Ich danke dir. Wo find ich denn wie das letzte Update heißt und wo ich es wieder löschen kann?
Den Rest werde ich mal ausführen ...
Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Suchlauf Datum: 25.02.2015
Suchlauf-Zeit: 22:09:53
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.25.06
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x64
Dateisystem: NTFS
Benutzer: Schwarzkopf&Nails
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 355707
Verstrichene Zeit: 27 Min, 35 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam_64.exe, 2736, Löschen bei Neustart, [4e5c3ae8434794a26cf144289967eb15]
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam_64.exe, 3144, Löschen bei Neustart, [4e5c3ae8434794a26cf144289967eb15]
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam.exe, 3136, Löschen bei Neustart, [2e7c79a9bbcf6bcb2538aebebb45b749]
Module: 2
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\kxrpohpkftco.dll, Löschen bei Neustart, [0f9b1a081377fc3a9496f3a242c1ab55],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\kxrpohpkftco.dll, Löschen bei Neustart, [0f9b1a081377fc3a9496f3a242c1ab55],
Registrierungsschlüssel: 3
PUP.Optional.Wajam.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wajam Web Enhancer, In Quarantäne, [4e5c3ae8434794a26cf144289967eb15],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\Wajam Web Enhancer, In Quarantäne, [1c8e2002d4b689ad7320555526dd56aa],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3728198647-4080070119-460406438-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [525811117218f83e5bcdfbab927158a8],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 16
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer, Löschen bei Neustart, [0f9b1a081377fc3a9496f3a242c1ab55],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls, Löschen bei Neustart, [0f9b1a081377fc3a9496f3a242c1ab55],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar, Löschen bei Neustart, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML, Löschen bei Neustart, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\DE, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
Dateien: 77
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam_64.exe, Löschen bei Neustart, [4e5c3ae8434794a26cf144289967eb15],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\wajam.exe, Löschen bei Neustart, [2e7c79a9bbcf6bcb2538aebebb45b749],
PUP.Optional.Wajam.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\RHEng\3E440CA81BDA495D8AE22AAF6E6AC097\WWE_1.2.0.53.exe, In Quarantäne, [2d7d65bdbdcd8da9e27bb1bb659b24dc],
PUP.Optional.InstallCore, C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\a9YOhvhs.exe.part, In Quarantäne, [3179140e523893a37a46f47c0afb11ef],
PUP.Optional.InstallCore, C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\5k2GaY7K.exe.part, In Quarantäne, [86242cf6c7c31e18b81cb2990af7718f],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-1.xml, In Quarantäne, [3a70d052aedc51e566fac0d963a03ac6],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-10.xml, In Quarantäne, [a70351d191f9fe383f21c9d035ce07f9],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-2.xml, In Quarantäne, [3a70b86aee9c6dc9263a78218380d12f],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-3.xml, In Quarantäne, [1b8f849e6e1ce3539dc3c4d546bd1ae6],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-4.xml, In Quarantäne, [7b2f32f0a8e237ff5c041980cd36b14f],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-5.xml, In Quarantäne, [c8e23be7c6c40b2b6cf4108928dbd52b],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-6.xml, In Quarantäne, [3d6d69b9e8a25adc85db2277c83b9e62],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-7.xml, In Quarantäne, [59510121aedc152170f060396b98a65a],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-8.xml, In Quarantäne, [fcae45ddc7c3f1452e327f1aed16c937],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin-9.xml, In Quarantäne, [ebbf38ea048694a2ef71c2d76a99fc04],
PUP.Optional.ICQPlugin.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\icqplugin.xml, In Quarantäne, [a208220001899a9c134da8f1659e7b85],
PUP.Optional.Conduit.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\searchplugins\conduit.xml, In Quarantäne, [624890923456082e198137a4ed16c838],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\kxrpohpkftco.dll, Löschen bei Neustart, [0f9b1a081377fc3a9496f3a242c1ab55],
PUP.Optional.Wajam.A, C:\Program Files\WajaWebEnhancer\dlls\nyhhkrvzjoatuwr.dll, Löschen bei Neustart, [0f9b1a081377fc3a9496f3a242c1ab55],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\voucher.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\Configuration.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\OptionDlg.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\RegionalSettings.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\UserInterface.xml, In Quarantäne, [5456f52d79112d096aeee8af59aa1de3],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\config.xml, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\Icons.bmp, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\icq6Toolbar.ico, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\ICQUnToolbar.exe, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\logo_small.gif, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\ServiceStarter.exe, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\short.wav, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\Version.txt, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\voucher.bmp, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.ICQToolbar.A, C:\Program Files (x86)\ICQ6Toolbar\voucher2.bmp, In Quarantäne, [ffabb46e6f1b9f978bcea9eedc278e72],
PUP.Optional.Conduit.A, C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\prefs.js, Gut: (), Schlecht: (user_pref("CT2319825.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319825&q=");), Ersetzt,[169438eaa5e559dd3945a964d53130d0]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.111 - Bericht erstellt 25/02/2015 um 23:07:21
# Aktualisiert 18/02/2015 von Xplode
# Datenbank : 2015-02-18.3 [Lokal]
# Betriebssystem : Windows (TM) Vista Home Premium Service Pack 2 (x64)
# Benutzername : Schwarzkopf&Nails - PRIVAT
# Gestarted von : C:\Users\Schwarzkopf&Nails\Downloads\AdwCleaner_4.111.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
[!] Ordner Gelöscht : C:\Program Files (x86)\Conduit
[!] Ordner Gelöscht : C:\Users\Schwarzkopf&Nails\Tutorials
[!] Ordner Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\LocalLow\Conduit
[!] Ordner Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Roaming\dvdvideosoftiehelpers
[!] Ordner Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Roaming\RHEng
[!] Ordner Gelöscht : C:\Users\Schwarzkopf&Nails\Documents\Updater
[!] Ordner Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
Datei Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}.xpi
Datei Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\user.js
Datei Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
Datei Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
Datei Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2319825
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
***** [ Internetbrowser ] *****
-\\ Internet Explorer v9.0.8112.16609
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v35.0.1 (x86 de)
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.SearchEngine", "Suchenhxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2319825&octid=EB_ORIGINAL_CTID&SearchSource=1");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CT2319825.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"803651ba7facb1:0\"");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\"");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.EngineOwner", "");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.EngineOwnerGuid", "");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.EngineOwnerToolbarId", "");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.IsEngineShown", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.OriginalEngineOwner", "");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.properties");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2319825");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2319825");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon May 09 2011 16:40:37 GMT+0200");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.locale", "en");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon May 09 2011 16:40:36 GMT+0200");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1303303927");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.showTrayIcon", false);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.alert.userId", "de50f63a-0141-47a8-ab5f-f106104e040b");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun May 30 2010 16:06:28 GMT+0200");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2319825");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.twitter.user_45621383.LastCheckTime", "Sun May 30 2010 16:26:09 GMT+0200");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultthis.engineName", "Winload Customized Web Search");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.allowSendURL", false);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.defSearchChange", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.engineVerified", false);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.geolastmodified", 1320919740);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.history", "regendusche%20anbringenduscheArdian%20Bujupi%20-%20This%20is%20my%20Timebabyzimmerrockstarbadplanerdesigner%20fliesenmosaik%20weissbadmosaik%20barbud[...]
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.hpChange", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.icqgeo", 49);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.installTime", "1320663882");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.installsource", "1");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.newtab_state", "0");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.previousFFVersion", "7.0.1");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.suggestions", false);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.uniqueID", "129707436312970741601297201516238");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1321208055);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.userEngineApproved", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.userHpApproved", true);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.version", "1.3.6");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.voucherWasShown", 0);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.xmlEnableHomePageDsGuard", false);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
[xa7z13sl.default\prefs.js] - Zeile Gelöscht : user_pref("keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.6&q=");
-\\ Google Chrome v40.0.2214.115
*************************
AdwCleaner[R0].txt - [12750 Bytes] - [25/02/2015 23:05:08]
AdwCleaner[S0].txt - [12653 Bytes] - [25/02/2015 23:07:21]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12713 Bytes] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows (TM) Vista Home Premium x64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Windows\wininit.ini"
~~~ Folders
~~~ FireFox
user_pref("CT2319825.CTID", "CT2319825");
user_pref("CT2319825.CurrentServerDate", "30-5-2010");
user_pref("CT2319825.DialogsAlignMode", "LTR");
user_pref("CT2319825.EMailNotifierPollDate", "Sun May 30 2010 16:31:11 GMT+0200");
user_pref("CT2319825.FeedLastCount128902288263982011", 10);
user_pref("CT2319825.FeedLastCount129056115025381886", 10);
user_pref("CT2319825.FeedLastCount129098533413278042", 0);
user_pref("CT2319825.FeedLastCount129125391839060113", 0);
user_pref("CT2319825.FeedLastCount129136397984372631", 60);
user_pref("CT2319825.FeedPollDate11908299", "Sun May 30 2010 16:56:09 GMT+0200");
user_pref("CT2319825.FeedPollDate128902288263982011", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.FeedPollDate129056115025381886", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.FeedPollDate129098533413278042", "Sun May 30 2010 16:26:09 GMT+0200");
user_pref("CT2319825.FeedPollDate129125391839060113", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.FeedPollDate129136397985935164", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.FeedPollDate129136397985935165", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.FeedPollDate129136397985935166", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.FeedTTL129136397985935164", 40);
user_pref("CT2319825.FeedTTL129136397985935165", 40);
user_pref("CT2319825.FeedTTL129136397985935166", 40);
user_pref("CT2319825.FirstServerDate", "30-5-2010");
user_pref("CT2319825.FirstTime", true);
user_pref("CT2319825.FirstTimeFF3", true);
user_pref("CT2319825.FixPageNotFoundErrors", true);
user_pref("CT2319825.GroupingServerCheckInterval", 1440);
user_pref("CT2319825.Initialize", true);
user_pref("CT2319825.InitializeCommonPrefs", true);
user_pref("CT2319825.InstalledDate", "Sun May 30 2010 16:06:27 GMT+0200");
user_pref("CT2319825.InvalidateCache", false);
user_pref("CT2319825.IsGrouping", false);
user_pref("CT2319825.IsMulticommunity", false);
user_pref("CT2319825.IsOpenThankYouPage", false);
user_pref("CT2319825.IsOpenUninstallPage", true);
user_pref("CT2319825.LanguagePackLastCheckTime", "Sun May 30 2010 16:06:29 GMT+0200");
user_pref("CT2319825.LanguagePackReloadIntervalMM", 1440);
user_pref("CT2319825.LastLogin_2.5.8.6", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.LatestVersion", "2.1.0.18");
user_pref("CT2319825.Locale", "de");
user_pref("CT2319825.LoginCache", 4);
user_pref("CT2319825.MCDetectTooltipHeight", "83");
user_pref("CT2319825.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
user_pref("CT2319825.MCDetectTooltipWidth", "295");
user_pref("CT2319825.RadioIsPodcast", false);
user_pref("CT2319825.RadioLastCheckTime", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.RadioLastUpdateIPServer", "3");
user_pref("CT2319825.RadioLastUpdateServer", "129089199971230000");
user_pref("CT2319825.RadioMediaID", "11949532");
user_pref("CT2319825.RadioMediaType", "Media Player");
user_pref("CT2319825.RadioMenuSelectedID", "EBRadioMenu_CT231982511949532");
user_pref("CT2319825.RadioStationName", "1Live");
user_pref("CT2319825.RadioStationURL", "hxxp://gffstream.ic.llnwd.net/stream/gffstream_stream_wdr_einslive_a");
user_pref("CT2319825.SHRINK_TOOLBAR", 1);
user_pref("CT2319825.SavedHomepage", "resource:/browserconfig.properties");
user_pref("CT2319825.SearchFromAddressBarIsInit", true);
user_pref("CT2319825.SearchInNewTabEnabled", true);
user_pref("CT2319825.SearchInNewTabIntervalMM", 1440);
user_pref("CT2319825.SearchInNewTabLastCheckTime", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.SettingsCheckIntervalMin", 120);
user_pref("CT2319825.SettingsLastCheckTime", "Sun May 30 2010 16:06:21 GMT+0200");
user_pref("CT2319825.SettingsLastUpdate", "1274806145");
user_pref("CT2319825.ThirdPartyComponentsInterval", 504);
user_pref("CT2319825.ThirdPartyComponentsLastCheck", "Sun May 30 2010 16:06:21 GMT+0200");
user_pref("CT2319825.ThirdPartyComponentsLastUpdate", "1274806145");
user_pref("CT2319825.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=101&sealid=112");
user_pref("CT2319825.UserID", "UN95194845687367965");
user_pref("CT2319825.ValidationData_Toolbar", 0);
user_pref("CT2319825.WeatherNetwork", "");
user_pref("CT2319825.WeatherPollDate", "Sun May 30 2010 16:06:28 GMT+0200");
user_pref("CT2319825.WeatherUnit", "C");
user_pref("CT2319825.alertChannelId", "715912");
user_pref("CT2319825.clientLogIsEnabled", true);
user_pref("CT2319825.myStuffEnabled", true);
user_pref("CT2319825.myStuffPublihserMinWidth", 400);
user_pref("CT2319825.myStuffServiceIntervalMM", 1440);
Emptied folder: C:\Users\Schwarzkopf&Nails\AppData\Roaming\mozilla\firefox\profiles\xa7z13sl.default\minidumps [29 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.02.2015 at 23:26:28,69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-02-2015 01
Ran by Schwarzkopf&Nails (administrator) on PRIVAT on 25-02-2015 23:35:42
Running from c:\Users\Schwarzkopf&Nails\Downloads
Loaded Profiles: Schwarzkopf&Nails (Available profiles: Schwarzkopf&Nails)
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Packard Bell BV) C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
() C:\Windows\Samsung\PanelMgr\caller64.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6242816 2008-04-24] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [225792 2008-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SmpcSys] => C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe [1038136 2008-07-07] (Packard Bell BV)
HKLM-x32\...\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\SSMMgr.exe [524288 2008-08-08] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\ezShellStart.exe, [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\...\Run: [SmpcSys] => C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe [1038136 2008-07-07] (Packard Bell BV)
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\...\Run: [WMPNSCFG] => C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
Startup: C:\Users\Schwarzkopf&Nails\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3728198647-4080070119-460406438-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: SparweltGutscheinAlarm.Sparwelt_Gutschein_Tool -> {10945114-b19f-4614-8450-b25e444a1020} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKU\S-1-5-21-3728198647-4080070119-460406438-1000 -> &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: HKLM-x32 {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v1111/Navigram.cab
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} Microsoft Office Download - Microsoft Store Deutschland
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [49152 2010-05-30] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-12-22]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-06-01]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-01-16]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Kaspersky виртуелна тастатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Gevaarlijke websiteblokkering - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-02-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-21]
CHR Extension: (Google Search) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2012-02-10]
CHR Extension: (Kaspersky Protection) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpoimibckejjdjcfbdnajaicnklhfplh [2014-05-27]
CHR Extension: (Google Wallet) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-01-23]
CHR Extension: (Gmail) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19]
CHR Extension: (Anti-Banner) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2012-02-10]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2011-01-31] (Adobe Systems) [File not signed]
R2 AdobeActiveFileMonitor6.0; C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832 2007-09-10] ()
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2008-10-21] (Macrovision Europe Ltd.) [File not signed]
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-04-28] (Nero AG)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-03-07] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [54072 2007-08-13] (Samsung Electronics)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [91008 2014-05-27] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [628320 2014-05-27] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-28] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [177864 2015-02-17] (Kaspersky Lab ZAO)
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.)
S3 PCAMp50a64; C:\Windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 PCASp50a64; C:\Windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 23:35 - 2015-02-25 23:35 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Downloads\FRST-OlderVersion
2015-02-25 23:26 - 2015-02-25 23:26 - 00005490 _____ () C:\Users\Schwarzkopf&Nails\Desktop\JRT.txt
2015-02-25 23:19 - 2015-02-25 23:19 - 01388274 _____ (Thisisu) C:\Users\Schwarzkopf&Nails\Desktop\JRT.exe
2015-02-25 23:04 - 2015-02-25 23:07 - 00000000 ____D () C:\AdwCleaner
2015-02-25 23:03 - 2015-02-25 23:03 - 02126848 _____ () C:\Users\Schwarzkopf&Nails\Downloads\AdwCleaner_4.111.exe
2015-02-25 23:01 - 2015-02-25 23:01 - 00015302 _____ () C:\Users\Schwarzkopf&Nails\Desktop\mbam.txt
2015-02-25 22:09 - 2015-02-25 22:59 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-25 22:09 - 2015-02-25 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-25 22:09 - 2015-02-25 22:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-25 22:09 - 2015-02-25 22:09 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-25 22:09 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-25 22:09 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-25 22:06 - 2015-02-25 22:07 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Schwarzkopf&Nails\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-25 21:58 - 2015-02-25 21:58 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Schwarzkopf&Nails\Downloads\revosetup95.exe
2015-02-25 21:58 - 2015-02-25 21:58 - 00001101 _____ () C:\Users\Schwarzkopf&Nails\Desktop\Revo Uninstaller.lnk
2015-02-25 21:58 - 2015-02-25 21:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-24 15:22 - 2015-02-24 15:23 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (6)
2015-02-23 09:46 - 2015-02-23 09:49 - 00029172 _____ () C:\Users\Schwarzkopf&Nails\Downloads\Addition.txt
2015-02-23 09:45 - 2015-02-25 23:35 - 00021103 _____ () C:\Users\Schwarzkopf&Nails\Downloads\FRST.txt
2015-02-23 09:44 - 2015-02-25 23:35 - 02087936 _____ (Farbar) C:\Users\Schwarzkopf&Nails\Downloads\FRST64.exe
2015-02-23 09:44 - 2015-02-25 23:35 - 00000000 ____D () C:\FRST
2015-02-23 00:37 - 2015-02-23 00:37 - 06372800 _____ (Tim Kosse) C:\Users\Schwarzkopf&Nails\Downloads\FileZilla_3.10.1.1_win32-setup.exe
2015-02-23 00:37 - 2015-02-23 00:37 - 06057862 _____ (Tim Kosse) C:\Users\Schwarzkopf&Nails\Downloads\FileZilla_3.9.0.5_win32-setup.exe
2015-02-23 00:13 - 2015-02-23 00:13 - 00002495 _____ () C:\Users\Schwarzkopf&Nails\Downloads\Eine Nachricht von Ihrem Kontaktformular (1)
2015-02-23 00:12 - 2015-02-23 00:12 - 00002495 _____ () C:\Users\Schwarzkopf&Nails\Downloads\Eine Nachricht von Ihrem Kontaktformular
2015-02-22 18:11 - 2015-02-22 18:12 - 03312104 _____ (DVDVideoSoft Ltd. ) C:\Users\Schwarzkopf&Nails\Downloads\FreeYouTubeDownload.exe
2015-02-17 01:02 - 2015-02-17 01:02 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (5)
2015-02-17 00:51 - 2015-02-24 15:46 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\konzept
2015-02-16 21:16 - 2015-02-24 16:20 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\rosen
2015-02-14 17:41 - 2015-02-24 16:20 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (2)
2015-02-14 17:41 - 2015-02-22 22:59 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (2)(214)
2015-02-13 22:08 - 2015-02-17 01:37 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\comic
2015-02-13 20:14 - 2015-01-23 05:07 - 02339840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-13 20:14 - 2015-01-23 04:59 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-02-13 20:14 - 2015-01-23 04:00 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-13 20:14 - 2015-01-23 03:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-02-13 11:19 - 2015-01-09 01:34 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-13 11:19 - 2014-12-08 02:59 - 00306176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-13 11:19 - 2014-12-08 02:37 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-13 11:18 - 2014-11-26 03:05 - 00564224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-13 11:18 - 2014-11-26 02:42 - 00847360 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-13 11:17 - 2015-01-13 02:51 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-13 11:17 - 2015-01-13 02:39 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-13 11:08 - 2015-01-15 07:53 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-13 11:08 - 2015-01-15 05:08 - 00516536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-12 21:50 - 2015-01-14 04:08 - 17878016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-12 21:50 - 2015-01-14 03:59 - 10924032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-12 21:50 - 2015-01-14 03:59 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-02-12 21:50 - 2015-01-14 03:49 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-12 21:50 - 2015-01-14 03:49 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-12 21:50 - 2015-01-14 03:47 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-12 21:50 - 2015-01-14 03:47 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-12 21:50 - 2015-01-14 03:47 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-02-12 21:50 - 2015-01-14 03:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-12 21:50 - 2015-01-14 03:46 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-12 21:50 - 2015-01-14 03:46 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-12 21:50 - 2015-01-14 03:45 - 02157056 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-12 21:50 - 2015-01-14 03:45 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-12 21:50 - 2015-01-14 03:45 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-12 21:50 - 2015-01-14 03:44 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-02-12 21:50 - 2015-01-14 03:44 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-02-12 21:50 - 2015-01-14 02:51 - 12371456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-12 21:50 - 2015-01-14 02:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-02-12 21:50 - 2015-01-14 02:46 - 09742336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-12 21:50 - 2015-01-14 02:43 - 01139712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-12 21:50 - 2015-01-14 02:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-12 21:50 - 2015-01-14 02:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 01802752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-12 21:50 - 2015-01-14 02:41 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-12 21:50 - 2015-01-14 02:40 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-02-12 21:50 - 2015-01-14 02:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 23:17 - 2009-12-12 01:11 - 01504594 _____ () C:\Windows\WindowsUpdate.log
2015-02-25 23:16 - 2008-01-21 12:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-25 23:16 - 2008-01-21 12:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2015-02-25 23:16 - 2008-01-21 12:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2015-02-25 23:12 - 2012-02-10 10:52 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-02-25 23:10 - 2010-07-15 09:18 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-25 23:10 - 2010-07-02 23:04 - 00000320 _____ () C:\Windows\Tasks\RtlVistaStart.job
2015-02-25 23:10 - 2006-11-02 16:22 - 00004784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-25 23:10 - 2006-11-02 16:22 - 00004784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-25 23:09 - 2010-05-30 12:48 - 00000000 ____D () C:\Users\Schwarzkopf&Nails
2015-02-25 23:09 - 2008-01-21 04:26 - 00297516 _____ () C:\Windows\PFRO.log
2015-02-25 23:09 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-25 23:08 - 2006-11-02 16:42 - 00032602 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-25 22:59 - 2014-04-07 20:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-25 22:47 - 2011-02-08 22:45 - 00000000 ____D () C:\ProgramData\ICQ
2015-02-25 22:23 - 2014-01-30 18:13 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\motive
2015-02-25 22:12 - 2015-01-20 20:17 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\ostern
2015-02-25 22:09 - 2010-07-15 09:18 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-24 16:33 - 2006-11-02 14:34 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-02-24 16:32 - 2006-11-02 13:33 - 86245376 _____ () C:\Windows\system32\config\software_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 79429632 _____ () C:\Windows\system32\config\system_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 56623104 _____ () C:\Windows\system32\config\components_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 00262144 _____ () C:\Windows\system32\config\security_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 00262144 _____ () C:\Windows\system32\config\default_previous
2015-02-24 16:20 - 2013-03-06 23:28 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Documents\BFBC2
2015-02-24 16:20 - 2011-01-27 00:15 - 00000000 ___RD () C:\Users\Schwarzkopf&Nails\Desktop\Festplatte
2015-02-24 16:20 - 2010-10-10 22:10 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\AppData\Roaming\DVDVideoSoft
2015-02-24 16:20 - 2010-08-12 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-24 16:20 - 2010-07-18 17:29 - 00000000 ___HD () C:\Users\Schwarzkopf&Nails\Desktop\.picasaoriginals
2015-02-24 16:20 - 2010-05-30 13:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-24 16:20 - 2006-11-02 14:34 - 00000000 ____D () C:\Windows\system32\spool
2015-02-24 16:20 - 2006-11-02 14:33 - 00000000 __RSD () C:\Windows\Media
2015-02-24 16:19 - 2006-11-02 14:33 - 00000000 ____D () C:\Windows\registration
2015-02-24 15:40 - 2012-07-30 15:40 - 00000000 ___RD () C:\Users\Schwarzkopf&Nails\Desktop\BACKEN_KOCHEN
2015-02-24 13:50 - 2015-01-12 20:40 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\GlitzerOrdnung
2015-02-23 00:44 - 2011-02-21 01:47 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\AppData\Roaming\FileZilla
2015-02-22 23:14 - 2013-09-16 11:46 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\sortiren
2015-02-22 22:50 - 2015-01-12 20:41 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\HAUSEINRICHTUNG
2015-02-22 18:35 - 2010-05-30 21:35 - 00000069 _____ () C:\Windows\NeroDigital.ini
2015-02-22 18:23 - 2010-05-30 17:16 - 00030208 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-19 21:53 - 2013-03-06 23:28 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-02-19 21:53 - 2011-04-03 13:54 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-02-19 21:51 - 2011-04-03 13:54 - 00215128 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-02-17 21:13 - 2012-08-13 16:49 - 00177864 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2015-02-17 01:37 - 2015-01-11 16:10 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Vintageideen
2015-02-17 01:27 - 2014-02-16 21:45 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\nägel sortieren
2015-02-17 00:59 - 2010-05-30 16:37 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Zur_Bearbeitung
2015-02-17 00:56 - 2011-01-26 18:40 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Sonstiges
2015-02-14 12:35 - 2014-11-26 19:35 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (4)
2015-02-14 12:26 - 2013-04-13 15:00 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\MODE
2015-02-13 11:38 - 2006-11-02 16:21 - 00408888 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-13 11:17 - 2008-10-21 13:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-13 11:08 - 2013-08-18 21:04 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-13 10:59 - 2006-11-02 13:35 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-02-12 20:23 - 2015-01-22 19:29 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (3)
2015-02-11 20:24 - 2014-09-13 23:28 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Handyfotos
2015-02-04 23:59 - 2014-04-07 20:27 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 23:59 - 2013-07-09 18:08 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-04 23:59 - 2011-06-01 19:06 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-04 23:04 - 2010-07-15 09:18 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-04 23:04 - 2010-07-15 09:18 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-02 18:25 - 2015-01-16 23:38 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\valentinstag
2015-02-02 18:23 - 2015-01-11 16:11 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Frühling
==================== Files in the root of some directories =======
2007-03-12 17:59 - 2007-03-12 17:59 - 0299008 _____ () C:\Program Files (x86)\navigram_register.exe
2010-06-30 10:09 - 2010-06-30 10:09 - 0020317 _____ () C:\Users\Schwarzkopf&Nails\AppData\Roaming\UserTile.png
2010-05-30 15:56 - 2010-06-30 13:04 - 0000132 _____ () C:\Users\Schwarzkopf&Nails\AppData\Roaming\wklnhst.dat
2010-06-16 12:51 - 2014-10-13 10:07 - 0000680 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\d3d9caps.dat
2013-08-27 17:27 - 2014-11-27 14:23 - 0000732 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\d3d9caps64.dat
2010-05-30 17:16 - 2015-02-22 18:23 - 0030208 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-05-30 15:23 - 2010-05-30 15:23 - 0427532 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistMSI21E8.txt
2014-01-14 21:46 - 2014-01-14 21:46 - 0362874 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistMSI2D3A.txt
2012-06-11 17:38 - 2012-06-11 17:39 - 0411666 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistMSI4E31.txt
2010-05-30 15:23 - 2010-05-30 15:23 - 0011610 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistUI21E8.txt
2014-01-14 21:46 - 2014-01-14 21:46 - 0012134 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistUI2D3A.txt
2012-06-11 17:38 - 2012-06-11 17:39 - 0011378 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistUI4E31.txt
2012-12-22 10:01 - 2012-12-22 10:01 - 0004096 ____H () C:\Users\Schwarzkopf&Nails\AppData\Local\keyfile3.drm
2012-02-10 10:57 - 2012-02-10 10:57 - 0017408 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\WebpageIcons.db
Some content of TEMP:
====================
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\0a50e25a83046228c11dcaa7eeed09bb.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\AskSLib.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\AutoRun.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\contentDATs.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\DivXSetup.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dyndata_7330014.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dyndata_7380009.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\EAD5F6D.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\eauninstall.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\firefoxjre_exe-1.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\First15.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\installerdll36002534.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\installerdll8673405.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\installerdll8693904.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u30-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\MS Office Enterprise 2007.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Quarantine.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\rootsupd.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Setup.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Shockwave_Installer_FF.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\sqlite3.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\VP6Install.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\VP6VFW.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\WindowsInstaller-KB893803-v2-x86.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Winload.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\_is57EF.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\_is7889.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-25 23:18
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-02-2015 01
Ran by Schwarzkopf&Nails (administrator) on PRIVAT on 25-02-2015 23:35:42
Running from c:\Users\Schwarzkopf&Nails\Downloads
Loaded Profiles: Schwarzkopf&Nails (Available profiles: Schwarzkopf&Nails)
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\Pac207\Monitor.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe
(Packard Bell BV) C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
() C:\Windows\Samsung\PanelMgr\SSMMgr.exe
() C:\Windows\Samsung\PanelMgr\caller64.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6242816 2008-04-24] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-11-20] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [225792 2008-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [SmpcSys] => C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe [1038136 2008-07-07] (Packard Bell BV)
HKLM-x32\...\Run: [Samsung PanelMgr] => C:\Windows\Samsung\PanelMgr\SSMMgr.exe [524288 2008-08-08] ()
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\ezShellStart.exe, [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\...\Run: [SmpcSys] => C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe [1038136 2008-07-07] (Packard Bell BV)
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\...\Run: [WMPNSCFG] => C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
Startup: C:\Users\Schwarzkopf&Nails\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKU\S-1-5-21-3728198647-4080070119-460406438-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&s=1&o=vp64&d=1209&m=imedia_x5500_ge
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3728198647-4080070119-460406438-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: SparweltGutscheinAlarm.Sparwelt_Gutschein_Tool -> {10945114-b19f-4614-8450-b25e444a1020} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKU\S-1-5-21-3728198647-4080070119-460406438-1000 -> &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: HKLM-x32 {6E718D87-6909-4FCE-92D4-EDCB2F725727} hxxp://www.navigram.com/engine/v1111/Navigram.cab
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} Microsoft Office Download - Microsoft Store Deutschland
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [49152 2010-05-30] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Schwarzkopf&Nails\AppData\Roaming\Mozilla\Firefox\Profiles\xa7z13sl.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-12-22]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2010-06-01]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-01-16]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Kaspersky виртуелна тастатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Gevaarlijke websiteblokkering - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-02-04]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-02-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-21]
CHR Extension: (Google Search) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2012-02-10]
CHR Extension: (Kaspersky Protection) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpoimibckejjdjcfbdnajaicnklhfplh [2014-05-27]
CHR Extension: (Google Wallet) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-01-23]
CHR Extension: (Gmail) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19]
CHR Extension: (Anti-Banner) - C:\Users\Schwarzkopf&Nails\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2012-02-10]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2011-01-31] (Adobe Systems) [File not signed]
R2 AdobeActiveFileMonitor6.0; C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [124832 2007-09-10] ()
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezsvc7.dll [129992 2008-02-03] (EasyBits Sofware AS) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2008-10-21] (Macrovision Europe Ltd.) [File not signed]
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-02-18] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [529704 2008-04-28] (Nero AG)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-03-07] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [54072 2007-08-13] (Samsung Electronics)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [91008 2014-05-27] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [628320 2014-05-27] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-28] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [177864 2015-02-17] (Kaspersky Lab ZAO)
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [572416 2006-12-05] (PixArt Imaging Inc.)
S3 PCAMp50a64; C:\Windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 PCASp50a64; C:\Windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 23:35 - 2015-02-25 23:35 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Downloads\FRST-OlderVersion
2015-02-25 23:26 - 2015-02-25 23:26 - 00005490 _____ () C:\Users\Schwarzkopf&Nails\Desktop\JRT.txt
2015-02-25 23:19 - 2015-02-25 23:19 - 01388274 _____ (Thisisu) C:\Users\Schwarzkopf&Nails\Desktop\JRT.exe
2015-02-25 23:04 - 2015-02-25 23:07 - 00000000 ____D () C:\AdwCleaner
2015-02-25 23:03 - 2015-02-25 23:03 - 02126848 _____ () C:\Users\Schwarzkopf&Nails\Downloads\AdwCleaner_4.111.exe
2015-02-25 23:01 - 2015-02-25 23:01 - 00015302 _____ () C:\Users\Schwarzkopf&Nails\Desktop\mbam.txt
2015-02-25 22:09 - 2015-02-25 22:59 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-25 22:09 - 2015-02-25 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-25 22:09 - 2015-02-25 22:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-25 22:09 - 2015-02-25 22:09 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-25 22:09 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-25 22:09 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-25 22:06 - 2015-02-25 22:07 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Schwarzkopf&Nails\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-25 21:58 - 2015-02-25 21:58 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Schwarzkopf&Nails\Downloads\revosetup95.exe
2015-02-25 21:58 - 2015-02-25 21:58 - 00001101 _____ () C:\Users\Schwarzkopf&Nails\Desktop\Revo Uninstaller.lnk
2015-02-25 21:58 - 2015-02-25 21:58 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-24 15:22 - 2015-02-24 15:23 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (6)
2015-02-23 09:46 - 2015-02-23 09:49 - 00029172 _____ () C:\Users\Schwarzkopf&Nails\Downloads\Addition.txt
2015-02-23 09:45 - 2015-02-25 23:35 - 00021103 _____ () C:\Users\Schwarzkopf&Nails\Downloads\FRST.txt
2015-02-23 09:44 - 2015-02-25 23:35 - 02087936 _____ (Farbar) C:\Users\Schwarzkopf&Nails\Downloads\FRST64.exe
2015-02-23 09:44 - 2015-02-25 23:35 - 00000000 ____D () C:\FRST
2015-02-23 00:37 - 2015-02-23 00:37 - 06372800 _____ (Tim Kosse) C:\Users\Schwarzkopf&Nails\Downloads\FileZilla_3.10.1.1_win32-setup.exe
2015-02-23 00:37 - 2015-02-23 00:37 - 06057862 _____ (Tim Kosse) C:\Users\Schwarzkopf&Nails\Downloads\FileZilla_3.9.0.5_win32-setup.exe
2015-02-23 00:13 - 2015-02-23 00:13 - 00002495 _____ () C:\Users\Schwarzkopf&Nails\Downloads\Eine Nachricht von Ihrem Kontaktformular (1)
2015-02-23 00:12 - 2015-02-23 00:12 - 00002495 _____ () C:\Users\Schwarzkopf&Nails\Downloads\Eine Nachricht von Ihrem Kontaktformular
2015-02-22 18:11 - 2015-02-22 18:12 - 03312104 _____ (DVDVideoSoft Ltd. ) C:\Users\Schwarzkopf&Nails\Downloads\FreeYouTubeDownload.exe
2015-02-17 01:02 - 2015-02-17 01:02 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (5)
2015-02-17 00:51 - 2015-02-24 15:46 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\konzept
2015-02-16 21:16 - 2015-02-24 16:20 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\rosen
2015-02-14 17:41 - 2015-02-24 16:20 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (2)
2015-02-14 17:41 - 2015-02-22 22:59 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (2)(214)
2015-02-13 22:08 - 2015-02-17 01:37 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\comic
2015-02-13 20:14 - 2015-01-23 05:07 - 02339840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-13 20:14 - 2015-01-23 04:59 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-02-13 20:14 - 2015-01-23 04:00 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-13 20:14 - 2015-01-23 03:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-02-13 11:19 - 2015-01-09 01:34 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-13 11:19 - 2014-12-08 02:59 - 00306176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-13 11:19 - 2014-12-08 02:37 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-13 11:18 - 2014-11-26 03:05 - 00564224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-13 11:18 - 2014-11-26 02:42 - 00847360 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-13 11:17 - 2015-01-13 02:51 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-13 11:17 - 2015-01-13 02:39 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-13 11:08 - 2015-01-15 07:53 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-13 11:08 - 2015-01-15 05:08 - 00516536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-12 21:50 - 2015-01-14 04:08 - 17878016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-12 21:50 - 2015-01-14 03:59 - 10924032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-12 21:50 - 2015-01-14 03:59 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-02-12 21:50 - 2015-01-14 03:49 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-12 21:50 - 2015-01-14 03:49 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-12 21:50 - 2015-01-14 03:47 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-12 21:50 - 2015-01-14 03:47 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-12 21:50 - 2015-01-14 03:47 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-02-12 21:50 - 2015-01-14 03:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-12 21:50 - 2015-01-14 03:46 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-12 21:50 - 2015-01-14 03:46 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-12 21:50 - 2015-01-14 03:45 - 02157056 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-12 21:50 - 2015-01-14 03:45 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-12 21:50 - 2015-01-14 03:45 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-12 21:50 - 2015-01-14 03:44 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-02-12 21:50 - 2015-01-14 03:44 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-02-12 21:50 - 2015-01-14 03:44 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-02-12 21:50 - 2015-01-14 02:51 - 12371456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-12 21:50 - 2015-01-14 02:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-02-12 21:50 - 2015-01-14 02:46 - 09742336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-12 21:50 - 2015-01-14 02:43 - 01139712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-12 21:50 - 2015-01-14 02:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-12 21:50 - 2015-01-14 02:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 01802752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-02-12 21:50 - 2015-01-14 02:41 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-12 21:50 - 2015-01-14 02:41 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-12 21:50 - 2015-01-14 02:40 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-02-12 21:50 - 2015-01-14 02:40 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-02-12 21:50 - 2015-01-14 02:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 23:17 - 2009-12-12 01:11 - 01504594 _____ () C:\Windows\WindowsUpdate.log
2015-02-25 23:16 - 2008-01-21 12:10 - 01567488 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-25 23:16 - 2008-01-21 12:09 - 00674024 _____ () C:\Windows\system32\perfh007.dat
2015-02-25 23:16 - 2008-01-21 12:09 - 00146036 _____ () C:\Windows\system32\perfc007.dat
2015-02-25 23:12 - 2012-02-10 10:52 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-02-25 23:10 - 2010-07-15 09:18 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-25 23:10 - 2010-07-02 23:04 - 00000320 _____ () C:\Windows\Tasks\RtlVistaStart.job
2015-02-25 23:10 - 2006-11-02 16:22 - 00004784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-25 23:10 - 2006-11-02 16:22 - 00004784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-25 23:09 - 2010-05-30 12:48 - 00000000 ____D () C:\Users\Schwarzkopf&Nails
2015-02-25 23:09 - 2008-01-21 04:26 - 00297516 _____ () C:\Windows\PFRO.log
2015-02-25 23:09 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-25 23:08 - 2006-11-02 16:42 - 00032602 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-25 22:59 - 2014-04-07 20:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-25 22:47 - 2011-02-08 22:45 - 00000000 ____D () C:\ProgramData\ICQ
2015-02-25 22:23 - 2014-01-30 18:13 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\motive
2015-02-25 22:12 - 2015-01-20 20:17 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\ostern
2015-02-25 22:09 - 2010-07-15 09:18 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-24 16:33 - 2006-11-02 14:34 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-02-24 16:32 - 2006-11-02 13:33 - 86245376 _____ () C:\Windows\system32\config\software_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 79429632 _____ () C:\Windows\system32\config\system_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 56623104 _____ () C:\Windows\system32\config\components_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 00262144 _____ () C:\Windows\system32\config\security_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2015-02-24 16:32 - 2006-11-02 13:33 - 00262144 _____ () C:\Windows\system32\config\default_previous
2015-02-24 16:20 - 2013-03-06 23:28 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Documents\BFBC2
2015-02-24 16:20 - 2011-01-27 00:15 - 00000000 ___RD () C:\Users\Schwarzkopf&Nails\Desktop\Festplatte
2015-02-24 16:20 - 2010-10-10 22:10 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\AppData\Roaming\DVDVideoSoft
2015-02-24 16:20 - 2010-08-12 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-24 16:20 - 2010-07-18 17:29 - 00000000 ___HD () C:\Users\Schwarzkopf&Nails\Desktop\.picasaoriginals
2015-02-24 16:20 - 2010-05-30 13:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-24 16:20 - 2006-11-02 14:34 - 00000000 ____D () C:\Windows\system32\spool
2015-02-24 16:20 - 2006-11-02 14:33 - 00000000 __RSD () C:\Windows\Media
2015-02-24 16:19 - 2006-11-02 14:33 - 00000000 ____D () C:\Windows\registration
2015-02-24 15:40 - 2012-07-30 15:40 - 00000000 ___RD () C:\Users\Schwarzkopf&Nails\Desktop\BACKEN_KOCHEN
2015-02-24 13:50 - 2015-01-12 20:40 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\GlitzerOrdnung
2015-02-23 00:44 - 2011-02-21 01:47 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\AppData\Roaming\FileZilla
2015-02-22 23:14 - 2013-09-16 11:46 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\sortiren
2015-02-22 22:50 - 2015-01-12 20:41 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\HAUSEINRICHTUNG
2015-02-22 18:35 - 2010-05-30 21:35 - 00000069 _____ () C:\Windows\NeroDigital.ini
2015-02-22 18:23 - 2010-05-30 17:16 - 00030208 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-19 21:53 - 2013-03-06 23:28 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-02-19 21:53 - 2011-04-03 13:54 - 00282296 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-02-19 21:51 - 2011-04-03 13:54 - 00215128 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-02-17 21:13 - 2012-08-13 16:49 - 00177864 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2015-02-17 01:37 - 2015-01-11 16:10 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Vintageideen
2015-02-17 01:27 - 2014-02-16 21:45 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\nägel sortieren
2015-02-17 00:59 - 2010-05-30 16:37 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Zur_Bearbeitung
2015-02-17 00:56 - 2011-01-26 18:40 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Sonstiges
2015-02-14 12:35 - 2014-11-26 19:35 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (4)
2015-02-14 12:26 - 2013-04-13 15:00 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\MODE
2015-02-13 11:38 - 2006-11-02 16:21 - 00408888 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-13 11:17 - 2008-10-21 13:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-13 11:08 - 2013-08-18 21:04 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-13 10:59 - 2006-11-02 13:35 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-02-12 20:23 - 2015-01-22 19:29 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Neuer Ordner (3)
2015-02-11 20:24 - 2014-09-13 23:28 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Handyfotos
2015-02-04 23:59 - 2014-04-07 20:27 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 23:59 - 2013-07-09 18:08 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-04 23:59 - 2011-06-01 19:06 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-04 23:04 - 2010-07-15 09:18 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-04 23:04 - 2010-07-15 09:18 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-02 18:25 - 2015-01-16 23:38 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\valentinstag
2015-02-02 18:23 - 2015-01-11 16:11 - 00000000 ____D () C:\Users\Schwarzkopf&Nails\Desktop\Frühling
==================== Files in the root of some directories =======
2007-03-12 17:59 - 2007-03-12 17:59 - 0299008 _____ () C:\Program Files (x86)\navigram_register.exe
2010-06-30 10:09 - 2010-06-30 10:09 - 0020317 _____ () C:\Users\Schwarzkopf&Nails\AppData\Roaming\UserTile.png
2010-05-30 15:56 - 2010-06-30 13:04 - 0000132 _____ () C:\Users\Schwarzkopf&Nails\AppData\Roaming\wklnhst.dat
2010-06-16 12:51 - 2014-10-13 10:07 - 0000680 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\d3d9caps.dat
2013-08-27 17:27 - 2014-11-27 14:23 - 0000732 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\d3d9caps64.dat
2010-05-30 17:16 - 2015-02-22 18:23 - 0030208 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-05-30 15:23 - 2010-05-30 15:23 - 0427532 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistMSI21E8.txt
2014-01-14 21:46 - 2014-01-14 21:46 - 0362874 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistMSI2D3A.txt
2012-06-11 17:38 - 2012-06-11 17:39 - 0411666 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistMSI4E31.txt
2010-05-30 15:23 - 2010-05-30 15:23 - 0011610 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistUI21E8.txt
2014-01-14 21:46 - 2014-01-14 21:46 - 0012134 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistUI2D3A.txt
2012-06-11 17:38 - 2012-06-11 17:39 - 0011378 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\dd_vcredistUI4E31.txt
2012-12-22 10:01 - 2012-12-22 10:01 - 0004096 ____H () C:\Users\Schwarzkopf&Nails\AppData\Local\keyfile3.drm
2012-02-10 10:57 - 2012-02-10 10:57 - 0017408 _____ () C:\Users\Schwarzkopf&Nails\AppData\Local\WebpageIcons.db
Some content of TEMP:
====================
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\0a50e25a83046228c11dcaa7eeed09bb.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\AskSLib.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\AutoRun.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\contentDATs.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\DivXSetup.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dyndata_7330014.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dyndata_7370012.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\drm_dyndata_7380009.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\EAD5F6D.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\eauninstall.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\firefoxjre_exe-1.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\firefoxjre_exe.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\First15.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\installerdll36002534.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\installerdll8673405.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\installerdll8693904.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-6u30-windows-i586-iftw-rv.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\MS Office Enterprise 2007.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Quarantine.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\rootsupd.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Setup.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Shockwave_Installer_FF.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\sqlite3.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\VP6Install.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\VP6VFW.dll
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\WindowsInstaller-KB893803-v2-x86.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\Winload.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\_is57EF.exe
C:\Users\Schwarzkopf&Nails\AppData\Local\Temp\_is7889.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-25 23:18
==================== End Of Log ============================
--- --- ---
--- --- ---