06 | Hier die Dateien:
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 12.11.2014
Suchlauf-Zeit: 19:39:43
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.11.12.08
Rootkit Datenbank: v2014.11.12.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Heinz
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 389515
Verstrichene Zeit: 14 Min, 45 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.SpeedTest.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jljheddigenhleadfofeccneimcmlefp, In Quarantäne, [3badca706e0e95a12efe4c2262a15aa6],
PUP.Optional.ReMarkit.A, HKU\S-1-5-21-1327107963-4175824153-2169469409-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Re_markit, In Quarantäne, [c523ac8e26565adcb8243007c83b8c74],
PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1327107963-4175824153-2169469409-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nikpibnbobmbdbheedjfogjlikpgpnhp, In Quarantäne, [8761043617658caa3c33f6438d7605fb],
Registrierungswerte: 1
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Mysearchdial, In Quarantäne, [f7f1bd7d2953d26409853613bc47dc24]
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[37b158e2f389082ee862ed583bca7b85]
Ordner: 3
PUP.Optional.SpeedTest.A, C:\Users\Heinz\AppData\Roaming\speedtest4354, In Quarantäne, [0fd91624502c5dd95c5838cbe51e49b7],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
Dateien: 34
Trojan.BProtector, C:\Users\Heinz\AppData\Roaming\speedtest4354\install_helper.exe, In Quarantäne, [27c1fb3fc2ba7db9fb63847af31135cb],
Trojan.Malpack, C:\Users\Heinz\AppData\Local\Temp\67EA.tmp, In Quarantäne, [6187da60f78551e5784a06d60ef3ec14],
Trojan.Malpack, C:\Users\Heinz\AppData\Local\Temp\680A.tmp, In Quarantäne, [fcecc377d4a8b383dfe4eeee936e6799],
Trojan.Malpack, C:\Users\Heinz\AppData\Local\Temp\83C.tmp, In Quarantäne, [3aaea09a1369a2949033518b0001cb35],
PUP.Optional.QuickStart.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx, In Quarantäne, [d216c6742c50082eade54df011f26e92],
PUP.Optional.SpeedTest.A, C:\Users\Heinz\AppData\Roaming\speedtest4354\install_helper.exe, In Quarantäne, [0fd91624502c5dd95c5838cbe51e49b7],
PUP.Optional.SpeedTest.A, C:\Users\Heinz\AppData\Roaming\speedtest4354\speedtest4354.crx, In Quarantäne, [0fd91624502c5dd95c5838cbe51e49b7],
PUP.Optional.SpeedTest.A, C:\Users\Heinz\AppData\Roaming\speedtest4354\speedtest4354.xpi, In Quarantäne, [0fd91624502c5dd95c5838cbe51e49b7],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\background.html, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\button.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\ci.bg.pack.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\ci.browser.helper.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\ci.content.pack.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\content.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon128.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon128.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon16.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon16.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon18.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon18.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon24.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon24.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon32.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon32.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon48.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon48.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon64.ico, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\icon64.png, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\jquery-1.9.1.min.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\jquery.uuid.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\manifest.json, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\popup.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\rjs.js, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
PUP.Optional.SpeedAnalysis.A, C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jljheddigenhleadfofeccneimcmlefp\3.0.0.0\settings.json, In Quarantäne, [12d697a3562686b02b914fb4c3402ad6],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
AdwCleanerS1.txt
AdwCleaner Logfile: Code:
# AdwCleaner v4.101 - Bericht erstellt am 13/11/2014 um 15:27:38
# Aktualisiert 09/11/2014 von Xplode
# Database : 2014-11-12.2 [Live]
# Betriebssystem : Windows 8 Pro (64 bits)
# Benutzername : Heinz - HEINZ-WIN8
# Gestartet von : D:\Downloads\Trojaner Board\AdwCleaner_4.101.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\PC Cleaner
Ordner Gelöscht : C:\Program Files (x86)\wiseconvert
Ordner Gelöscht : C:\Users\Heinz\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Users\Heinz\daemonprocess.txt
Datei Gelöscht : C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage
***** [ Tasks ] *****
Task Gelöscht : AmiUpdXp
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F1963E76-845B-474C-8C7F-D69A96D8AA34}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawarebp
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17116
-\\ Mozilla Firefox v32.0.3 (x86 de)
-\\ Google Chrome v
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=b8e90340-3d15-4eb4-bcac-b1dc1d3b8659&searchtype=ds&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=b8e90340-3d15-4eb4-bcac-b1dc1d3b8659&searchtype=ds&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=b8e90340-3d15-4eb4-bcac-b1dc1d3b8659&searchtype=ds&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.nationzoom.com/web/?type=ds&ts=1389894747&from=amt&uid=WDCXWD3000HLFS-01G6U0_WD-WX60C592519325193&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_12_ie&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDtDyE0A0FyEtCtB0D0CyBtN0D0Tzu0SzztCtDtN1L2XzutBtFtCzztFyBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StA0B0FtCyC0ByEyCtGyC0AyByCtGzyzzyDyDtG0Ezy0E0CtGyBzy0CyE0D0ByC0ByEtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyDyDtBtAzy0BtGzy0D0CtAtG0AyEyB0CtGyD0EtD0DtGyD0FyDtA0FtB0FtDzytB0EyB2Q&cr=1219713004&ir=
-\\ Chromium v
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=b8e90340-3d15-4eb4-bcac-b1dc1d3b8659&searchtype=ds&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=b8e90340-3d15-4eb4-bcac-b1dc1d3b8659&searchtype=ds&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=DE&userid=b8e90340-3d15-4eb4-bcac-b1dc1d3b8659&searchtype=ds&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.nationzoom.com/web/?type=ds&ts=1389894747&from=amt&uid=WDCXWD3000HLFS-01G6U0_WD-WX60C592519325193&q={searchTerms}
[C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=ir_14_12_ie&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyDtDyE0A0FyEtCtB0D0CyBtN0D0Tzu0SzztCtDtN1L2XzutBtFtCzztFyBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StA0B0FtCyC0ByEyCtGyC0AyByCtGzyzzyDyDtG0Ezy0E0CtGyBzy0CyE0D0ByC0ByEtB0CtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyCyDyDtBtAzy0BtGzy0D0CtAtG0AyEyB0CtGyD0EtD0DtGyD0FyDtA0FtB0FtDzytB0EyB2Q&cr=1219713004&ir=
*************************
AdwCleaner[R0].txt - [49066 octets] - [16/01/2014 19:36:12]
AdwCleaner[R1].txt - [6477 octets] - [22/03/2014 17:31:45]
AdwCleaner[R2].txt - [1169 octets] - [28/03/2014 17:43:50]
AdwCleaner[R3].txt - [1289 octets] - [28/03/2014 17:47:48]
AdwCleaner[R4].txt - [1410 octets] - [28/03/2014 17:50:51]
AdwCleaner[R5].txt - [1627 octets] - [19/04/2014 08:04:44]
AdwCleaner[R6].txt - [8314 octets] - [13/11/2014 15:20:53]
AdwCleaner[S0].txt - [45080 octets] - [16/01/2014 19:37:39]
AdwCleaner[S1].txt - [5480 octets] - [22/03/2014 17:33:39]
AdwCleaner[S2].txt - [1231 octets] - [28/03/2014 17:45:05]
AdwCleaner[S3].txt - [1351 octets] - [28/03/2014 17:48:25]
AdwCleaner[S4].txt - [1690 octets] - [19/04/2014 08:05:30]
AdwCleaner[S5].txt - [9846 octets] - [13/11/2014 15:27:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [9906 octets] ########## --- --- ---
[/CODE]
JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.7 (11.08.2014:1)
OS: Windows 8 Pro x64
Ran by Heinz on 13.11.2014 at 15:32:54,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{09610820-A937-4FFD-8DA3-30BDB5351524}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{09C08306-A3CB-411B-AEE8-96FD57ABE6EA}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{0D2B3E53-C7DD-4B2F-BDC0-10CFE1A3A80D}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{0F04CC4F-EBBB-4DE9-93CA-C72D4284C35D}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{108B8146-2179-4030-8D6C-20987321CD84}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{10EC440A-6333-4D31-B583-287B8B5A1D63}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{12E3986B-08F1-44C4-B757-FAD7A7EFF422}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{13C19CDB-7121-4EA6-99D0-60D76DF3ED50}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{17897CAD-53CB-48DC-B7AF-77ABA6C2C56A}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{1BBC1C89-5F00-40AB-A531-832A705A3632}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{20A4053D-2CF0-4333-BE90-2C37B66496AB}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{295D65C5-97B9-4722-9FDE-2D8DED89C4BC}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{2A85CB1C-FAAB-4130-BD72-A92D8A7C7433}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{2AF55C39-53AE-473C-A70F-B171BEF3F855}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{2BA23D6A-2B4F-4FEF-A790-7A972D2F554C}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{3184CB7A-6319-49B8-8C98-1895CAF591AC}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{31AF5EAB-60A8-4D93-8342-A3D0334123A4}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{3562B73A-CB3C-4E71-BCB9-6B58091DE6E7}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{36C275B6-18EC-407C-A0A5-7FBBE4549DB6}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{387DBFD1-6735-40A7-AEEF-DD4BD5A0CEB1}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{3F098A85-7809-49A8-9245-46D383552F60}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{4057F64A-8DAF-40AA-9E50-0F653810ECE4}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{4073DF31-DB58-4B13-ACFE-C4BE45A468F7}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{49071886-FF32-4B8D-8ED2-85BB4A4BDC18}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{4B3E1992-CA24-42FE-B19C-12299F732ED2}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{4DBFDD39-EA92-4BD8-BDC0-E0BE2A707A95}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{4F888B0A-C3C3-421B-9136-DC8C269858D5}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{50B9575B-0A87-4BB7-AA59-69F16C69A381}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{5184A34D-6A7E-450B-BC7A-FFACF59B4467}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{58D9C506-A71D-4D12-86AF-642E2F98D32F}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{5A2CE045-4837-414A-89C7-B26DAAF61FA9}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{5C495438-4751-4F7D-9F17-618E0810FEBA}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{5F9AD3C1-590F-44E2-BC80-61BFF15198A9}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{605AFCD6-E475-4EA4-ABED-83AD3708874E}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{61B5BCB5-9334-4B1E-8E83-C63949DA42E1}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{6454F59A-06D8-4137-B6A8-34E0D3FDAC22}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{64D09400-1F79-4CB3-9E6B-213419762F20}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{66DB5CED-8595-46B9-B35A-D43888EECBD3}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{716A7D90-D467-4CB8-A70A-C633D50507FD}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{760DDBA1-A8A4-4D14-BCEC-7C13CFF73385}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{76990AA0-FC8E-4CF6-A290-C9B886C94BCE}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{7922C334-3D83-4FEB-AD67-114D7C93B68C}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{7B0C4FBB-C1DF-408C-9E38-D4D7B5EE4C0A}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{7C341470-A4DF-4034-AE85-0D1F3C2E78AB}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{7D87E45E-426A-459F-A1F6-F7BA045DBDCE}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{7F0DCB86-8B82-4275-9BBB-BD8DA90FABBE}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{7F42F1CA-EB93-46A9-B465-42BAB307C84F}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{86BA8644-B1E8-4EF2-BD10-B756BB9FB1F2}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{887C1DDA-461F-4283-85C0-048BE4624476}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{89F97128-BEC9-4992-9B13-CE3A4587848F}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{8B500145-A003-489C-A3A3-FF8E7A335EFF}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{8BCF32B8-7A02-4065-8031-E5C5663896E6}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{8DDBC56C-59CE-4A25-8ADA-A3133B1B8507}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{92E83217-1386-45FF-B172-4BB76FE6972C}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{93D12DE0-9269-4C3E-B7E9-B9CDC25D9377}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{942DF5C4-4ACA-484E-957E-43A02084F8ED}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{9556F891-0F06-4D62-B174-FF5B71C13AB6}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{A07B04A0-BCE7-4EE3-9452-D921F350478A}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{A0E3F1CF-3B5B-4C78-89EA-D9CBC2C05BB6}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{A3148605-9B45-47C1-A96D-31466F05FC41}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{A8AA0E70-A20C-4A05-88EE-1D11791FBF8F}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{A8EF2428-F08A-4879-A010-484E52617972}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{A940A812-5EA9-4C7D-968C-C7E6ED6251DC}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{AB5C4D0E-83EF-48E0-8C81-8F26633293D1}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{ACAE3C69-2F14-4A2E-BED5-16C8BB0DDBB3}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{AE2530E1-55F9-438C-B63B-D624E43B97DC}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{AEECB1CA-3C04-493E-B962-EEEE2C2DB214}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{AFF6E179-58A6-472C-ACB6-9D09FD326056}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{B22B7FF2-A672-49FD-8145-A5D5822FC89D}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{B6F49149-ABC9-434B-A3BF-A069D5E3458B}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{B7916B52-3C3D-496C-9439-2769AD0C44D4}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{B8312255-0127-4B0D-9A0F-33FA0CD6E8C1}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{B83D477E-69A8-48D9-B2A4-D58A58C0C8E3}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{BCE0D061-0ABC-41CF-9FA6-7C4DBCCFC776}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{C0A57119-8B53-4AAF-BE24-C04E5DE4B127}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{C1CF6791-2E74-4593-BF1E-F01D1EC10E23}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{C9C333BA-9F9D-4962-94C0-07633FCAAD95}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{CBCF5106-1150-4928-8270-B5053240767F}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{CCD776CD-F4D9-4299-BE43-AE73AC4D70E8}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{D5205583-9DAE-4C8A-8D05-A1AA2A2BF795}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{D852A33A-C8A2-47D8-92F2-CD46D4106E02}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DA5D758C-730A-4942-B5D7-3CAA2C2D0F80}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DB621C1A-1C14-4761-A0D6-D6C12ED4EEEB}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DC020136-AB72-4A8E-9AD9-78BE65188B00}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DC409315-98D8-41CA-87D4-2CF58118C4C1}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DDD7AA71-E53F-4E35-9F27-8FDACB36A26C}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DE3DC2CB-368B-40FB-B553-FC8E3205D728}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{DF485CD1-9DC9-4144-B7F1-07CF594137BB}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{E06944CB-BBD6-4AB2-BB02-DCD79501E3BD}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{E07A387E-494B-4F4E-9D19-98DD121352ED}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{E1EB5C73-8D66-4669-9F6B-EC7708FD967D}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{E31E06EA-4007-4F59-ADEF-D7A5B6159ACD}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{E4BE334E-635D-4D17-B633-CC649439092A}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{E9D3E7D4-259F-4F78-AB59-87757706A770}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{EB90F6A5-A3E4-486E-B0B3-FD4A9D584915}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{EE189148-8692-4ED0-9C3B-FFEC2D9FDE52}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{EF1DFC7F-AFF3-414B-A58A-17520F1E725B}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{F387D74E-92A9-4E1E-8FCC-005B1B10CA48}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{F3B30B92-4FDD-4704-861B-86C4671F70B0}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{F58AE35F-59B7-4CCB-908A-6D990E123A87}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{F8A40B7E-C9DE-41AA-8F9B-844BF2500558}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{FC467BED-8FE0-4900-BFCF-ABBDD7F8E54B}
Successfully deleted: [Empty Folder] C:\Users\Heinz\appdata\local\{FDBB3A18-D951-4FD9-827B-B763A37CF866}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.11.2014 at 15:55:15,78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FIRST.txt
[CODE]

FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-11-2014 01
Ran by Heinz (administrator) on HEINZ-WIN8 on 13-11-2014 15:59:28
Running from D:\Downloads\Trojaner Board
Loaded Profile: Heinz (Available profiles: Heinz & DefaultAppPool)
Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Advanced Micro Devices, Inc.) C:\ATI\ATI.ACE\Fuel\Fuel.Service.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanNetService.exe
(REINER SCT) C:\WINDOWS\SysWOW64\cjpcsc.exe
() C:\WINDOWS\DAODx.exe
(DTS) C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
(Microsoft Corporation) C:\WINDOWS\System32\dasHost.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.4.6792.0\AdAwareService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
() C:\WINDOWS\SysWOW64\PSIService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(Akamai Technologies, Inc.) C:\Users\Heinz\AppData\Local\Akamai\netsession_win.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Akamai Technologies, Inc.) C:\Users\Heinz\AppData\Local\Akamai\netsession_win.exe
(AVM Berlin) C:\Program Files (x86)\avmwlanstick\WLanGUI.exe
(ZF Electronics GmbH) C:\Program Files (x86)\Cherry\KeyMan\KeyMan.exe
(ZF Electronics GmbH) C:\Program Files (x86)\Cherry\CDI\cdi.exe
(ZF Electronics GmbH) C:\Program Files (x86)\Common Files\Cherry\Common\kbdhook64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
((주)마í¬ì•*니) C:\Program Files (x86)\MarkAny\ContentSafer\MaAgent.exe
(CANON INC.) C:\Program Files (x86)\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe
() C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(SAMSUNG ELECTRONICS) C:\Program Files (x86)\Samsung\Samsung Media Studio 5\SMSTray.exe
(RAPOO) C:\Program Files (x86)\Rapoo\RP24G\RP24G_Config.exe
() C:\Program Files (x86)\Rapoo\RP24G\LedStatus.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe
(Check Point Software Technologies Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
(Advanced Micro Devices Inc.) C:\ATI\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\ATI\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\WINDOWS\splwow64.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-25] (CANON INC.)
HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [itype] => C:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation)
HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6468712 2012-03-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.4.6792.0\AdAwareTray.exe [8925504 2014-10-15] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVMWlanClient] => C:\Program Files (x86)\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [75048 2009-08-28] (cyberlink)
HKLM-x32\...\Run: [CherryKeyMan] => C:\Program Files (x86)\Cherry\KeyMan\KeyMan.exe [258100 2009-07-29] (ZF Electronics GmbH)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-19] ()
HKLM-x32\...\Run: [MAAgent] => C:\Program Files (x86)\MarkAny\ContentSafer\MAAgent.exe [57344 2007-01-30] ((주)마í¬ì•*니)
HKLM-x32\...\Run: [MDS_Menu] => C:\Program Files (x86)\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM-x32\...\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1406248 2011-04-08] (Nero AG)
HKLM-x32\...\Run: [PDUiP6600DMon] => C:\Program Files (x86)\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe [75376 2006-10-03] (CANON INC.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2009-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [Philips Device Listener] => C:\Program Files (x86)\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe [380416 2012-03-19] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [RemoteControl8] => C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [91432 2009-07-16] (CyberLink Corp.)
HKLM-x32\...\Run: [SMSTray] => C:\Program Files (x86)\Samsung\Samsung Media Studio 5\SMSTray.exe [126976 2007-02-23] (SAMSUNG ELECTRONICS)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-17] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe [210216 2009-10-23] (CyberLink Corp.)
HKLM-x32\...\Run: [Rapoo RP24G] => C:\Program Files (x86)\Rapoo\RP24G\RP24G_Config.exe [5386752 2012-09-19] (RAPOO)
HKLM-x32\...\Run: [LedStatus] => C:\Program Files (x86)\Rapoo\RP24G\LedStatus.exe [1701888 2012-02-20] ()
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1163264 2012-09-25] ()
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-05-30] (Check Point Software Technologies Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\ATI\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\Run: [Google Update] => C:\Users\Heinz\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-10-30] (Google Inc.)
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2013-04-19] (Nokia)
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\Run: [SystemExplorerAutoStart] => C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2513920 2011-01-04] (Mister Group)
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\Run: [BrowserChoice] => C:\Windows\BrowserChoice\browserchoice.exe [86696 2012-08-15] (Microsoft Corporation)
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Heinz\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x91000000
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\MountPoints2: {88fb2212-00b7-11e1-8067-bcaec504af41} - "Q:\pushinst.exe"
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\MountPoints2: {8a25c12d-74d0-11e0-88bc-bcaec504af41} - "F:\LaunchU3.exe" -a
HKU\S-1-5-21-1327107963-4175824153-2169469409-1000\...\MountPoints2: {9717af58-2931-11e3-be81-bc054307648b} - "J:\LaunchU3.exe" -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Akruto Sync.lnk
ShortcutTarget: Akruto Sync.lnk -> C:\Program Files\Akruto\AkrutoSync.exe (Akruto)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/?gws_rd=ssl
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKLM-x32 - (No Name) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll (pdfforge GmbH)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll (pdfforge GmbH)
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
DPF: HKLM {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.4.2/jinstall-1_4-windows-i586.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab
DPF: HKLM-x32 {65EEE2E1-B8D5-4724-8489-048B551045BF} https://karte.santanderbank.de/gei/plugins/SantanderChipcardPlugin1212.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
ShellExecuteHooks-x32: ShellHook Class - {88485281-8b4b-4f8d-9ede-82e29a064277} - C:\Program Files (x86)\MarkAny\ContentSafer\MACSMANAGER.dll [192512 2004-11-23] (MarkAny Cooperation.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Heinz\AppData\Roaming\Mozilla\Firefox\Profiles\0fjzdvst.default-1396025695923
FF Homepage: https://meine.deutsche-bank.de/trxm/db/init.do?logintab=WebSign
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @soe.sony.com/installer,version=1.0.3 -> C:\Users\Heinz\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-1327107963-4175824153-2169469409-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Heinz\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1327107963-4175824153-2169469409-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Heinz\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1327107963-4175824153-2169469409-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-05-09]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-05-09]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-05-09]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-10-31]
Chrome:
=======
CHR Profile: C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-30]
CHR Extension: (Google Search) - C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-30]
CHR Extension: (Gmail) - C:\Users\Heinz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\ATI\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed]
S4 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363616 2014-01-03] (Microsoft Corporation)
S4 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748640 2014-01-03] (Microsoft Corporation)
R3 Cherry Device Interface; C:\Program Files (x86)\Cherry\CDI\cdi.exe [585774 2009-05-28] (ZF Electronics GmbH) [File not signed]
R2 cjpcsc; C:\WINDOWS\SysWOW64\cjpcsc.exe [515632 2013-05-21] (REINER SCT)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft) [File not signed]
R2 DTSAudioService; C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe [210024 2011-05-31] (DTS)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.4.6792.0\AdAwareService.exe [707888 2014-10-15] ()
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2011-03-04] (Hewlett-Packard Company) [File not signed]
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 MSMQ; C:\Windows\system32\mqsvc.exe [25088 2012-07-26] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
U2 ProtexisLicensing; C:\Windows\SysWOW64\PSIService.exe [177704 2007-06-05] ()
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-07-02] () [File not signed]
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [471552 2012-07-26] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [29184 2012-07-03] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [36352 2012-07-03] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\system32\DRIVERS\lgandnetndis64.sys [93184 2012-07-04] (LG Electronics Inc.)
R2 AODDriver4.3; C:\ATI\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [13368 2009-07-06] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [215040 2013-12-19] (Advanced Micro Devices)
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin)
R1 BdfNdisf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfndisf6.sys [97816 2013-07-17] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Firewall Engine\1.6.0.0\Drivers\bdfwfpf.sys [107080 2013-07-17] (BitDefender LLC)
R3 cjusb; C:\Windows\system32\DRIVERS\cjusb.sys [35192 2012-09-04] (REINER SCT)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-18] (Windows (R) Win 7 DDK provider)
R3 fwlanusbn; C:\Windows\system32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH)
R3 gzflt; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Antimalware Engine\3.0.0.56\gzflt.sys [150256 2014-04-22] (BitDefender LLC)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2014-04-30] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2014-04-30] (Kaspersky Lab)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [92768 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [490080 2014-04-30] (Kaspersky Lab ZAO)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [185856 2012-07-26] (Microsoft Corporation)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
R3 rpkmdrv; C:\Windows\system32\drivers\rpkmdrv.sys [21248 2012-08-16] ()
S3 slabbus; C:\Windows\System32\drivers\slabbus.sys [88360 2014-07-04] (MCCI Corporation)
S3 slabser; C:\Windows\system32\DRIVERS\slabser.sys [112424 2014-07-04] (MCCI Corporation)
S3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [389240 2014-04-22] (BitDefender S.R.L.)
R1 Vsdatant; C:\Windows\System32\drivers\vsdatant.sys [450968 2014-05-30] (Check Point Software Technologies Ltd.)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [64000 2012-07-26] (Microsoft Corporation)
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl [146928 2009-08-28] (CyberLink Corp.)
S3 AODDriver4.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
S2 AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [X]
U3 idsvc; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-13 15:55 - 2014-11-13 15:55 - 00011783 _____ () C:\Users\Heinz\Desktop\JRT.txt
2014-11-13 15:32 - 2014-11-13 15:32 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-11-13 15:31 - 2014-11-13 15:31 - 00001357 _____ () C:\Users\Heinz\Desktop\AdwCleaner_4.101.lnk
2014-11-12 20:03 - 2014-11-13 15:28 - 00014112 _____ () C:\WINDOWS\PFRO.log
2014-11-12 19:38 - 2014-11-13 15:58 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-11-12 19:38 - 2014-11-12 19:38 - 00001115 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-12 19:38 - 2014-11-12 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-12 19:38 - 2014-11-12 19:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-12 19:38 - 2014-11-12 19:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-12 19:38 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-11-12 19:38 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-11-12 19:38 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-11-11 19:43 - 2014-11-13 15:28 - 00061208 _____ () C:\WINDOWS\setupact.log
2014-11-11 19:43 - 2014-11-11 19:43 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-11-11 15:15 - 2014-11-13 15:40 - 00087483 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-10 19:27 - 2014-11-13 15:59 - 00000000 ____D () C:\FRST
2014-11-08 12:28 - 2014-11-09 10:48 - 00000000 ____D () C:\WINDOWS\system32\AutoUpdateLicense
2014-11-08 12:27 - 2014-10-22 04:34 - 00010777 _____ () C:\WINDOWS\system32\AutoconfigV2.cab
2014-11-08 12:27 - 2014-10-22 04:33 - 00581016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AutoUpdate.exe
2014-11-08 12:27 - 2014-10-22 04:33 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationUI.exe
2014-11-08 12:27 - 2014-10-22 02:08 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-11-08 12:27 - 2014-10-22 02:08 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-11-08 12:27 - 2014-10-22 02:01 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-11-08 12:27 - 2014-10-22 02:01 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2014-11-08 12:27 - 2014-10-22 02:01 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-11-08 12:27 - 2014-10-22 02:00 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2014-11-07 09:01 - 2014-11-07 09:01 - 00000000 ____D () C:\Users\Heinz\AppData\Local\PDFCreator
2014-10-31 17:41 - 2014-10-31 17:41 - 00001026 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-10-31 17:40 - 2014-10-31 17:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-10-31 17:39 - 2014-10-31 17:39 - 00110776 _____ (pdfforge GmbH) C:\WINDOWS\system32\pdfcmon.dll
2014-10-31 17:39 - 2014-10-31 17:39 - 00000845 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-10-31 17:39 - 2014-10-31 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-10-28 19:45 - 2014-10-28 19:45 - 00000000 ____D () C:\Users\Heinz\AppData\Roaming\PDF Architect 2
2014-10-28 19:26 - 2014-10-31 17:41 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-10-28 19:25 - 2014-11-05 19:22 - 00000000 ____D () C:\Program Files\PDFCreator
2014-10-28 19:25 - 2014-10-28 19:25 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-10-28 18:51 - 2012-05-16 08:10 - 00000000 ____D () C:\Users\Heinz\Desktop\CP210x_VCP_Win7
2014-10-24 07:22 - 2014-09-13 07:24 - 02233152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-10-24 07:22 - 2014-09-06 01:46 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-10-24 07:22 - 2014-09-03 03:48 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2014-10-24 07:22 - 2014-09-03 03:48 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2014-10-24 07:22 - 2014-09-03 03:22 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2014-10-24 07:22 - 2014-09-03 03:21 - 00623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2014-10-24 07:22 - 2014-09-03 03:21 - 00212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2014-10-24 07:22 - 2014-08-29 05:17 - 02043392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2014-10-24 07:22 - 2014-08-29 05:17 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2014-10-24 07:22 - 2014-08-29 05:04 - 02837504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-10-24 07:22 - 2014-08-29 05:04 - 00309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2014-10-24 07:22 - 2014-08-28 07:04 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSCOMEX.dll
2014-10-24 07:22 - 2014-08-28 07:04 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2014-10-24 07:22 - 2014-08-28 06:59 - 00616448 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2014-10-24 07:22 - 2014-08-28 06:59 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2014-10-24 07:22 - 2014-08-28 06:59 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSTIFF.dll
2014-10-24 07:22 - 2014-08-28 06:59 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXST30.dll
2014-10-24 07:22 - 2014-07-24 14:12 - 00328512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-10-24 07:21 - 2014-09-18 00:24 - 02416128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-10-24 07:21 - 2014-09-17 23:56 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-10-23 13:27 - 2014-10-23 13:28 - 00000000 ____D () C:\Program Files (x86)\GUM103C.tmp
2014-10-22 16:30 - 2014-10-22 16:30 - 00001251 _____ () C:\Users\Heinz\Desktop\fritz.box.lnk
2014-10-19 17:53 - 2014-10-19 17:53 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-10-19 17:53 - 2014-10-19 17:53 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-10-19 09:38 - 2014-10-19 09:38 - 00000253 _____ () C:\Users\Heinz\Spraydosen.txt
2014-10-19 09:02 - 2014-10-19 09:03 - 00000000 ____D () C:\Program Files (x86)\GUM6277.tmp
2014-10-18 17:45 - 2014-10-18 17:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2014-10-18 17:44 - 2014-10-18 17:44 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-10-17 15:03 - 2014-10-17 15:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!Box
2014-10-17 15:03 - 2014-10-17 15:03 - 00000000 ____D () C:\Program Files (x86)\FRITZ!BoxPrint
2014-10-17 15:03 - 2014-10-17 15:03 - 00000000 ____D () C:\Program Files (x86)\FRITZ!Box
2014-10-17 15:03 - 2006-12-14 13:42 - 00069120 ____R (AVM Berlin) C:\WINDOWS\SysWOW64\avmadd32.dll
2014-10-17 15:03 - 2006-05-29 02:00 - 00016384 ____R (AVM Berlin GmbH) C:\WINDOWS\SysWOW64\avmprmon.dll
2014-10-17 10:40 - 2014-09-29 23:49 - 00705480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-10-17 10:40 - 2014-09-29 23:49 - 00104904 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-17 10:26 - 2014-09-20 06:16 - 19280896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-10-17 10:26 - 2014-09-20 04:57 - 14368768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-10-17 10:26 - 2014-09-13 06:29 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-10-17 10:26 - 2014-09-13 05:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-10-17 10:26 - 2014-09-03 03:48 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-10-17 10:26 - 2014-09-03 03:21 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-10-17 10:26 - 2014-07-07 06:53 - 01125376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2014-10-17 10:26 - 2014-07-07 06:52 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-10-17 10:26 - 2014-07-07 06:52 - 00724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-10-17 10:26 - 2014-07-07 06:52 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsta.dll
2014-10-17 10:26 - 2014-07-07 06:51 - 05982208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-10-17 10:26 - 2014-07-07 05:01 - 01049600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2014-10-17 10:26 - 2014-07-07 05:01 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsta.dll
2014-10-17 10:26 - 2014-07-07 05:00 - 05095424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-10-17 10:26 - 2014-07-07 04:59 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aaclient.dll
2014-10-17 10:25 - 2014-09-20 06:18 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-10-17 10:25 - 2014-09-20 06:17 - 02236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-10-17 10:25 - 2014-09-20 06:17 - 01407488 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-10-17 10:25 - 2014-09-20 06:17 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2014-10-17 10:25 - 2014-09-20 06:17 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 15399424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 02655232 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-10-17 10:25 - 2014-09-20 06:16 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-10-17 10:25 - 2014-09-20 06:15 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-10-17 10:25 - 2014-09-20 06:15 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-10-17 10:25 - 2014-09-20 06:15 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 13757952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 02861568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 01762816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 01180672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-10-17 10:25 - 2014-09-20 04:57 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-10-17 10:25 - 2014-09-20 04:56 - 01440768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-10-17 10:25 - 2014-09-20 04:56 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-10-17 10:25 - 2014-09-20 04:56 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-10-17 10:25 - 2014-09-20 04:38 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-10-17 10:25 - 2014-09-20 04:33 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-10-17 10:25 - 2014-09-20 02:06 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2014-10-15 17:40 - 2014-10-15 17:40 - 00000000 ____D () C:\WINDOWS\SysWOW64\Adobe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-13 15:35 - 2012-07-26 11:27 - 00871150 _____ () C:\WINDOWS\system32\perfh007.dat
2014-11-13 15:35 - 2012-07-26 11:27 - 00199216 _____ () C:\WINDOWS\system32\perfc007.dat
2014-11-13 15:35 - 2012-07-26 08:28 - 02057842 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-13 15:32 - 2011-05-02 17:38 - 00001130 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-13 15:30 - 2013-08-11 15:20 - 00000000 ____D () C:\Users\Heinz\AppData\Local\Akruto
2014-11-13 15:29 - 2014-03-23 18:52 - 00002314 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2014-11-13 15:29 - 2011-05-02 17:38 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-13 15:29 - 2011-05-02 17:00 - 00000000 ____D () C:\Users\Heinz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2014-11-13 15:28 - 2012-07-26 08:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-13 15:27 - 2014-01-16 19:36 - 00000000 ____D () C:\AdwCleaner
2014-11-13 15:27 - 2013-08-16 08:33 - 00000000 ____D () C:\Users\Heinz
2014-11-13 15:27 - 2011-05-02 17:47 - 00002566 _____ () C:\WINDOWS\UltraEdit
2014-11-13 15:27 - 2011-05-02 17:46 - 00012706 _____ () C:\WINDOWS\UEDIT32.INI
2014-11-13 15:17 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-11-13 12:07 - 2012-10-30 16:49 - 00001142 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1327107963-4175824153-2169469409-1000UA.job
2014-11-12 20:03 - 2012-07-26 09:12 - 00000000 __RSD () C:\WINDOWS\Media
2014-11-12 18:16 - 2014-06-28 15:40 - 00000000 ____D () C:\Users\Heinz\AppData\Local\DoNotTrackPlus
2014-11-11 20:43 - 2012-07-26 06:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-11-11 20:41 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\rescache
2014-11-11 20:15 - 2012-07-26 06:26 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-11-11 19:45 - 2012-05-11 09:05 - 00000000 ____D () C:\Users\Heinz\AppData\Local\CrashDumps
2014-11-10 14:55 - 2011-05-02 17:07 - 00000000 ____D () C:\Temp
2014-11-10 14:32 - 2011-05-02 16:09 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-08 12:28 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\WinStore
2014-11-08 12:28 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-11-07 16:17 - 2014-04-29 17:49 - 00000432 _____ () C:\WINDOWS\BRWMARK.INI
2014-11-07 16:16 - 2011-05-03 11:14 - 00000544 _____ () C:\WINDOWS\I_VIEW32.INI
2014-11-07 13:38 - 2011-12-29 09:49 - 00000000 ____D () C:\Users\Heinz\AppData\Roaming\Skype
2014-11-07 13:29 - 2011-12-29 09:49 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-11-07 13:29 - 2011-12-29 09:49 - 00000000 ____D () C:\ProgramData\Skype
2014-11-07 10:07 - 2012-10-30 16:49 - 00001090 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1327107963-4175824153-2169469409-1000Core.job
2014-11-07 09:34 - 2013-11-07 15:39 - 00000000 ____D () C:\Users\Heinz\AppData\Roaming\vlc
2014-10-31 17:41 - 2013-06-26 16:04 - 00030665 ____H () C:\WINDOWS\SysWOW64\BTImages.dat
2014-10-30 09:09 - 2012-10-30 16:50 - 00002370 _____ () C:\Users\Heinz\Desktop\Google Chrome.lnk
2014-10-29 12:59 - 2013-08-16 09:04 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1327107963-4175824153-2169469409-1000
2014-10-27 15:19 - 2014-02-20 19:22 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-10-24 10:56 - 2012-07-26 09:12 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-10-24 10:46 - 2014-09-21 12:30 - 00439352 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-10-24 08:07 - 2012-07-26 09:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-23 13:27 - 2011-05-02 17:38 - 00004102 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-23 13:27 - 2011-05-02 17:38 - 00003866 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-19 17:54 - 2013-10-19 10:55 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-19 17:53 - 2014-08-11 14:58 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-10-19 17:53 - 2014-08-11 14:58 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-10-19 09:02 - 2012-10-30 16:49 - 00004092 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1327107963-4175824153-2169469409-1000UA
2014-10-19 09:02 - 2012-10-30 16:49 - 00003712 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1327107963-4175824153-2169469409-1000Core
2014-10-17 15:43 - 2014-02-28 13:41 - 00000851 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Akruto Sync.lnk
2014-10-17 15:43 - 2014-02-28 13:41 - 00000839 _____ () C:\Users\Public\Desktop\Akruto Sync.lnk
2014-10-17 15:43 - 2014-02-28 13:41 - 00000000 ____D () C:\Program Files\Akruto
2014-10-17 10:32 - 2013-08-01 16:12 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-17 10:26 - 2011-05-02 15:48 - 103265616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Heinz\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Heinz\AppData\Local\Temp\Quarantine.exe
C:\Users\Heinz\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-13 15:39
==================== End Of Log ============================ --- --- ---
Viele Grüße, Heinz |