Tobi428833 | 15.12.2014 19:43 | Hi, hier einmal die gmer.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-12-2014
Ran by Mimi (administrator) on TOBI on 14-12-2014 22:10:24
Running from C:\Users\Mimi\Downloads
Loaded Profile: Mimi (Available profiles: Mimi)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Windows\PLFSetI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-11] (Egis Technology Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2009-11-20] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-18] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-09-24] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1094736 2009-11-02] (Dritek System Inc.)
HKLM-x32\...\Run: [ArcadeDeluxeAgent] => C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [419112 2009-10-06] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Mimi\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [39712 2014-10-22] (Overwolf LTD)
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1940160 2014-11-18] (Valve Corporation)
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22041192 2014-08-27] (Skype Technologies S.A.)
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\MountPoints2: E - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\MountPoints2: {26f4c788-5575-11e4-bad8-00262d8748bc} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\MountPoints2: {b157b662-02a2-11e4-a3d6-00262d8748bc} - E:\HTC_Sync_Manager_PC.exe
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll (Egis Technology Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://tikotin.com
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll No File
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1469723594-2657416431-1904025529-1000 -> No Name - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No File
Toolbar: HKU\S-1-5-21-1469723594-2657416431-1904025529-1000 -> No Name - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - No File
Toolbar: HKU\S-1-5-21-1469723594-2657416431-1904025529-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Winsock: Catalog9-x64 01 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 02 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 03 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 04 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 15 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{41DDF4E7-E417-4274-9078-418E7185998D}: [NameServer] 80.237.196.2,194.150.168.168
FireFox:
========
FF ProfilePath: C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Profiles\37judds5.default
FF SearchEngineOrder.1: Improved Search
FF SelectedSearchEngine: SafeFinder Search
FF NewTab: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1469723594-2657416431-1904025529-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mimi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Adblock Plus - C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Profiles\37judds5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-06]
FF Extension: No Name - C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Profiles\37judds5.default\extensions\boost@boost.net.xpi [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.mmoga.de/adventskalender.html?ref=683
CHR StartupUrls: Default -> "https://www.google.de/?gws_rd=ssl", "hxxp://www.facebook.com/", "hxxp://www.youtube.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Angry Birds) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-09-30]
CHR Extension: (Google Docs) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-24]
CHR Extension: (Google Drive) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-24]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-30]
CHR Extension: (YouTube) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-24]
CHR Extension: (Facebook) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2014-09-30]
CHR Extension: (Bouncy Mouse) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdllcbmneiklcmbeclfegccdjholomb [2014-09-30]
CHR Extension: (Google-Suche) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-24]
CHR Extension: (Weißes Rauschen) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkjpdnomgodmagfmhojepjlajpoicip [2014-09-30]
CHR Extension: (PanicButton) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\faminaibgiklngmfpfbhmokfmnglamcm [2014-09-30]
CHR Extension: (AdBlock) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-30]
CHR Extension: (AudioSauna) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2014-09-30]
CHR Extension: (Need for Speed World) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk [2014-09-30]
CHR Extension: (Google Wallet) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-30]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2014-09-30]
CHR Extension: (Picasa) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-09-30]
CHR Extension: (Red Bull TV) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbalkogcfbpplioohgihkidalmomblfc [2014-09-30]
CHR Extension: (Psykopaint) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2014-09-30]
CHR Extension: (Google Mail) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-24]
CHR Extension: (eBay WOW! Angebote) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pllkgmcojhajjmojfoagiegoibjognlc [2014-09-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-11] (Egis Technology Inc.)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [997664 2014-10-22] (Overwolf LTD)
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe [126392 2011-11-07] (Symantec Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 b786bdb3c67d; C:\Windows\System32\drivers\b786bdb3c67d.sys [46920 2014-11-20] (Windows (R) Win 7 DDK provider)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-08-22] (Sony Mobile Communications)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [41168 2014-11-19] (NetFilterSDK.com)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed]
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S3 IlvMoneyDRIVER53; \??\C:\Users\Mimi\Desktop\MoonLight_Engine_1236.4.0.18\MoonLight Engine 1236.4.0.18\Money1280.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-14 22:11 - 2014-12-14 22:11 - 00380416 _____ () C:\Users\Mimi\Downloads\Gmer-19357.exe
2014-12-14 22:10 - 2014-12-14 22:11 - 00022341 _____ () C:\Users\Mimi\Downloads\FRST.txt
2014-12-14 22:10 - 2014-12-14 22:10 - 00000000 ____D () C:\FRST
2014-12-14 22:09 - 2014-12-14 22:09 - 02119680 _____ (Farbar) C:\Users\Mimi\Downloads\FRST64.exe
2014-12-14 21:10 - 2014-12-14 21:11 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-14 21:10 - 2014-12-14 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-14 21:10 - 2014-12-14 21:10 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware_old
2014-12-14 21:10 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-14 21:10 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-14 21:10 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-14 21:02 - 2014-12-14 21:02 - 00000000 ____D () C:\Users\Mimi\Documents\PC Speed Maximizer
2014-12-14 20:59 - 2014-12-14 21:02 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Mimi\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-14 20:57 - 2014-12-14 20:57 - 00000000 ____D () C:\MININT
2014-12-14 20:53 - 2014-12-14 20:53 - 00054956 _____ () C:\Users\Mimi\Desktop\firewall snap-in - SysProfile Forum.htm
2014-12-14 20:53 - 2014-12-14 20:53 - 00000000 ____D () C:\Users\Mimi\Desktop\firewall snap-in - SysProfile Forum_files
2014-12-14 20:51 - 2014-12-14 20:51 - 00724800 _____ ( ) C:\Users\Mimi\Downloads\IDM2-Win-EN.exe
2014-12-14 10:40 - 2014-12-14 10:40 - 00013233 _____ () C:\Users\Mimi\Desktop\Realtek HD Audio-Manager.lnk
2014-12-12 00:23 - 2014-12-12 00:23 - 00000000 ____D () C:\Users\Mimi\Documents\Optimizer Pro
2014-12-12 00:03 - 2014-12-12 00:03 - 00000000 ____D () C:\Users\Mimi\AppData\Local\WorldofTanks
2014-12-12 00:03 - 2014-12-12 00:03 - 00000000 ____D () C:\Users\Mimi\AppData\Local\Pirates
2014-12-12 00:02 - 2014-12-12 00:02 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Windows Essentials Codec Pack
2014-12-11 23:59 - 2014-12-11 23:59 - 00790656 _____ ( ) C:\Users\Mimi\Downloads\WindowsCodec.exe
2014-12-09 14:13 - 2014-12-09 14:14 - 00000000 ____D () C:\Users\Mimi\Documents\Wondershare DVD Slideshow Builder Standard
2014-12-09 14:13 - 2014-12-09 14:13 - 00000000 ____D () C:\ProgramData\Wondershare
2014-12-09 14:12 - 2014-12-09 14:12 - 00000000 ____D () C:\Program Files (x86)\Wondershare
2014-12-09 14:07 - 2014-12-09 14:10 - 37893168 _____ (WonderShare Software Co.,Ltd. ) C:\Users\Mimi\Downloads\dvdslideshow-hd-photo_full757.exe
2014-12-09 11:13 - 2014-12-09 11:13 - 00380416 _____ () C:\Users\Mimi\Downloads\vkujklc4.exe
2014-12-09 11:13 - 2014-12-09 11:13 - 00380416 _____ () C:\Users\Mimi\Downloads\d4wfje5z.exe
2014-12-09 11:13 - 2014-12-09 11:13 - 00370943 _____ () C:\Users\Mimi\Downloads\gmer.zip
2014-12-09 11:12 - 2014-12-09 11:12 - 00380416 _____ () C:\Users\Mimi\Downloads\xkkkoi20.exe
2014-12-09 10:36 - 2014-12-09 10:36 - 00000005 _____ () C:\end
2014-12-08 16:23 - 2014-12-08 16:23 - 00000695 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-12-08 16:23 - 2014-12-08 16:23 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\TS3Client
2014-12-08 16:23 - 2014-12-08 16:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-12-08 16:22 - 2014-12-08 16:23 - 00000000 ____D () C:\ts3undso
2014-12-08 16:18 - 2014-12-08 16:20 - 32155104 _____ (TeamSpeak Systems GmbH) C:\Users\Mimi\Downloads\TeamSpeak3-Client-win64-3.0.7.exe
2014-12-08 16:15 - 2014-12-08 16:15 - 00000000 ____D () C:\Users\Mimi\Desktop\teamspeak3-server_win64-3.0.11.1
2014-12-08 16:15 - 2014-12-08 16:14 - 04522122 _____ () C:\Users\Mimi\Desktop\teamspeak3-server_win64-3.0.11.1.zip
2014-12-08 16:14 - 2014-12-08 16:14 - 04522122 _____ () C:\Users\Mimi\Downloads\teamspeak3-server_win64-3.0.11.1.zip
2014-12-08 16:13 - 2014-12-08 16:14 - 04155977 _____ () C:\Users\Mimi\Downloads\teamspeak3-server_win32-3.0.11.1.zip
2014-12-08 02:10 - 2014-12-11 19:23 - 00000009 _____ () C:\Users\Mimi\Desktop\pw_WMC.txt
2014-12-07 21:27 - 2014-12-07 21:27 - 00031880 _____ () C:\Users\Mimi\Desktop\anti_backdoor.rar
2014-12-07 21:23 - 2014-12-07 21:24 - 00000000 ____D () C:\Users\Mimi\Desktop\anti_backdoor_und_beleidigung
2014-12-07 11:32 - 2014-12-07 11:32 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Mimi\Downloads\TeamSpeak3-Client-win64-3.0.16.exe
2014-12-07 11:32 - 2014-12-07 11:32 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Mimi\Downloads\TeamSpeak3-Client-win64-3.0.16 (1).exe
2014-12-07 11:30 - 2014-12-07 11:30 - 00000000 ____D () C:\Users\Mimi\Desktop\ts undso
2014-12-05 20:38 - 2014-12-05 20:38 - 00001934 _____ () C:\Users\Mimi\Desktop\MTA San Andreas.lnk
2014-11-30 23:28 - 2014-11-30 23:37 - 00014150 _____ () C:\Users\Mimi\Desktop\chrome.exe - Verknüpfung.lnk
2014-11-30 20:37 - 2014-11-30 20:37 - 00004096 _____ () C:\Users\Mimi\482AA67AD25E6E74E9F48BD5FBE8533C20141130.dat
2014-11-30 20:13 - 2014-11-30 20:13 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-11-30 19:11 - 2014-12-14 21:50 - 00160400 _____ () C:\Users\Mimi\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-30 19:10 - 2014-12-14 21:49 - 05209648 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-30 19:10 - 2014-12-14 21:48 - 00043426 _____ () C:\Windows\PFRO.log
2014-11-30 19:10 - 2014-12-05 19:44 - 00007752 _____ () C:\EamClean.log
2014-11-30 16:03 - 2014-12-14 21:49 - 00003028 _____ () C:\Windows\setupact.log
2014-11-30 16:03 - 2014-11-30 16:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-30 14:44 - 2014-12-08 10:32 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-11-30 09:45 - 2014-07-13 14:29 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141130-094551.backup
2014-11-30 09:34 - 2014-11-30 10:24 - 163225944 _____ (Emsisoft GmbH ) C:\Users\Mimi\Downloads\EmsisoftAntiMalware457Setup.exe
2014-11-30 09:34 - 2014-11-30 10:22 - 163225944 _____ (Emsisoft GmbH ) C:\Users\Mimi\Downloads\EmsisoftAntiMalware457Setup (1).exe
2014-11-30 09:26 - 2014-11-30 09:27 - 00757040 _____ (Reimage®) C:\Users\Mimi\Downloads\ReimageRepair (1).exe
2014-11-30 09:25 - 2014-11-30 09:25 - 00757040 _____ (Reimage®) C:\Users\Mimi\Downloads\ReimageRepair.exe
2014-11-30 00:52 - 2014-11-30 00:52 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-30 00:51 - 2014-12-05 19:45 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-30 00:51 - 2014-12-02 16:53 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-27 23:40 - 2014-12-14 21:48 - 00000000 ____D () C:\Program Files (x86)\38402C13-488C-4881-8EF1-52F3C056692B
2014-11-26 23:38 - 2014-12-14 21:46 - 00000000 ____D () C:\Users\Mimi\AppData\Local\29987
2014-11-25 11:30 - 2014-12-02 20:09 - 00000000 ____D () C:\Users\Mimi\Desktop\kpp
2014-11-23 10:39 - 2014-11-25 12:43 - 00000000 ____D () C:\Users\Mimi\Desktop\Zeug(2)
2014-11-20 21:47 - 2014-11-20 21:47 - 00046920 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\b786bdb3c67d.sys
2014-11-19 18:51 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 18:51 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 18:51 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 18:51 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:38 - 2014-11-19 16:38 - 00041168 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\netfilter64.sys
2014-11-14 21:14 - 2014-11-14 21:14 - 00000513 _____ () C:\Users\Mimi\Desktop\Programme und Funktionen.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-14 22:02 - 2010-03-21 17:39 - 01715335 _____ () C:\Windows\WindowsUpdate.log
2014-12-14 22:02 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-14 22:02 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-14 21:54 - 2013-12-27 11:53 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-14 21:53 - 2013-12-24 23:54 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Skype
2014-12-14 21:52 - 2013-12-24 19:04 - 00000000 ____D () C:\Users\Mimi\AppData\Local\Overwolf
2014-12-14 21:49 - 2010-05-09 18:40 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-12-14 21:49 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-14 21:49 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-14 21:46 - 2014-01-24 16:10 - 00000000 ____D () C:\ProgramData\Updater
2014-12-14 20:55 - 2014-09-03 15:58 - 00000000 ____D () C:\Users\Mimi\Desktop\Neuer Ordner
2014-12-14 15:06 - 2011-09-19 17:08 - 15822848 ___SH () C:\Users\Mimi\Desktop\Thumbs.db
2014-12-13 13:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2014-12-11 19:18 - 2014-03-05 18:47 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-12-08 16:14 - 2014-06-12 21:34 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-12-07 16:16 - 2010-03-22 02:32 - 02293040 _____ () C:\Windows\system32\perfh007.dat
2014-12-07 16:16 - 2010-03-22 02:32 - 00661452 _____ () C:\Windows\system32\perfc007.dat
2014-12-07 16:16 - 2009-07-14 06:13 - 00006534 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-07 12:22 - 2011-08-30 22:05 - 03462144 ___SH () C:\Users\Mimi\Downloads\Thumbs.db
2014-12-07 12:02 - 2014-07-26 02:24 - 00000000 ____D () C:\Users\Mimi\AppData\Local\LogMeIn Hamachi
2014-12-05 20:28 - 2014-10-08 13:18 - 00000000 ____D () C:\Users\Mimi\Desktop\alles
2014-12-05 20:28 - 2014-06-03 19:14 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-12-05 20:24 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-05 20:22 - 2014-06-17 05:11 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-02 16:53 - 2012-07-15 12:55 - 00000778 _____ () C:\Windows\wininit.ini
2014-11-30 23:29 - 2014-08-22 14:57 - 00000000 ____D () C:\Users\Mimi\Desktop\Zeug
2014-11-30 20:37 - 2010-04-28 19:56 - 00000000 ____D () C:\Users\Mimi
2014-11-30 20:16 - 2014-03-23 17:47 - 00000000 ____D () C:\Users\Mimi\AppData\Local\Popajar
2014-11-30 20:00 - 2010-04-30 15:04 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-30 19:31 - 2012-04-22 11:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-30 19:23 - 2014-06-04 13:23 - 00000276 _____ () C:\Windows\Tasks\SpeedUpMyPC Maintenance.job
2014-11-30 19:15 - 2014-09-15 02:00 - 00000000 ___HD () C:\Users\Public\Temp
2014-11-30 19:13 - 2014-03-25 17:23 - 00000000 ____D () C:\ProgramData\ProductData
2014-11-30 19:12 - 2010-04-30 15:04 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-30 19:11 - 2014-06-04 13:23 - 00000270 _____ () C:\Windows\Tasks\SpeedUpMyPC Startup.job
2014-11-30 16:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-11-30 00:48 - 2013-12-28 03:46 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Winamp
2014-11-30 00:48 - 2011-04-26 13:38 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Sony
2014-11-30 00:47 - 2013-12-28 00:34 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\FileZilla
2014-11-30 00:43 - 2009-07-27 21:41 - 00000000 ____D () C:\Windows\Panther
2014-11-30 00:39 - 2010-12-18 13:03 - 00000000 ____D () C:\Windows\Minidump
2014-11-30 00:39 - 2010-08-13 23:12 - 00000000 ____D () C:\Users\Mimi\AppData\Local\CrashDumps
2014-11-27 22:28 - 2012-04-22 11:52 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-27 22:28 - 2012-04-22 11:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-27 22:28 - 2011-05-18 18:57 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 09:34 - 2014-09-01 14:30 - 00000000 ____D () C:\Users\Mimi\Desktop\SSD
2014-11-16 08:55 - 2010-04-30 15:04 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-16 08:55 - 2010-04-30 15:04 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-14 03:02 - 2010-11-27 19:16 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-11-14 00:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
Files to move or delete:
====================
C:\Users\Mimi\482AA67AD25E6E74E9F48BD5FBE8533C20141130.dat
Some content of TEMP:
====================
C:\Users\Mimi\AppData\Local\Temp\nshC45E.tmp.exe
C:\Users\Mimi\AppData\Local\Temp\optprosetup.exe
C:\Users\Mimi\AppData\Local\Temp\sqlite3.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-25 11:57
==================== End Of Log ============================ --- --- ---
-----
-----
-----
-----
Hier die addition.txt
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2014
Ran by Mimi at 2014-12-14 22:13:01
Running from C:\Users\Mimi\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Broadcom Gigabit NetLink Controller (HKLM\...\{96F70DF8-160F-4F9C-9B9E-2A9B439B4EB9}) (Version: 12.26.02 - Broadcom Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 4.05 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
Compatibility Pack für 2007 Office System (HKLM-x32\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
FileZilla Client 3.8.1 (HKLM-x32\...\FileZilla Client) (Version: 3.8.1 - Tim Kosse)
GIANTS Editor 5.5.0 64-bit Beta (HKLM-x32\...\giants_editor_5.5.0_win64_is1) (Version: 5.5.0 - GIANTS Software GmbH)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Horizon v2.8.0.1 (HKLM-x32\...\d4cfeebc-b821-40b7-9f81-d366b1466f03_is1) (Version: 2.8.0.1 - Daring Development Inc.)
HyperCam 2 (HKLM-x32\...\HyperCam 2) (Version: 2.29.01 - Hyperionics Technology LLC)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle)
Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.1.94 - LSI Corporation)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710F4C1C-CC18-4C49-8CBF-51240C89A1A2}) (Version: - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837B34E3-7C30-493C-8F6A-2B0F04E2912C}) (Version: - )
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - )
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: - )
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
MTA:SA v1.3.1 (HKLM-x32\...\MTA:SA 1.3) (Version: v1.3.1 - Multi Theft Auto)
MTA:SA v1.4.0 (HKLM-x32\...\MTA:SA 1.4) (Version: v1.4.0 - Multi Theft Auto)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.81.34.0 - Overwolf Ltd.)
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
s_vuupc (HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\S_Vuupc) (Version: - )
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.6 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.32494 - TeamViewer)
Unity Web Player (HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2014-09-24 15:57 - 2014-11-30 09:45 - 00450813 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activation.cloud.techsmith.com
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0491D9DF-5467-43CD-880E-9BFB704324E1} - \Plus-HD-9.3-enabler No Task File <==== ATTENTION
Task: {142CC62E-4BCB-4CE3-9189-7B609673864F} - System32\Tasks\{06B2A101-EEA6-45E4-AB00-06B59CAB644D} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.59.105/de/go/help.faq.installer?LastError=1638
Task: {19BA3CBE-847B-4816-AAB9-6C53C64B9CC4} - \FF Watcher {59E22D3A-70EA-40C6-A56D-4A7CAF3A102A} No Task File <==== ATTENTION
Task: {2268CC71-BF7C-4729-9A67-A01D5CCEE25E} - System32\Tasks\{180AEF1A-A0C2-42C6-BDA0-CB802336EEBE} => pcalua.exe -a C:\ProgramData\TVWizard\uninstall.exe -c /kb=y /ic=1
Task: {227164F6-06E4-47BE-BEC5-E5F01D442293} - System32\Tasks\{0886B85D-46CE-40DF-B05B-39E50B212DD0} => C:\Program Files (x86)\Audiosurf\Audiosurf.exe
Task: {24A33EE3-DFB5-4C65-88C2-ECECD500F77C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {39AAF83A-9B5B-4E68-AE57-6EFF40556D55} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {3CC0CF58-11D9-491D-B383-7A33B1389B69} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2014-10-22] (Overwolf LTD)
Task: {4DC760DB-AF9E-49D2-AC59-CEB78B955720} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03] (Adobe Systems Incorporated)
Task: {50762EB4-62C9-4EC9-BC93-719604C8FC29} - System32\Tasks\SimpleFiles Update Service => C:\Program Files (x86)\SimpleFilesUpdater\SimpleFilesUpdater.exe
Task: {56A49095-6830-4E70-920A-A8B17E41CD70} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {5FA470C2-670F-432E-AAB4-D0835C7D69CB} - System32\Tasks\{A7C40F04-2CA3-4A41-90AD-E05094C37A54} => pcalua.exe -a "C:\Program Files (x86)\Skype Webcam Hacker v3.1.8\Uninstal.exe"
Task: {60D674FA-E928-4F5E-B535-39EEDA132F67} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {6754FC9E-62E0-4372-B645-35A6221749FC} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {75906899-3CD3-4C85-AC73-320FF351A146} - System32\Tasks\Egis technology-Online-Aktualisierungsprogramm => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04] (Egis Technology Inc.)
Task: {826480C4-D550-49E2-B38A-F98E8CE673B6} - \Plus-HD-9.3-chromeinstaller No Task File <==== ATTENTION
Task: {883B62B7-1409-4364-A6FA-CF29D03B6245} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {901E3814-998A-4B5D-B317-1AC1C118F617} - \Plus-HD-9.3-firefoxinstaller No Task File <==== ATTENTION
Task: {9B90489C-9139-45C9-B7B2-444B8EF097CB} - \Plus-HD-9.3-updater No Task File <==== ATTENTION
Task: {9C702043-F204-45A0-88D6-2249A34FD5AA} - System32\Tasks\{035BBBDD-8A3F-4016-A962-1EEC9C6AF404} => pcalua.exe -a "C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe" -c /uninstall
Task: {A1B828AD-DC74-42AC-BC61-9F4FFC86BC75} - System32\Tasks\{B076DDB5-1DC3-4F86-9ECB-0160401214EA} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.11.0.102&LastError=12002
Task: {A27F613C-EF5F-4305-A665-8517FE911EA9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-27] (Adobe Systems Incorporated)
Task: {A43C3928-8A70-4A66-A3B1-4F7C87CBEBA2} - System32\Tasks\{EA6BAC2C-992A-4ACF-9399-AB1F833D99F3} => pcalua.exe -a D:\AP\SETUP.EXE -d D:\AP
Task: {B284E1DF-585E-440A-8484-3128FFA20DB5} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ATTENTION
Task: {B5A1C2A3-D6A7-4F07-9DEB-5520D94CDCA2} - System32\Tasks\{265A18EE-104A-403E-9422-04ECCE2E31C9} => pcalua.exe -a "C:\Users\Mimi\Desktop\Advanced Webcam Hacker PRO\Advanced Webcam Hacker PRO\Advanced Webcam Hacker PRO - Full Version_Installer\Advanced Webcam Hacker PRO - Full Version_Installer.exe" -d "C:\Users\Mimi\Desktop\Advanced Webcam Hacker PRO\Advanced Webcam Hacker PRO\Advanced Webcam Hacker PRO - Full Version_Installer"
Task: {B8DBB042-B2F3-4C7E-A39B-55ED7093BF2C} - \Plus-HD-9.3-codedownloader No Task File <==== ATTENTION
Task: {BBF82001-B9F8-4EAF-9C58-793A6709113B} - System32\Tasks\{9BF61961-4AE3-432C-A595-14DF2E37CBAB} => pcalua.exe -a D:\InstallCD.exe -d D:\
Task: {C470CB2C-4184-4C20-98AC-D914419CFAD6} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {C6069B37-3940-4E35-A3FF-EB52A9D6BACD} - System32\Tasks\{C9F8839B-F652-4C27-A975-FF236E65CA4B} => C:\Program Files (x86)\TuneUp Utilities 2013\Integrator.exe
Task: {DB398E70-5FA3-49D8-B87C-6AB299D1BC42} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ATTENTION
Task: {DC013BA5-ED0C-4F04-B384-7F7F69CAC90C} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {F32FB322-A597-432B-B7BE-940F9BD32EF9} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {F3405692-71F7-4870-B014-F523BF7F8721} - System32\Tasks\SMupdate1 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update1 <==== ATTENTION
Task: {F4327C36-5812-4130-84C6-34DB8F6D0045} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-26] (Google Inc.)
Task: {FFF1F3C6-D565-4070-80BE-813C539D757C} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SpeedUpMyPC Maintenance.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ATTENTION
Task: C:\Windows\Tasks\SpeedUpMyPC Startup.job => C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2014-05-01 20:29 - 2014-05-01 20:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2010-03-21 17:44 - 2009-11-20 15:34 - 00200704 _____ () C:\Windows\PLFSetI.exe
2009-02-03 01:33 - 2009-02-03 01:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-29 01:55 - 2008-09-29 01:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2014-06-01 10:08 - 2014-06-01 10:08 - 00035328 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00091648 _____ () C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll
2014-05-24 17:41 - 2014-05-24 17:41 - 00892416 _____ () C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-09-30 17:34 - 2014-09-23 05:06 - 01098056 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libglesv2.dll
2014-09-30 17:34 - 2014-09-23 05:06 - 00174408 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libegl.dll
2014-09-30 17:34 - 2014-09-23 05:07 - 08577864 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\pdf.dll
2014-09-30 17:34 - 2014-09-23 05:07 - 00331592 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ppGoogleNaClPluginChrome.dll
2014-09-30 17:34 - 2014-09-23 05:06 - 01660232 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ffmpegsumo.dll
2014-09-30 17:34 - 2014-09-23 05:07 - 14891848 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData:NT2
AlternateDataStreams: C:\Users\All Users:NT2
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT2
AlternateDataStreams: C:\ProgramData\Application Data:NT2
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2
AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:444C53BA
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E3C56885
AlternateDataStreams: C:\Users\Mimi\Anwendungsdaten:NT
AlternateDataStreams: C:\Users\Mimi\Anwendungsdaten:NT2
AlternateDataStreams: C:\Users\Mimi\Lokale Einstellungen:hTnYWI9XeKchsPoF8fYLqmruOW
AlternateDataStreams: C:\Users\Mimi\AppData\Local:hTnYWI9XeKchsPoF8fYLqmruOW
AlternateDataStreams: C:\Users\Mimi\AppData\Roaming:NT
AlternateDataStreams: C:\Users\Mimi\AppData\Roaming:NT2
AlternateDataStreams: C:\Users\Mimi\AppData\Local\Anwendungsdaten:hTnYWI9XeKchsPoF8fYLqmruOW
AlternateDataStreams: C:\Users\Mimi\AppData\Local\XzOJVY7khBAc:Bhua4MlQ7t3nEdIeHZGRG5JY5PxTrs
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
========================= Accounts: ==========================
Administrator (S-1-5-21-1469723594-2657416431-1904025529-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1469723594-2657416431-1904025529-1004 - Limited - Enabled)
Gast (S-1-5-21-1469723594-2657416431-1904025529-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1469723594-2657416431-1904025529-1002 - Limited - Enabled)
Mimi (S-1-5-21-1469723594-2657416431-1904025529-1000 - Administrator - Enabled) => C:\Users\Mimi
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: MAC Bridge Miniport
Description: MAC Bridge Miniport
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BridgeMP
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/14/2014 09:49:24 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (12/14/2014 09:47:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: wmpnetwk.exe, Version: 12.0.7601.17514, Zeitstempel: 0x4ce7ae7f
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x5315a05a
Ausnahmecode: 0x0000046b
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x5dc
Startzeit der fehlerhaften Anwendung: 0xwmpnetwk.exe0
Pfad der fehlerhaften Anwendung: wmpnetwk.exe1
Pfad des fehlerhaften Moduls: wmpnetwk.exe2
Berichtskennung: wmpnetwk.exe3
Error: (12/11/2014 05:11:38 PM) (Source: TestWorker) (EventID: 1) (User: )
Description: TestWorkerFailed to send data to service: Norton PC Checkup Application Launcher
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: Fehler beim Löschen der Schattenkopie "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5" auf Volume "\\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\".
VSS-Fehler: Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Benutzeraktion
Wiederholen Sie den Löschvorgang, oder öffnen Sie das Ereignisprotokoll, um zugehörige VSS-Einträge anzuzeigen.
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: Fehler beim Löschen der Schattenkopie "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy4" auf Volume "\\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\".
VSS-Fehler: Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Benutzeraktion
Wiederholen Sie den Löschvorgang, oder öffnen Sie das Ereignisprotokoll, um zugehörige VSS-Einträge anzuzeigen.
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: Fehler beim Löschen der Schattenkopie "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3" auf Volume "\\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\".
VSS-Fehler: Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Benutzeraktion
Wiederholen Sie den Löschvorgang, oder öffnen Sie das Ereignisprotokoll, um zugehörige VSS-Einträge anzuzeigen.
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: Fehler beim Löschen der Schattenkopie "\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2" auf Volume "\\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\".
VSS-Fehler: Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Benutzeraktion
Wiederholen Sie den Löschvorgang, oder öffnen Sie das Ereignisprotokoll, um zugehörige VSS-Einträge anzuzeigen.
Error: (12/09/2014 10:36:32 AM) (Source: CouponarificService64) (EventID: 1) (User: )
Description: CouponarificService64In SvcInstall, CreateService failed (1073)
failed with 1073
Error: (12/08/2014 10:45:00 AM) (Source: TestWorker) (EventID: 1) (User: )
Description: TestWorkerFailed to send data to service: Norton PC Checkup Application Launcher
Error: (12/08/2014 10:33:26 AM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
System errors:
=============
Error: (12/14/2014 10:02:42 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.
Neue Signaturversion:
Vorherige Signaturversion: 113.28.0.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsphase: 4.6.0305.00
Quellpfad: 4.6.0305.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/14/2014 10:02:37 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.
Neue Signaturversion:
Vorherige Signaturversion: 1.189.1041.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsphase: 4.6.0305.00
Quellpfad: 4.6.0305.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/14/2014 10:02:37 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.
Neue Signaturversion:
Vorherige Signaturversion: 1.189.1041.0
Aktualisierungsquelle: %NT-AUTORITÄT51
Aktualisierungsphase: 4.6.0305.00
Quellpfad: 4.6.0305.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\NETZWERKDIENST
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/14/2014 10:02:33 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.
Neue Signaturversion:
Vorherige Signaturversion: 1.189.1041.0
Aktualisierungsquelle: %NT-AUTORITÄT59
Aktualisierungsphase: 4.6.0305.00
Quellpfad: 4.6.0305.01
Signaturtyp: %NT-AUTORITÄT602
Aktualisierungstyp: %NT-AUTORITÄT604
Benutzer: NT-AUTORITÄT\SYSTEM
Aktuelle Modulversion: %NT-AUTORITÄT605
Vorherige Modulversion: %NT-AUTORITÄT606
Fehlercode: %NT-AUTORITÄT607
Fehlerbeschreibung: %NT-AUTORITÄT608
Error: (12/14/2014 10:02:03 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet:
%%-2147014790
Error: (12/14/2014 10:01:33 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet:
%%-2147014790
Error: (12/14/2014 09:53:35 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet:
%%-2147014790
Error: (12/14/2014 09:53:35 PM) (Source: WMPNetworkSvc) (EventID: 14348) (User: )
Description: 0x80070057
Error: (12/14/2014 09:53:35 PM) (Source: WMPNetworkSvc) (EventID: 14323) (User: )
Description: WMPNetworkSvc0xc00d4268
Error: (12/14/2014 09:53:35 PM) (Source: WMPNetworkSvc) (EventID: 14356) (User: )
Description: 0x80070057
Microsoft Office Sessions:
=========================
Error: (12/14/2014 09:49:24 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (12/14/2014 09:47:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: wmpnetwk.exe12.0.7601.175144ce7ae7fKERNELBASE.dll6.1.7601.184095315a05a0000046b000000000000940d5dc01d012ca6534ad3bC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Windows\system32\KERNELBASE.dll683225d5-83d2-11e4-bbd0-00262d8748bc
Error: (12/11/2014 05:11:38 PM) (Source: TestWorker) (EventID: 1) (User: )
Description: TestWorkerFailed to send data to service: Norton PC Checkup Application Launcher
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: \\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: \\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy4Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: \\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Error: (12/09/2014 11:09:09 AM) (Source: SPP) (EventID: 16388) (User: )
Description: \\?\Volume{f03e448b-3507-11df-be05-806e6f6e6963}\\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2Das angegebene Objekt wurde nicht gefunden. (0x80042308)
Error: (12/09/2014 10:36:32 AM) (Source: CouponarificService64) (EventID: 1) (User: )
Description: CouponarificService64In SvcInstall, CreateService failed (1073)
failed with 1073
Error: (12/08/2014 10:45:00 AM) (Source: TestWorker) (EventID: 1) (User: )
Description: TestWorkerFailed to send data to service: Norton PC Checkup Application Launcher
Error: (12/08/2014 10:33:26 AM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
CodeIntegrity Errors:
===================================
Date: 2014-12-14 21:36:03.208
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\PCTRunner\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-12-14 21:36:00.968
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\PCTRunner\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-12-14 21:35:58.596
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\PCTRunner\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-12-14 21:19:06.552
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\PCTRunner\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-12-14 21:19:04.398
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\PCTRunner\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-12-14 21:19:02.064
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files (x86)\PCTRunner\pcwtc64f.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-02-10 11:59:31.223
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\Mimi\Desktop\MoonLight_Engine_1236.4.0.18\MoonLight Engine 1236.4.0.18\Money1280.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-10 11:59:30.337
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\Mimi\Desktop\MoonLight_Engine_1236.4.0.18\MoonLight Engine 1236.4.0.18\Money1280.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-10 11:51:43.681
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\Mimi\Desktop\MoonLight_Engine_1236.4.0.18\MoonLight Engine 1236.4.0.18\Money1280.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-02-10 11:51:42.604
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Users\Mimi\Desktop\MoonLight_Engine_1236.4.0.18\MoonLight Engine 1236.4.0.18\Money1280.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz
Percentage of memory in use: 44%
Total physical RAM: 4090.93 MB
Available physical RAM: 2263.88 MB
Total Pagefile: 8180.03 MB
Available Pagefile: 6131.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:286.27 GB) (Free:34.71 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: E7DCE7DC)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=286.3 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- ---
-----
-----
-----
-----
Hier einmal die FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-12-2014
Ran by Mimi (administrator) on TOBI on 14-12-2014 22:10:24
Running from C:\Users\Mimi\Downloads
Loaded Profile: Mimi (Available profiles: Mimi)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Windows\PLFSetI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-11] (Egis Technology Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2009-11-20] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-18] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-09-24] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1094736 2009-11-02] (Dritek System Inc.)
HKLM-x32\...\Run: [ArcadeDeluxeAgent] => C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [419112 2009-10-06] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Mimi\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [39712 2014-10-22] (Overwolf LTD)
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1940160 2014-11-18] (Valve Corporation)
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22041192 2014-08-27] (Skype Technologies S.A.)
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\MountPoints2: E - E:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\MountPoints2: {26f4c788-5575-11e4-bad8-00262d8748bc} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\...\MountPoints2: {b157b662-02a2-11e4-a3d6-00262d8748bc} - E:\HTC_Sync_Manager_PC.exe
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll (Egis Technology Inc.)
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll (Egis Technology Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1469723594-2657416431-1904025529-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://tikotin.com
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll No File
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1469723594-2657416431-1904025529-1000 -> No Name - {C2DB4FE6-8409-45CE-8010-189A7B5CCE86} - No File
Toolbar: HKU\S-1-5-21-1469723594-2657416431-1904025529-1000 -> No Name - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - No File
Toolbar: HKU\S-1-5-21-1469723594-2657416431-1904025529-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Winsock: Catalog9-x64 01 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 02 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 03 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 04 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Winsock: Catalog9-x64 15 C:\Windows\system32\MyOSProtect64.dll File Not found ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Tcpip\..\Interfaces\{41DDF4E7-E417-4274-9078-418E7185998D}: [NameServer] 80.237.196.2,194.150.168.168
FireFox:
========
FF ProfilePath: C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Profiles\37judds5.default
FF SearchEngineOrder.1: Improved Search
FF SelectedSearchEngine: SafeFinder Search
FF NewTab: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1469723594-2657416431-1904025529-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mimi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Adblock Plus - C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Profiles\37judds5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-06]
FF Extension: No Name - C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Profiles\37judds5.default\extensions\boost@boost.net.xpi [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.mmoga.de/adventskalender.html?ref=683
CHR StartupUrls: Default -> "https://www.google.de/?gws_rd=ssl", "hxxp://www.facebook.com/", "hxxp://www.youtube.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Angry Birds) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-09-30]
CHR Extension: (Google Docs) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-24]
CHR Extension: (Google Drive) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-24]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-30]
CHR Extension: (YouTube) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-24]
CHR Extension: (Facebook) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2014-09-30]
CHR Extension: (Bouncy Mouse) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdllcbmneiklcmbeclfegccdjholomb [2014-09-30]
CHR Extension: (Google-Suche) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-24]
CHR Extension: (Weißes Rauschen) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkjpdnomgodmagfmhojepjlajpoicip [2014-09-30]
CHR Extension: (PanicButton) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\faminaibgiklngmfpfbhmokfmnglamcm [2014-09-30]
CHR Extension: (AdBlock) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-30]
CHR Extension: (AudioSauna) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkgfemnodkdnenmfkblebnkjpckkjcae [2014-09-30]
CHR Extension: (Need for Speed World) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk [2014-09-30]
CHR Extension: (Google Wallet) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-30]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2014-09-30]
CHR Extension: (Picasa) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-09-30]
CHR Extension: (Red Bull TV) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbalkogcfbpplioohgihkidalmomblfc [2014-09-30]
CHR Extension: (Psykopaint) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2014-09-30]
CHR Extension: (Google Mail) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-24]
CHR Extension: (eBay WOW! Angebote) - C:\Users\Mimi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pllkgmcojhajjmojfoagiegoibjognlc [2014-09-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-11] (Egis Technology Inc.)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [997664 2014-10-22] (Overwolf LTD)
R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.20\ccSvcHst.exe [126392 2011-11-07] (Symantec Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 b786bdb3c67d; C:\Windows\System32\drivers\b786bdb3c67d.sys [46920 2014-11-20] (Windows (R) Win 7 DDK provider)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-08-22] (Sony Mobile Communications)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [41168 2014-11-19] (NetFilterSDK.com)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed]
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S3 IlvMoneyDRIVER53; \??\C:\Users\Mimi\Desktop\MoonLight_Engine_1236.4.0.18\MoonLight Engine 1236.4.0.18\Money1280.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-14 22:11 - 2014-12-14 22:11 - 00380416 _____ () C:\Users\Mimi\Downloads\Gmer-19357.exe
2014-12-14 22:10 - 2014-12-14 22:11 - 00022341 _____ () C:\Users\Mimi\Downloads\FRST.txt
2014-12-14 22:10 - 2014-12-14 22:10 - 00000000 ____D () C:\FRST
2014-12-14 22:09 - 2014-12-14 22:09 - 02119680 _____ (Farbar) C:\Users\Mimi\Downloads\FRST64.exe
2014-12-14 21:10 - 2014-12-14 21:11 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-14 21:10 - 2014-12-14 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-14 21:10 - 2014-12-14 21:10 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware_old
2014-12-14 21:10 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-14 21:10 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-14 21:10 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-14 21:02 - 2014-12-14 21:02 - 00000000 ____D () C:\Users\Mimi\Documents\PC Speed Maximizer
2014-12-14 20:59 - 2014-12-14 21:02 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Mimi\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-14 20:57 - 2014-12-14 20:57 - 00000000 ____D () C:\MININT
2014-12-14 20:53 - 2014-12-14 20:53 - 00054956 _____ () C:\Users\Mimi\Desktop\firewall snap-in - SysProfile Forum.htm
2014-12-14 20:53 - 2014-12-14 20:53 - 00000000 ____D () C:\Users\Mimi\Desktop\firewall snap-in - SysProfile Forum_files
2014-12-14 20:51 - 2014-12-14 20:51 - 00724800 _____ ( ) C:\Users\Mimi\Downloads\IDM2-Win-EN.exe
2014-12-14 10:40 - 2014-12-14 10:40 - 00013233 _____ () C:\Users\Mimi\Desktop\Realtek HD Audio-Manager.lnk
2014-12-12 00:23 - 2014-12-12 00:23 - 00000000 ____D () C:\Users\Mimi\Documents\Optimizer Pro
2014-12-12 00:03 - 2014-12-12 00:03 - 00000000 ____D () C:\Users\Mimi\AppData\Local\WorldofTanks
2014-12-12 00:03 - 2014-12-12 00:03 - 00000000 ____D () C:\Users\Mimi\AppData\Local\Pirates
2014-12-12 00:02 - 2014-12-12 00:02 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Windows Essentials Codec Pack
2014-12-11 23:59 - 2014-12-11 23:59 - 00790656 _____ ( ) C:\Users\Mimi\Downloads\WindowsCodec.exe
2014-12-09 14:13 - 2014-12-09 14:14 - 00000000 ____D () C:\Users\Mimi\Documents\Wondershare DVD Slideshow Builder Standard
2014-12-09 14:13 - 2014-12-09 14:13 - 00000000 ____D () C:\ProgramData\Wondershare
2014-12-09 14:12 - 2014-12-09 14:12 - 00000000 ____D () C:\Program Files (x86)\Wondershare
2014-12-09 14:07 - 2014-12-09 14:10 - 37893168 _____ (WonderShare Software Co.,Ltd. ) C:\Users\Mimi\Downloads\dvdslideshow-hd-photo_full757.exe
2014-12-09 11:13 - 2014-12-09 11:13 - 00380416 _____ () C:\Users\Mimi\Downloads\vkujklc4.exe
2014-12-09 11:13 - 2014-12-09 11:13 - 00380416 _____ () C:\Users\Mimi\Downloads\d4wfje5z.exe
2014-12-09 11:13 - 2014-12-09 11:13 - 00370943 _____ () C:\Users\Mimi\Downloads\gmer.zip
2014-12-09 11:12 - 2014-12-09 11:12 - 00380416 _____ () C:\Users\Mimi\Downloads\xkkkoi20.exe
2014-12-09 10:36 - 2014-12-09 10:36 - 00000005 _____ () C:\end
2014-12-08 16:23 - 2014-12-08 16:23 - 00000695 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-12-08 16:23 - 2014-12-08 16:23 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\TS3Client
2014-12-08 16:23 - 2014-12-08 16:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-12-08 16:22 - 2014-12-08 16:23 - 00000000 ____D () C:\ts3undso
2014-12-08 16:18 - 2014-12-08 16:20 - 32155104 _____ (TeamSpeak Systems GmbH) C:\Users\Mimi\Downloads\TeamSpeak3-Client-win64-3.0.7.exe
2014-12-08 16:15 - 2014-12-08 16:15 - 00000000 ____D () C:\Users\Mimi\Desktop\teamspeak3-server_win64-3.0.11.1
2014-12-08 16:15 - 2014-12-08 16:14 - 04522122 _____ () C:\Users\Mimi\Desktop\teamspeak3-server_win64-3.0.11.1.zip
2014-12-08 16:14 - 2014-12-08 16:14 - 04522122 _____ () C:\Users\Mimi\Downloads\teamspeak3-server_win64-3.0.11.1.zip
2014-12-08 16:13 - 2014-12-08 16:14 - 04155977 _____ () C:\Users\Mimi\Downloads\teamspeak3-server_win32-3.0.11.1.zip
2014-12-08 02:10 - 2014-12-11 19:23 - 00000009 _____ () C:\Users\Mimi\Desktop\pw_WMC.txt
2014-12-07 21:27 - 2014-12-07 21:27 - 00031880 _____ () C:\Users\Mimi\Desktop\anti_backdoor.rar
2014-12-07 21:23 - 2014-12-07 21:24 - 00000000 ____D () C:\Users\Mimi\Desktop\anti_backdoor_und_beleidigung
2014-12-07 11:32 - 2014-12-07 11:32 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Mimi\Downloads\TeamSpeak3-Client-win64-3.0.16.exe
2014-12-07 11:32 - 2014-12-07 11:32 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Mimi\Downloads\TeamSpeak3-Client-win64-3.0.16 (1).exe
2014-12-07 11:30 - 2014-12-07 11:30 - 00000000 ____D () C:\Users\Mimi\Desktop\ts undso
2014-12-05 20:38 - 2014-12-05 20:38 - 00001934 _____ () C:\Users\Mimi\Desktop\MTA San Andreas.lnk
2014-11-30 23:28 - 2014-11-30 23:37 - 00014150 _____ () C:\Users\Mimi\Desktop\chrome.exe - Verknüpfung.lnk
2014-11-30 20:37 - 2014-11-30 20:37 - 00004096 _____ () C:\Users\Mimi\482AA67AD25E6E74E9F48BD5FBE8533C20141130.dat
2014-11-30 20:13 - 2014-11-30 20:13 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-11-30 19:11 - 2014-12-14 21:50 - 00160400 _____ () C:\Users\Mimi\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-30 19:10 - 2014-12-14 21:49 - 05209648 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-30 19:10 - 2014-12-14 21:48 - 00043426 _____ () C:\Windows\PFRO.log
2014-11-30 19:10 - 2014-12-05 19:44 - 00007752 _____ () C:\EamClean.log
2014-11-30 16:03 - 2014-12-14 21:49 - 00003028 _____ () C:\Windows\setupact.log
2014-11-30 16:03 - 2014-11-30 16:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-30 14:44 - 2014-12-08 10:32 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-11-30 09:45 - 2014-07-13 14:29 - 00000864 _____ () C:\Windows\system32\Drivers\etc\hosts.20141130-094551.backup
2014-11-30 09:34 - 2014-11-30 10:24 - 163225944 _____ (Emsisoft GmbH ) C:\Users\Mimi\Downloads\EmsisoftAntiMalware457Setup.exe
2014-11-30 09:34 - 2014-11-30 10:22 - 163225944 _____ (Emsisoft GmbH ) C:\Users\Mimi\Downloads\EmsisoftAntiMalware457Setup (1).exe
2014-11-30 09:26 - 2014-11-30 09:27 - 00757040 _____ (Reimage®) C:\Users\Mimi\Downloads\ReimageRepair (1).exe
2014-11-30 09:25 - 2014-11-30 09:25 - 00757040 _____ (Reimage®) C:\Users\Mimi\Downloads\ReimageRepair.exe
2014-11-30 00:52 - 2014-11-30 00:52 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-30 00:51 - 2014-12-05 19:45 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-30 00:51 - 2014-12-02 16:53 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-27 23:40 - 2014-12-14 21:48 - 00000000 ____D () C:\Program Files (x86)\38402C13-488C-4881-8EF1-52F3C056692B
2014-11-26 23:38 - 2014-12-14 21:46 - 00000000 ____D () C:\Users\Mimi\AppData\Local\29987
2014-11-25 11:30 - 2014-12-02 20:09 - 00000000 ____D () C:\Users\Mimi\Desktop\kpp
2014-11-23 10:39 - 2014-11-25 12:43 - 00000000 ____D () C:\Users\Mimi\Desktop\Zeug(2)
2014-11-20 21:47 - 2014-11-20 21:47 - 00046920 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\b786bdb3c67d.sys
2014-11-19 18:51 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 18:51 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 18:51 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 18:51 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-19 16:38 - 2014-11-19 16:38 - 00041168 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\netfilter64.sys
2014-11-14 21:14 - 2014-11-14 21:14 - 00000513 _____ () C:\Users\Mimi\Desktop\Programme und Funktionen.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-14 22:02 - 2010-03-21 17:39 - 01715335 _____ () C:\Windows\WindowsUpdate.log
2014-12-14 22:02 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-14 22:02 - 2009-07-14 05:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-14 21:54 - 2013-12-27 11:53 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-14 21:53 - 2013-12-24 23:54 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Skype
2014-12-14 21:52 - 2013-12-24 19:04 - 00000000 ____D () C:\Users\Mimi\AppData\Local\Overwolf
2014-12-14 21:49 - 2010-05-09 18:40 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-12-14 21:49 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-14 21:49 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-14 21:46 - 2014-01-24 16:10 - 00000000 ____D () C:\ProgramData\Updater
2014-12-14 20:55 - 2014-09-03 15:58 - 00000000 ____D () C:\Users\Mimi\Desktop\Neuer Ordner
2014-12-14 15:06 - 2011-09-19 17:08 - 15822848 ___SH () C:\Users\Mimi\Desktop\Thumbs.db
2014-12-13 13:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2014-12-11 19:18 - 2014-03-05 18:47 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-12-08 16:14 - 2014-06-12 21:34 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-12-07 16:16 - 2010-03-22 02:32 - 02293040 _____ () C:\Windows\system32\perfh007.dat
2014-12-07 16:16 - 2010-03-22 02:32 - 00661452 _____ () C:\Windows\system32\perfc007.dat
2014-12-07 16:16 - 2009-07-14 06:13 - 00006534 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-07 12:22 - 2011-08-30 22:05 - 03462144 ___SH () C:\Users\Mimi\Downloads\Thumbs.db
2014-12-07 12:02 - 2014-07-26 02:24 - 00000000 ____D () C:\Users\Mimi\AppData\Local\LogMeIn Hamachi
2014-12-05 20:28 - 2014-10-08 13:18 - 00000000 ____D () C:\Users\Mimi\Desktop\alles
2014-12-05 20:28 - 2014-06-03 19:14 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-12-05 20:24 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-05 20:22 - 2014-06-17 05:11 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-02 16:53 - 2012-07-15 12:55 - 00000778 _____ () C:\Windows\wininit.ini
2014-11-30 23:29 - 2014-08-22 14:57 - 00000000 ____D () C:\Users\Mimi\Desktop\Zeug
2014-11-30 20:37 - 2010-04-28 19:56 - 00000000 ____D () C:\Users\Mimi
2014-11-30 20:16 - 2014-03-23 17:47 - 00000000 ____D () C:\Users\Mimi\AppData\Local\Popajar
2014-11-30 20:00 - 2010-04-30 15:04 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-30 19:31 - 2012-04-22 11:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-30 19:23 - 2014-06-04 13:23 - 00000276 _____ () C:\Windows\Tasks\SpeedUpMyPC Maintenance.job
2014-11-30 19:15 - 2014-09-15 02:00 - 00000000 ___HD () C:\Users\Public\Temp
2014-11-30 19:13 - 2014-03-25 17:23 - 00000000 ____D () C:\ProgramData\ProductData
2014-11-30 19:12 - 2010-04-30 15:04 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-30 19:11 - 2014-06-04 13:23 - 00000270 _____ () C:\Windows\Tasks\SpeedUpMyPC Startup.job
2014-11-30 16:05 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-11-30 00:48 - 2013-12-28 03:46 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Winamp
2014-11-30 00:48 - 2011-04-26 13:38 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\Sony
2014-11-30 00:47 - 2013-12-28 00:34 - 00000000 ____D () C:\Users\Mimi\AppData\Roaming\FileZilla
2014-11-30 00:43 - 2009-07-27 21:41 - 00000000 ____D () C:\Windows\Panther
2014-11-30 00:39 - 2010-12-18 13:03 - 00000000 ____D () C:\Windows\Minidump
2014-11-30 00:39 - 2010-08-13 23:12 - 00000000 ____D () C:\Users\Mimi\AppData\Local\CrashDumps
2014-11-27 22:28 - 2012-04-22 11:52 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-27 22:28 - 2012-04-22 11:52 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-27 22:28 - 2011-05-18 18:57 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 09:34 - 2014-09-01 14:30 - 00000000 ____D () C:\Users\Mimi\Desktop\SSD
2014-11-16 08:55 - 2010-04-30 15:04 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-16 08:55 - 2010-04-30 15:04 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-14 03:02 - 2010-11-27 19:16 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-11-14 00:45 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
Files to move or delete:
====================
C:\Users\Mimi\482AA67AD25E6E74E9F48BD5FBE8533C20141130.dat
Some content of TEMP:
====================
C:\Users\Mimi\AppData\Local\Temp\nshC45E.tmp.exe
C:\Users\Mimi\AppData\Local\Temp\optprosetup.exe
C:\Users\Mimi\AppData\Local\Temp\sqlite3.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-25 11:57
==================== End Of Log ============================ --- --- --- |