Chris180294 | 09.03.2015 17:21 | Hey
Malware Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
(end) AWD Cleaner Code:
# AdwCleaner v4.111 - Bericht erstellt 09/03/2015 um 16:51:11
# Aktualisiert 18/02/2015 von Xplode
# Datenbank : 2015-03-05.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Tabea - TABEA-PC
# Gestarted von : C:\Users\Tabea\Desktop\AdwCleaner_4.111.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : sbmntr
Dienst Gelöscht : vToolbarUpdater18.1.9
[#] Dienst Gelöscht : BrsHelper
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\TVWizard
Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\Browser
Ordner Gelöscht : C:\ProgramData\Conduit
Ordner Gelöscht : C:\ProgramData\866380c8000013fa
Ordner Gelöscht : C:\ProgramData\c669c6df00005ae7
Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\AVG Security Toolbar
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\PC Speed Maximizer
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Program Files (x86)\Probit Software
Ordner Gelöscht : C:\Program Files (x86)\vGrabber-software
Ordner Gelöscht : C:\Program Files (x86)\YTDownloader
Ordner Gelöscht : C:\Program Files (x86)\speed browser
Ordner Gelöscht : C:\Program Files (x86)\Assets Manager
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro 3.38
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files\BubbleSound
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\NativeMessaging
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\TVWizard
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\speed browser
Ordner Gelöscht : C:\Users\Tabea\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\ap_logs
Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\Probit Software
Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BubbleSound 1.0
[!] Ordner Gelöscht : C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Ordner Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Datei Gelöscht : C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C}.xpi
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\Reimage.ini
Datei Gelöscht : C:\Users\Tabea\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Tabea\Desktop\YTDownloader.lnk
Datei Gelöscht : C:\Users\Tabea\Desktop\3D BubbleSound.lnk
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\searchplugins\icqplugin.gif
Datei Gelöscht : C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\searchplugins\icqplugin.src
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_api.ciuvo.com_0.localstorage
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_api.ciuvo.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovigo.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
Task Gelöscht : ShopperPro
Task Gelöscht : ShopperProJSUpd
Task Gelöscht : SPDriver
Task Gelöscht : YTDownloader
Task Gelöscht : YTDownloaderUpd
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Tabea\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\conduit.com
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduitapps.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainerV2]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\inetstat.exe
Wert Gelöscht : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [YTDownloader]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ShopperPro.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\YTDownloader.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P4ac8969b_a8e9_4074_8cf0_24db1c47cc7e_.P4ac8969b_a8e9_4074_8cf0_24db1c47cc7e_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P4ac8969b_a8e9_4074_8cf0_24db1c47cc7e_.P4ac8969b_a8e9_4074_8cf0_24db1c47cc7e_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\.
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\..9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4ac8969b-a8e9-4074-8cf0-24db1c47cc7e}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{c3333b78-4d26-4073-b4b6-8f01d9289227}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611381133}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622422201}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345541}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655385533}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655425501}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346641}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666386633}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666426601}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{41F978F3-431A-4464-A789-5C0692D562FB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644424401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ac8969b-a8e9-4074-8cf0-24db1c47cc7e}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4ac8969b-a8e9-4074-8cf0-24db1c47cc7e}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622422201}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345541}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655385533}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655425501}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346641}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666386633}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666426601}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{23D12D0A-CA1B-4D6A-B0CD-BB2C72E24E53}
Schlüssel Gelöscht : HKCU\Software\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\pc speed maximizer
Schlüssel Gelöscht : HKCU\Software\PennyBee
Schlüssel Gelöscht : HKCU\Software\RegisteredApplicationsEx
Schlüssel Gelöscht : HKCU\Software\ShopperPro
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Tutorials
Schlüssel Gelöscht : HKCU\Software\Ciuvo GmbH
Schlüssel Gelöscht : HKCU\Software\YTDownloader
Schlüssel Gelöscht : HKCU\Software\Super Optimizer
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\BackgroundContainer
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\BackgroundContainerV2
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\SpeedBrowser
Schlüssel Gelöscht : HKLM\SOFTWARE\YTDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Schlüssel Gelöscht : HKLM\SOFTWARE\SPPDCOM
Schlüssel Gelöscht : HKLM\SOFTWARE\SearchModule
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B114619-78B7-1CFF-55EF-74266954F883}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Speed Maximizer_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\ShopperPro
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\BubbleSound
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\SearchModule
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BubbleSound
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5081D2D4-1637-404c-B74F-50526718257D}_is1
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\app.mam.conduit.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istart.webssearches.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\trovigo.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\webssearches.com
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17496
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v35.0.1 (x86 de)
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.SearchFromAddressBarUrl", "hxxp://trovi.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&CUI=UN27098573081436117&UM=8&q=");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://www.trovi.com/?gd=&ctid=CT2625848&octid=CT2625848&ISID=ISID_ID&SearchSource=15&CUI=UN27098573081436117&Lay=1&UM=8\[...]
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.originalSearchAddressUrl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.originalSearchEngine", "DVDVideoSoftTB DE Customized Web Search");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.originalSearchEngineName", "DVDVideoSoftTB DE Customized Web Search");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.smartbar.CTID", "CT2625848");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.smartbar.Uninstall", "0");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.smartbar.homepage", true);
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.smartbar.toolbarName", "DVDVideoSoftTB DE ");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.3&q=");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.TBHomepagesList", "hxxp://trovi.com/?UM=8&ctid=CT2625848&SearchSource=13&CUI=UN27098573081436117");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.TBSearchEngineList", "DVDVideoSoftTB DE Customized Web Search");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.TBSearchUrlList", "hxxp://trovi.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&CUI=UN27098573081436117&UM=8&q=");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT2625848");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.xpiState", "{\"app-profile\":{\"6bd508b5-8edf-4661-89eb-5b5186fa62d1@gmail.com\":{\"d\":\"C:\\\\Users\\\\Tabea\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\yn671juw[...]
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.engineVerified", false);
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.firstTbRun", false);
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.geolastmodified", 1425784244);
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.icqgeo", 49);
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.installTime", "1425783990");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.previousFFVersion", "35.0.1");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.uniqueID", "187789689012696201361425783990046");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1425783995);
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("icqtoolbar.version", "1.5.3");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.addressBarOwnerCTID", "CT2625848");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://trovi.com/?UM=8&ctid=CT2625848&SearchSource=13&CUI=UN27098573081436117");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://trovi.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&CUI=UN27098573081436117&UM=8&q=");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.defaultSearchOwnerCTID", "CT2625848");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.homePageOwnerCTID", "CT2625848");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.homepageList", "hxxp://trovi.com/?UM=8&ctid=CT2625848&SearchSource=13&CUI=UN27098573081436117");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.machineId", "XPGYQLJOHYTAHQD0ZW8NOHS3V5AAGVZ0ADFASOHUDXUBUVP8AIYW79ISU46I5OUAWKCFSFCHEWFW15IUMUTEFW");
[yn671juw.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.searchAddressUrlList", "hxxp://trovi.com/ResultsExt.aspx?ctid=CT2625848&SearchSource=2&CUI=UN27098573081436117&UM=8&q=");
-\\ Google Chrome v39.0.2171.65
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1407331032&from=tugs&uid=ST9640320AS_5WX3VG2ZXXXX5WX3VG2Z&q={searchTerms}
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1407331032&from=tugs&uid=ST9640320AS_5WX3VG2ZXXXX5WX3VG2Z&q={searchTerms}
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1407331032&from=tugs&uid=ST9640320AS_5WX3VG2ZXXXX5WX3VG2Z&q={searchTerms}
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1407331032&from=tugs&uid=ST9640320AS_5WX3VG2ZXXXX5WX3VG2Z&q={searchTerms}
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_tuto2_15_07&cd=2XzuyEtN2Y1L1Qzu0C0C0A0FyBzztDyB0B0FyEzy0BtAtCyEtN0D0Tzu0StCtCtAyDtN1L2XzutAtFyBtFtBtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StDyEzy0CyB0A0BtCtGyDyB0CyEtGyByDyCtAtGtD0FtCyEtGyB0EyDzzyDzz0D0FzyzytCzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0DyEyEtDzy0FyBtGyBzztA0EtGyEtByB0AtGzztD0AtBtG0C0BtA0AyCtCzyzztA0BtCtC2Q&cr=1844074412&ir=
[C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://taplika.com/results.php?f=4&q={searchTerms}&a=tpl_tuto2_15_07&cd=2XzuyEtN2Y1L1Qzu0C0C0A0FyBzztDyB0B0FyEzy0BtAtCyEtN0D0Tzu0StCtCtAyDtN1L2XzutAtFyBtFtBtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StDyEzy0CyB0A0BtCtGyDyB0CyEtGyByDyCtAtGtD0FtCyEtGyB0EyDzzyDzz0D0FzyzytCzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0D0DyEyEtDzy0FyBtGyBzztA0EtGyEtByB0AtGzztD0AtBtG0C0BtA0AyCtCzyzztA0BtCtC2Q&cr=1844074412&ir=
*************************
AdwCleaner[R0].txt - [32553 Bytes] - [09/03/2015 16:48:48]
AdwCleaner[S0].txt - [31390 Bytes] - [09/03/2015 16:51:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [31450 Bytes] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Home Premium x64
Ran by Tabea on 09.03.2015 at 16:57:37,13
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Windows\prefetch\SPEEDUPMYPC.EXE-B3192A3C.pf
Successfully deleted: [File] "C:\Windows\wininit.ini"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Tabea\appdata\local\cre"
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{060AF95C-EAB3-4CB3-A0DA-003C7FF8C6E2}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{0E35674C-54B9-407F-8429-FAB10396D3C0}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{1110B680-275B-464F-B7FA-5FCEDED508F6}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{11CEAC91-A2C0-4AAE-AB55-DFCCAC1C5542}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{15692D1F-3CCB-4125-824C-401173BD0F78}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{1685CD78-4860-460C-91B7-ADB3D54AECA9}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{19C4CFBE-108F-4CE7-84B8-FCD7A57F0A67}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{19E0F528-ED63-4E2C-A522-1EA991422F9D}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{1FE365AD-CEE5-44E5-AC86-BFE41D0EFA7F}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{2A274B2F-DD06-4C02-BDDE-31985D9B10E7}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{2F428D1F-CF4D-4C50-B79B-AB2E6AD7D18F}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{3696D7BE-1385-4698-8214-33455349B358}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{379DF6F1-F5E6-4891-B6EE-6E3B33FA2D77}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{3902AFD6-2DA2-4703-8961-9CACD17831EB}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{39695D1B-5698-4C09-A221-215CA1D1D3EC}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{43FD0524-8925-45FF-93C9-3B774E6E7730}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{46DD387A-FF33-43B0-ADFA-D0B4CF8F3218}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{4C35EFDC-4246-408B-85D5-07A1437DD426}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{51E1C23A-696F-4653-8A54-5151D26758F2}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{5F38C176-66E2-477B-87DF-1EFBFA1BC2E4}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{602472E2-9FE5-4A0E-83F0-2E07060B20A5}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{625B009C-C3E6-4D9A-9293-A28BAE97823E}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{693D7451-E0B4-4945-81D2-5CEA2EBDAFE8}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{6E6B06EC-F462-4679-ADD5-406520E03F7D}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{77CB1D91-0303-4346-A7BE-88B443A1AECC}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{7800C1F5-9055-4856-9699-A38455607139}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{7D3BA1E3-93A2-41AC-93D7-4FDF9A718B46}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{84151526-CEB2-4134-A2F7-3DA07B2A4F2C}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{884AB740-AFFB-4694-A249-3264A70E76DD}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{8CB4F222-3636-4763-A672-19D37170DD42}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{8E012F20-F879-4CF5-BFCD-AEE689B793A4}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{97DED18B-F692-466E-88C4-A036779F2855}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{9F56C363-EB75-4BF7-ACB3-FB889E0D0B9A}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{9F573084-926A-4304-91FC-405BD764871F}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{9FFFFD14-6C19-4031-A0BE-2405F1CA2A1D}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{A4AB8C15-D543-4C77-95A0-B510C77B2233}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{AB64E355-330A-4998-923A-7C2360C3BFEB}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{AFA1C665-EB3E-4FBB-A79A-1FB46F06AC21}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{B13F29A7-4B8D-41AE-8257-DA31C1AA5742}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{BB8EAF3C-70DB-443D-A427-EB609E2DDDC0}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{C8B5C561-08EB-40F7-88A6-9C209E354FA0}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{CB115A84-C65B-4C01-BA99-AE7D81486080}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{CBA940D5-E585-40B0-8C8C-5072FD7FEA3A}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{D08A718A-89E2-4B6F-8D06-288BA74FD1D7}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{D8195E5D-B34F-4DE1-80D9-B30315F11405}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{D9C382E4-EB49-4639-8CEC-70BCB9F23F76}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{DD96B35F-6A91-43E1-82B8-BA4ADEC89F58}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{DFF07A11-5E6E-45F5-8FF5-5C1D67D49983}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{E17E72C1-3D2D-41F8-97B7-CB6D5E6D9BC5}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{E2FB76C1-7613-4D8D-A267-77614FBE524D}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{EA4271A7-FBAF-401E-8FCF-5370B43179F7}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{EBA717E3-BF13-4CC6-8839-D7E6CB99243F}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{F073A8D9-5C9A-4DDF-93B0-AF099F4A0C4E}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{F187B1B2-6230-46F4-A07C-06657135E893}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{FA09ACC7-89FC-4FB4-B792-E2E15677284E}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{FD2A431B-E939-4083-8DCA-049B1614386B}
Successfully deleted: [Empty Folder] C:\Users\Tabea\appdata\local\{FE97493D-5447-4B90-99E7-056BD9D18053}
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Tabea\AppData\Roaming\mozilla\firefox\profiles\yn671juw.default\conduitcommon
Successfully deleted: [Folder] C:\Users\Tabea\AppData\Roaming\mozilla\firefox\profiles\yn671juw.default\smartbar
Successfully deleted the following from C:\Users\Tabea\AppData\Roaming\mozilla\firefox\profiles\yn671juw.default\prefs.js
user_pref("CT2625848.1000082.isPlayDisplay", "true");
user_pref("CT2625848.1000082.state", "{\"state\":\"stopped\"}");
user_pref("CT2625848.1000234.TWC_TMP_city", "HAMBURG");
user_pref("CT2625848.1000234.TWC_TMP_country", "DE");
user_pref("CT2625848.1000234.TWC_country", "GERMANY");
user_pref("CT2625848.1000234.TWC_locId", "USAR0242");
user_pref("CT2625848.1000234.TWC_location", "Hamburg, AR");
user_pref("CT2625848.1000234.TWC_region", "DE");
user_pref("CT2625848.1000234.TWC_temp_dis", "c");
user_pref("CT2625848.1000234.TWC_wind_dis", "kmh");
user_pref("CT2625848.2625848a129894023611240511000000paramsGK1.enc", "eyJ1cGRhdGVSZXFUaW1lIjoxNDI1Nzg1ODc3MzU2fQ==");
user_pref("CT2625848.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2625848.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2625848.FirstTime", "true");
user_pref("CT2625848.FirstTimeFF3", "true");
user_pref("CT2625848.PG_ENABLE", "dHJ1ZQ==");
user_pref("CT2625848.RestartDialogFirstTime", "false");
user_pref("CT2625848.RestartDialogShouldDisplay", "false");
user_pref("CT2625848.SearchAppState.enc", "Mg==");
user_pref("CT2625848.SearchAppTracking.enc", "MQ==");
user_pref("CT2625848.UserID", "UN27098573081436117");
user_pref("CT2625848.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT2625848.appOptions", "{\"1000034\":{\"render\":true},\"1000234\":{\"render\":true},\"1000515\":{\"render\":true},\"price-gong\":{\"disabled\":false,\"render\":tru
user_pref("CT2625848.cb_experience_000.enc", "Mw==");
user_pref("CT2625848.cb_firstuse0100.enc", "MQ==");
user_pref("CT2625848.cb_user_id_000.enc", "Q0I3Nzg2NjA0ODExXzE0MjU3ODQ0MTc4ODBfRmlyZWZveA==");
user_pref("CT2625848.cbfirsttime.enc", "U3VuIE1hciAwOCAyMDE1IDA0OjEzOjM3IEdNVCswMTAw");
user_pref("CT2625848.countryCode", "DE");
user_pref("CT2625848.dum", "2");
user_pref("CT2625848.firstTimeDialogOpened", "true");
user_pref("CT2625848.fixPageNotFoundErrorByUser", "TRUE");
user_pref("CT2625848.fixPageNotFoundErrorInHidden", "true");
user_pref("CT2625848.fullUserID", "UN27098573081436117.UP.2130");
user_pref("CT2625848.installType", "DirectDownload");
user_pref("CT2625848.isCheckedStartAsHidden", true);
user_pref("CT2625848.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2625848.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT2625848.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT2625848.keyword", true);
user_pref("CT2625848.lastVersion", "10.37.0.508");
user_pref("CT2625848.mam_gk_installer_preapproved.enc", "VFJVRQ==");
user_pref("CT2625848.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://DVDVideoSoftT
user_pref("CT2625848.originalHomepage", "chrome://branding/locale/browserconfig.properties");
user_pref("CT2625848.performedDomainChangesMigration", "true");
user_pref("CT2625848.personalApps", "{\"dataType\":\"object\",\"data\":\"[\\\"EMAIL_NOTIFIER\\\",\\\"WEATHER\\\",\\\"BROWSER_COMPONENT\\\"]\"}");
user_pref("CT2625848.price-gong.isManagedApp", "true");
user_pref("CT2625848.revertSettingsEnabled", "false");
user_pref("CT2625848.search.searchAppId", "129181467799155027");
user_pref("CT2625848.search.searchCount", "0");
user_pref("CT2625848.searchFromAddressBarEnabledByUser", "true");
user_pref("CT2625848.searchInNewTabEnabledByUser", "true");
user_pref("CT2625848.searchInNewTabEnabledInHidden", "true");
user_pref("CT2625848.searchSuggestEnabledByUser", "True");
user_pref("CT2625848.searchUninstallUserMode", "8");
user_pref("CT2625848.searchUserMode", "8");
user_pref("CT2625848.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2625848.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT2625848.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT2625848.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2625848\"}");
user_pref("CT2625848.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://DVDVideoSoftTBDE.OurToolbar.com//xpi\"}");
user_pref("CT2625848.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"DVDVideoSoftTB DE \"}");
user_pref("CT2625848.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2625848.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT2625848.serviceLayer_services_Configuration_lastUpdate", "1425783994089");
user_pref("CT2625848.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1425783993495");
user_pref("CT2625848.serviceLayer_services_appsMetadata_lastUpdate", "1425783994015");
user_pref("CT2625848.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1425783993974");
user_pref("CT2625848.serviceLayer_services_login_10.37.0.508_lastUpdate", "1425806870014");
user_pref("CT2625848.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1425783994006");
user_pref("CT2625848.serviceLayer_services_searchAPI_lastUpdate", "1425783993497");
user_pref("CT2625848.serviceLayer_services_serviceMap_lastUpdate", "1425783993882");
user_pref("CT2625848.serviceLayer_services_setupAPI_lastUpdate", "1425783993497");
user_pref("CT2625848.serviceLayer_services_toolbarContextMenu_lastUpdate", "1425783993972");
user_pref("CT2625848.serviceLayer_services_toolbarSettings_lastUpdate", "1425806870495");
user_pref("CT2625848.serviceLayer_services_translation_lastUpdate", "1425783993969");
user_pref("CT2625848.settingsINI", true);
user_pref("CT2625848.showToolbarPermission", "false");
user_pref("CT2625848.toolbarBornServerTime", "20-2-2015");
user_pref("CT2625848.toolbarCurrentServerTime", "8-3-2015");
user_pref("CT2625848.toolbarInstallDate", "08-03-2015 04:06:32");
user_pref("CT2625848.toolbarLoginClientTime", "Sun Mar 08 2015 04:06:32 GMT+0100");
user_pref("CT2625848.url_history0001.enc", "c3RhcnQ6OjpjbGlja2hhbmRsZXI6OjoxNDI1Nzg0Nzk2MTgwLCwsc3RhcnQ6OjpjbGlja2hhbmRsZXI6OjoxNDI1Nzg0Nzk2NzYzLCwsc3RhcnQ6OjpjbGlja2hhbmRsZXI
user_pref("CT2625848_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1425806952155,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("extensions.L1D9mvNDyem5Ut9W.scode", "(function(){try{if(window.self.location.href.indexOf(\"qds7rjYEqjkEqdC6pjrHpja9rY\")>-1){return;}}catch(e){}try{var d=[[\"acebo
user_pref("valueApps.CT2625848.SF_JUST_INSTALLED", "46414C5345");
user_pref("valueApps.CT2625848.SF_JUST_INSTALLED.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appStateReportTime", "31343235373834333731383632");
user_pref("valueApps.CT2625848.mam_gk_appStateReportTime.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appState_Clarity_Active", "6F6E");
user_pref("valueApps.CT2625848.mam_gk_appState_Clarity_Active.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appState_CouponBuddy", "6F6E");
user_pref("valueApps.CT2625848.mam_gk_appState_CouponBuddy.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appState_Easytobook", "6F6E");
user_pref("valueApps.CT2625848.mam_gk_appState_Easytobook.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appState_Easytobook_targeted", "6F6E");
user_pref("valueApps.CT2625848.mam_gk_appState_Easytobook_targeted.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appState_PriceGong", "6F6E");
user_pref("valueApps.CT2625848.mam_gk_appState_PriceGong.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appState_WindowShopper", "6F6E");
user_pref("valueApps.CT2625848.mam_gk_appState_WindowShopper.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_appsConfig.storedInFile", true);
user_pref("valueApps.CT2625848.mam_gk_appsDefaultEnabled", "6E756C6C");
user_pref("valueApps.CT2625848.mam_gk_appsDefaultEnabled.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_calledSetupService", "31");
user_pref("valueApps.CT2625848.mam_gk_calledSetupService.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_currentVersion", "312E31332E302E3137");
user_pref("valueApps.CT2625848.mam_gk_currentVersion.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_existingUsersRecoveryDone", "31");
user_pref("valueApps.CT2625848.mam_gk_existingUsersRecoveryDone.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_first_time", "31");
user_pref("valueApps.CT2625848.mam_gk_first_time.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_installer_preapproved", "46414C5345");
user_pref("valueApps.CT2625848.mam_gk_installer_preapproved.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_lastLoginTime", "31343235373834333732363431");
user_pref("valueApps.CT2625848.mam_gk_lastLoginTime.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_localization.storedInFile", true);
user_pref("valueApps.CT2625848.mam_gk_mamEnabled", "66616C7365");
user_pref("valueApps.CT2625848.mam_gk_mamEnabled.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_migrated_from_ls", "31");
user_pref("valueApps.CT2625848.mam_gk_migrated_from_ls.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_newApps", "5B5D");
user_pref("valueApps.CT2625848.mam_gk_newApps.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_new_welcome_experience", "31");
user_pref("valueApps.CT2625848.mam_gk_new_welcome_experience.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_settings1.13.0.17.storedInFile", true);
user_pref("valueApps.CT2625848.mam_gk_showWelcomeGadget", "66616C7365");
user_pref("valueApps.CT2625848.mam_gk_showWelcomeGadget.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_stamp", "313130315F30");
user_pref("valueApps.CT2625848.mam_gk_stamp.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_userBornDate", "4E2F41");
user_pref("valueApps.CT2625848.mam_gk_userBornDate.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_userId", "36353334343863632D313936342D343532662D393564652D613039396265666531303666");
user_pref("valueApps.CT2625848.mam_gk_userId.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_user_approval_interacted", "31");
user_pref("valueApps.CT2625848.mam_gk_user_approval_interacted.storedInFile", false);
user_pref("valueApps.CT2625848.mam_gk_welcomeDialogMode", "31");
user_pref("valueApps.CT2625848.mam_gk_welcomeDialogMode.storedInFile", false);
user_pref("valueApps.storage.mam_gk_userId", "36353334343863632D313936342D343532662D393564652D613039396265666531303666");
Emptied folder: C:\Users\Tabea\AppData\Roaming\mozilla\firefox\profiles\yn671juw.default\minidumps [59 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.03.2015 at 17:06:53,30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2015 03
Ran by Tabea (administrator) on TABEA-PC on 09-03-2015 17:08:40
Running from C:\Users\Tabea\Desktop
Loaded Profiles: Tabea (Available profiles: Tabea)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\nis.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-05] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-06-03] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe"
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-06-21] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-05-25] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-05-09] (CyberLink Corp.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\...\Run: [KiesPDLR] => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845120 2014-07-25] (Samsung)
HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-21] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:60649;https=127.0.0.1:60649
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=de&pid=NIS&pvid=21.6.0.32
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=de&pid=NIS&pvid=21.6.0.32
HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-09] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-09] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-09] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-09] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-03-08] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default
FF NewTab:
FF DefaultSearchEngine: Search Module
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll [2013-10-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll [2013-10-12] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-12-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\8\NP_wtapp.dll [2013-12-23] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1293511207-2862067052-4015422231-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Tabea\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF SearchPlugin: C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\searchplugins\icq-search.xml [2014-09-06]
FF Extension: ICQ Sparberater - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\Extensions\ciuvo-extension@icq.de.xpi [2012-05-15]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn
FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn [2015-01-25]
FF HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} [Not Found]
FF Extension: No Name - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\extensions\6bd508b5-8edf-4661-89eb-5b5186fa62d1@gmail.com [Not Found]
FF Extension: No Name - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\extensions\718bc5a3-95e4-4d4c-b94b-2c916fcf5266@gmail.com [Not Found]
FF Extension: No Name - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found]
FF Extension: No Name - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\extensions\TTSD90021300@PYDKGV101145942.com [Not Found]
FF Extension: No Name - C:\Users\Tabea\AppData\Roaming\Mozilla\Firefox\Profiles\yn671juw.default\extensions\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} [Not Found]
Chrome:
=======
CHR Profile: C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-18]
CHR Extension: (Google Drive) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-18]
CHR Extension: (No Name) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-18]
CHR Extension: (videos MediaPlayer+) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2014-09-10]
CHR Extension: (Google Search) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-18]
CHR Extension: (HC-nemA1.1) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkigkllnlkoblfbgfnfngfcnhmndonjm [2014-09-10]
CHR Extension: (ieelbggiidmnfbkjcjceknbhjgnhkjnf) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieelbggiidmnfbkjcjceknbhjgnhkjnf [2014-09-13]
CHR Extension: (Norton Identity Safe) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-09-07]
CHR Extension: (kofmneijajkgajeffbphblliaeidahcn) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\kofmneijajkgajeffbphblliaeidahcn [2014-09-14]
CHR Extension: (Google Wallet) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-18]
CHR Extension: (olplonfdcekbkpjnoeecfihlkfdkehbj) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\olplonfdcekbkpjnoeecfihlkfdkehbj [2014-09-13]
CHR Extension: (Cinem4S-2.1) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\ongeglooehhgapkfkjcehdcbiklhcpae [2014-09-11]
CHR Extension: (Gmail) - C:\Users\Tabea\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-18]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-17] (WildTangent)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\NIS.exe [276376 2014-09-21] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-10-31] (Microsoft Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2100024 2013-08-30] (TuneUp Software)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 1394843d; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\BorderlineEdit\BorderlineEdit.dll",serv
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-08-16] (AVG Technologies)
S1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20141209.001\BHDrvx64.sys [1587416 2014-10-03] (Symantec Corporation)
S1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1506000.020\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-11] (Symantec Corporation)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-12-30] () [File not signed]
R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20141230.001\IDSvia64.sys [637656 2014-11-23] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20141230.054\ENG64.SYS [129752 2014-09-02] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20141230.054\EX64.SYS [2137304 2014-09-02] (Symantec Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1506000.020\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1506000.020\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NISx64\1506000.020\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NISx64\1506000.020\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-12-30] (Symantec Corporation)
S1 SymIRON; C:\Windows\system32\drivers\NISx64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
S1 SymNetS; C:\Windows\System32\Drivers\NISx64\1506000.020\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-09 17:08 - 2015-03-09 17:09 - 00021072 _____ () C:\Users\Tabea\Desktop\FRST.txt
2015-03-09 17:08 - 2015-03-09 17:08 - 02095104 _____ (Farbar) C:\Users\Tabea\Desktop\FRST64.exe
2015-03-09 17:08 - 2015-03-09 17:08 - 00000000 ____D () C:\Users\Tabea\Desktop\FRST-OlderVersion
2015-03-09 17:06 - 2015-03-09 17:07 - 00018261 _____ () C:\Users\Tabea\Desktop\JRT.txt
2015-03-09 16:55 - 2015-03-09 16:55 - 00031655 _____ () C:\Users\Tabea\Desktop\AdwCleaner[S0].txt
2015-03-09 16:48 - 2015-03-09 16:51 - 00000000 ____D () C:\AdwCleaner
2015-03-09 16:48 - 2015-03-09 16:44 - 01388333 _____ (Thisisu) C:\Users\Tabea\Desktop\JRT.exe
2015-03-09 16:48 - 2015-03-09 16:41 - 02126848 _____ () C:\Users\Tabea\Desktop\AdwCleaner_4.111.exe
2015-03-09 15:57 - 2015-03-09 16:56 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-09 15:56 - 2015-03-09 15:56 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-09 15:56 - 2015-03-09 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-09 15:56 - 2015-03-09 15:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-09 15:56 - 2015-03-09 15:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-09 15:56 - 2015-03-09 15:53 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Tabea\Desktop\mbam-setup-2.0.4.1028.exe
2015-03-09 15:56 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-09 15:56 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-09 15:56 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-08 10:59 - 2015-03-08 10:59 - 00043329 _____ () C:\Users\Tabea\Desktop\Jip.txt
2015-03-08 10:58 - 2015-03-08 10:58 - 00043329 _____ () C:\ComboFix.txt
2015-03-08 10:36 - 2015-03-08 10:58 - 00000000 ____D () C:\ComboFix
2015-03-08 10:18 - 2015-03-08 23:08 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-08 04:54 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-08 04:54 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-08 04:54 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-08 04:54 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-08 04:54 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-08 04:54 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-08 04:54 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-08 04:54 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-08 04:52 - 2015-03-08 10:58 - 00000000 ____D () C:\Qoobox
2015-03-08 04:51 - 2015-03-08 10:56 - 00000000 ____D () C:\Windows\erdnt
2015-03-08 04:51 - 2015-03-08 04:48 - 05612482 ____R (Swearware) C:\Users\Tabea\Desktop\ComboFix.exe
2015-03-08 04:41 - 2015-03-08 04:41 - 00000000 ____D () C:\ProgramData\{e6b4eeaa-88b9-824f-e6b4-4eeaa88bbaaa}
2015-03-08 04:39 - 2015-03-08 10:47 - 00000000 ____D () C:\Program Files (x86)\472b501c-2f71-4a92-9f01-dfa921c5f98a
2015-03-08 04:39 - 2015-03-08 04:39 - 00000000 ____D () C:\Users\Public\Documents\ShopperPro
2015-03-08 04:38 - 2015-03-08 04:38 - 00003592 _____ () C:\Windows\System32\Tasks\SMWUpd
2015-03-08 04:38 - 2015-03-08 04:38 - 00000000 ____D () C:\Users\Tabea\AppData\Local\CrashRpt
2015-03-08 04:10 - 2015-03-09 16:44 - 00000000 ____D () C:\Program Files (x86)\BorderlineEdit
2015-03-08 04:06 - 2015-03-08 10:26 - 00001272 _____ () C:\Users\Tabea\Desktop\Revo Uninstaller.lnk
2015-03-08 04:06 - 2015-03-08 10:26 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-08 04:06 - 2015-03-08 04:04 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tabea\Desktop\revosetup95.exe
2015-03-07 14:17 - 2015-03-09 17:08 - 00000000 ____D () C:\FRST
2015-02-25 17:55 - 2015-02-25 17:55 - 00006470 _____ () C:\Users\Tabea\Desktop\Windows-Kompatibilitätsbericht.htm
2015-02-25 17:51 - 2015-02-25 17:55 - 00002562 _____ () C:\Windows\diagwrn.xml
2015-02-25 17:51 - 2015-02-25 17:55 - 00001908 _____ () C:\Windows\diagerr.xml
2015-02-25 16:44 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-25 16:44 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-02-25 14:08 - 2015-02-25 23:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
2015-02-25 14:08 - 2015-02-25 23:52 - 00000000 ____D () C:\Program Files (x86)\Magical Jelly Bean
2015-02-25 13:08 - 2015-02-25 13:08 - 00003344 ____N () C:\bootsqm.dat
2015-02-16 10:42 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-02-09 15:44 - 2015-02-09 15:44 - 00000010 _____ () C:\Users\Tabea\AppData\Local\DSI.DAT
2015-02-09 14:49 - 2015-02-25 23:52 - 00000000 ____D () C:\ProgramData\{16384246-2613-4553-1638-842462610918}
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-09 17:09 - 2011-09-24 05:17 - 02056373 _____ () C:\Windows\WindowsUpdate.log
2015-03-09 17:07 - 2011-09-24 15:05 - 00700118 _____ () C:\Windows\system32\perfh007.dat
2015-03-09 17:07 - 2011-09-24 15:05 - 00149968 _____ () C:\Windows\system32\perfc007.dat
2015-03-09 17:07 - 2009-07-14 06:13 - 01622228 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-09 17:04 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-09 17:04 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-09 16:54 - 2010-11-21 04:47 - 01878618 _____ () C:\Windows\PFRO.log
2015-03-09 16:54 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-09 16:54 - 2009-07-14 05:51 - 00002328 _____ () C:\Windows\setupact.log
2015-03-09 16:44 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\L2Schemas
2015-03-09 16:42 - 2012-05-14 14:02 - 00000000 ____D () C:\ProgramData\ICQ
2015-03-09 16:41 - 2014-04-03 16:18 - 00000000 ____D () C:\Users\Tabea\AppData\Local\TB
2015-03-09 16:18 - 2012-08-21 21:13 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1293511207-2862067052-4015422231-1000UA.job
2015-03-09 15:59 - 2013-12-24 20:59 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-03-09 15:57 - 2012-03-23 15:56 - 00003930 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A68B64F4-2F85-4E7F-BDF9-25A88BD71AF5}
2015-03-08 11:02 - 2014-09-10 19:52 - 00002034 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-08 11:02 - 2012-07-07 18:27 - 00001984 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-08 11:02 - 2011-12-25 20:48 - 00002370 _____ () C:\Users\Tabea\Desktop\Internet Explorer.lnk
2015-03-08 10:58 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-03-08 10:53 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-08 10:49 - 2009-07-14 03:34 - 93585408 _____ () C:\Windows\system32\config\software.bak
2015-03-08 10:49 - 2009-07-14 03:34 - 18612224 _____ () C:\Windows\system32\config\system.bak
2015-03-08 10:49 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\default.bak
2015-03-08 10:49 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2015-03-08 10:49 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2015-03-08 10:47 - 2011-08-12 12:37 - 00000000 ____D () C:\Program Files (x86)\Acer Games
2015-03-08 04:39 - 2013-12-18 19:35 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-08 04:39 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-03-08 04:20 - 2013-03-20 20:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2015-03-08 04:20 - 2011-12-25 20:45 - 00000000 ____D () C:\Program Files (x86)\AMD
2015-03-08 04:05 - 2012-08-21 21:13 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1293511207-2862067052-4015422231-1000Core.job
2015-03-07 12:50 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-25 23:53 - 2014-12-11 16:13 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-25 23:53 - 2014-10-19 13:49 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Internet Security
2015-02-25 23:53 - 2014-06-13 19:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-02-25 23:53 - 2014-06-13 19:57 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2015-02-25 23:53 - 2014-05-08 19:39 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-25 23:53 - 2014-02-12 20:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014
2015-02-25 23:53 - 2013-12-30 21:02 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2015-02-25 23:53 - 2013-12-18 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-25 23:53 - 2013-10-29 14:52 - 00000000 ___SD () C:\Users\Tabea\Documents\Meine Datenquellen
2015-02-25 23:53 - 2013-08-29 19:55 - 00000000 ____D () C:\Users\Tabea\Desktop\Andere Musik
2015-02-25 23:53 - 2012-10-27 11:55 - 00000000 ____D () C:\Users\Tabea\Documents\EA Games
2015-02-25 23:53 - 2012-07-06 17:18 - 00000000 ____D () C:\Users\Tabea\Documents\samsung
2015-02-25 23:53 - 2012-06-07 12:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-25 23:53 - 2012-05-31 19:51 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2015-02-25 23:53 - 2012-05-12 18:46 - 00000000 ___RD () C:\Users\Tabea\Documents\Notes
2015-02-25 23:53 - 2012-04-26 13:18 - 00000000 ___RD () C:\Users\Tabea\Desktop\Bilder
2015-02-25 23:53 - 2012-04-06 17:37 - 00000000 ____D () C:\Users\Tabea\Documents\Fax
2015-02-25 23:53 - 2011-12-27 20:30 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2015-02-25 23:53 - 2011-12-27 20:29 - 00000000 ____D () C:\Windows\system32\Drivers\NISx64
2015-02-25 23:53 - 2011-12-27 20:29 - 00000000 ____D () C:\ProgramData\Norton
2015-02-25 23:53 - 2011-12-27 20:29 - 00000000 ____D () C:\Program Files (x86)\Norton Internet Security
2015-02-25 23:53 - 2011-08-12 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2015-02-25 23:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-02-25 23:52 - 2013-11-15 15:36 - 00000000 ____D () C:\Users\Public\Downloads\Norton
2015-02-25 23:50 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-02-25 17:51 - 2009-07-14 05:51 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-25 16:35 - 2011-08-12 12:20 - 01596508 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-02-25 16:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-02-25 16:21 - 2011-12-25 20:44 - 00000000 ____D () C:\Users\Tabea
2015-02-24 03:17 - 2010-11-21 04:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-02-20 11:46 - 2012-01-08 18:57 - 00000000 ____D () C:\Users\Tabea\AppData\Local\CrashDumps
==================== Files in the root of some directories =======
2013-06-27 07:53 - 2014-06-22 15:36 - 0003730 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
2014-10-28 14:45 - 2015-01-05 10:20 - 0000092 _____ () C:\Users\Tabea\AppData\Roaming\WB.CFG
2015-02-09 15:44 - 2015-02-09 15:44 - 0000010 _____ () C:\Users\Tabea\AppData\Local\DSI.DAT
2011-09-24 05:33 - 2011-09-24 05:36 - 0015230 _____ () C:\ProgramData\ArcadeDeluxe5.log
2011-12-28 14:28 - 2011-12-28 14:28 - 0000033 _____ () C:\ProgramData\PS.log
Some content of TEMP:
====================
C:\Users\Tabea\AppData\Local\Temp\Quarantine.exe
C:\Users\Tabea\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-07 13:39
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2015 03
Ran by Tabea at 2015-03-09 17:09:32
Running from C:\Users\Tabea\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton Internet Security (Disabled - Out of date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton Internet Security (Disabled - Out of date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton Internet Security (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.99 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1904 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1904 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3008 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3502 - Acer Incorporated)
Acer Games (HKLM-x32\...\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.04.3503 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0517.2011 - Acer Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.0.4.13090 - Adobe Systems Inc.)
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
AMD System Monitor (HKLM-x32\...\{C1C82DC9-1547-4038-8F0A-C069F0B7F2ED}) (Version: 1.0.5 - Advanced Micro Devices, Inc.)
ANDI 2013 (HKLM-x32\...\{21E3464C-EE59-4EA2-B3E1-4FCE000B8722}) (Version: 5.0.5 - LGLN Hannover)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{9AFCE058-629E-B087-80A8-E0E415BA6FB9}) (Version: 3.0.820.0 - ATI Technologies, Inc.)
Backup Manager V3 (x32 Version: 3.0.0.99 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
clear.fi (x32 Version: 9.0.7709 - CyberLink Corp.) Hidden
clear.fi Client (HKLM-x32\...\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3500 - Acer Incorporated)
Crazy Chicken Kart 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Die Sims 2 (HKLM-x32\...\{6E7DD182-9FC6-4651-0095-2E666CC6AF35}) (Version: - )
Die Sims™ 2 Vier Jahreszeiten (HKLM-x32\...\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}) (Version: - )
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.4 - Dolby Laboratories Inc)
eBay Worldwide (HKLM-x32\...\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
ETDWare PS/2-X64 8.0.6.3_WHQL (HKLM\...\Elantech) (Version: 8.0.6.3 - ELAN Microelectronic Corp.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Fooz Kids (HKLM-x32\...\FoozKids) (Version: 2.1.31 - FUHU, Inc.)
Fooz Kids (x32 Version: 2.1.31 - FUHU, Inc.) Hidden
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.)
FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - )
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.)
ICQ Sparberater (HKLM-x32\...\{0766C1B9-B2DC-46E5-8934-4F3D6B42B1BD}) (Version: 1.3.671 - solute gmbh)
ICQ7M (HKLM-x32\...\{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}) (Version: 7.8 - ICQ)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
iTunes (HKLM\...\{A04DCB25-7040-4935-A30D-8E0A893ABF2D}) (Version: 11.1.2.32 - Apple Inc.)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Landwirtschafts Simulator 2011 (HKLM-x32\...\FarmingSimulator2011_PLATINUMDE_is1) (Version: 1.0 - GIANTS Software)
Landwirtschafts-Simulator 2009 (HKLM-x32\...\FarmingSimulator2009DE_is1) (Version: - GIANTS Software)
Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.7 - Acer Inc.)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4693.1002 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5128.5002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Moorhuhn Kart 3 (HKLM-x32\...\{46376BAF-996E-410E-82B2-5D9E61820E6D}) (Version: 1.00.0000 - )
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.18 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.18 - Egis Technology Inc.) Hidden
newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden
Norton Internet Security (HKLM-x32\...\NIS) (Version: 21.6.0.32 - Symantec Corporation)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.3.2.12054_20 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.3.2.12054_20 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.14072.12 - Samsung Electronics Co., Ltd.)
Samsung Kies3 (x32 Version: 3.2.14072.12 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Spielkanäle (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 6.1.0.5 - WildTangent, Inc.)
Stellar Phoenix Windows Data Recovery - Home (HKLM-x32\...\Stellar Phoenix Windows Data Recovery - Home_is1) (Version: 4.2.0.1 - Stellar Information Systems Ltd)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden
TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities 2014) (Version: 14.0.1000.89 - TuneUp Software)
TuneUp Utilities 2014 (x32 Version: 14.0.1000.89 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.97 - WildTangent) Hidden
Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3503 - Acer Incorporated)
WildTangent Games App (x32 Version: 4.0.11.14 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1293511207-2862067052-4015422231-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Tabea\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1293511207-2862067052-4015422231-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Tabea\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1293511207-2862067052-4015422231-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Tabea\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1293511207-2862067052-4015422231-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Tabea\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1293511207-2862067052-4015422231-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Tabea\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
08-03-2015 04:07:55 Revo Uninstaller's restore point - AnyProtect
08-03-2015 04:12:07 Revo Uninstaller's restore point - Browsers Apps
08-03-2015 04:15:50 Revo Uninstaller's restore point - DesktopWeatherAlerts
08-03-2015 04:17:13 Revo Uninstaller's restore point - Easy Speed Check
08-03-2015 04:18:50 Revo Uninstaller's restore point - Easy Speed PC
08-03-2015 04:21:02 Revo Uninstaller's restore point - FreeSoftToday 014.124
08-03-2015 04:22:57 Revo Uninstaller's restore point - FreeSoftToday 014.173
08-03-2015 04:24:09 Revo Uninstaller's restore point - FreeSoftToday 014.6
08-03-2015 04:25:07 Revo Uninstaller's restore point - Guard.ICQ
08-03-2015 04:26:09 Revo Uninstaller's restore point - InetStat
08-03-2015 04:27:52 Revo Uninstaller's restore point - NewPlayer
08-03-2015 04:30:07 Revo Uninstaller's restore point - OfferBoulevard
08-03-2015 04:31:31 Revo Uninstaller's restore point - PepperZip 1.0
08-03-2015 04:33:41 Revo Uninstaller's restore point - Remote Desktop Access (VuuPC)
08-03-2015 04:35:03 Revo Uninstaller's restore point - Search Protect
08-03-2015 04:40:42 Revo Uninstaller's restore point - speed browser
08-03-2015 04:42:53 Revo Uninstaller's restore point - SpeedUpMyPC
08-03-2015 04:43:54 Revo Uninstaller's restore point - TV Wizard
08-03-2015 04:44:55 Revo Uninstaller's restore point - VIS
08-03-2015 04:46:01 Revo Uninstaller's restore point - webssearches uninstall
08-03-2015 04:47:09 Revo Uninstaller's restore point - WindowsMangerProtect20.0.0.502
08-03-2015 04:48:21 Revo Uninstaller's restore point - Yahoo Community Smartbar
08-03-2015 04:50:04 Revo Uninstaller's restore point - Yahoo Community Smartbar Engine
08-03-2015 10:28:06 Revo Uninstaller's restore point - Super Optimizer v3.2
09-03-2015 16:05:47 Windows-Sicherung
09-03-2015 16:16:59 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2015-03-08 10:53 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1A21ED4D-C3F7-4019-A61E-0D3AF569DCDF} - \gtaUpt No Task File <==== ATTENTION
Task: {2B16FFDD-4E74-4A8E-9E7A-5A8DBE393D73} - System32\Tasks\Adobe ARM => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {2B97C0AD-B9F0-455A-B2A3-B0868B44312F} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation)
Task: {59BFD4A8-93E8-40D8-A25D-6F060A6C481A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1293511207-2862067052-4015422231-1000Core => C:\Users\Tabea\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-21] (Facebook Inc.)
Task: {65395456-7E58-4916-98A4-2E15BEEBA17B} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {6B48C106-9D35-4329-A1F2-B32BB62FDFA3} - \SPBIW_UpdateTask_Time_333939373531323939322d5a5b6c344a415745505a416c No Task File <==== ATTENTION
Task: {7AB0FA8F-F159-4506-9723-BEB70F3CC295} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {81A94C7F-4C1D-40B6-BA51-C1C23DBC24C2} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-10-31] (Microsoft Corporation)
Task: {81B04A54-51AA-4AE1-B109-7FC2EC572858} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {8907531D-6106-44C1-AEE0-88DDC58562B7} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {94A78365-4A08-4597-A6E1-E3DC90C2FA38} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A2A26CC0-06E7-487B-AEA0-4C2815760D7F} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2013-08-30] (TuneUp Software)
Task: {A53B0F86-3C57-4AB3-85DF-427D855B2B11} - System32\Tasks\Adobe Reader Speed Launcher => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
Task: {C59A50B5-F9C7-46FA-9541-E1F266B40AA0} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
Task: {C7F80C11-D7B8-4A28-926C-4EC93A92C453} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {CCCD0B32-E98A-4124-AF37-95601B40B23E} - System32\Tasks\SMWUpd => C:\Program Files\Common Files\Goobzo\GBUpdate\updater.exe <==== ATTENTION
Task: {D0BF0BCA-B98B-4651-8C77-BBEE4D6A8098} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1293511207-2862067052-4015422231-1000UA => C:\Users\Tabea\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-21] (Facebook Inc.)
Task: {D92B2C1A-5B73-44C1-B3DF-E66883C68F44} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {DD243F2D-FDF5-441B-8196-90B3489594B6} - \SMW_UpdateTask_Time_333939373531323939322d5a5b6c344a415745505a416c No Task File <==== ATTENTION
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1293511207-2862067052-4015422231-1000Core.job => C:\Users\Tabea\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1293511207-2862067052-4015422231-1000UA.job => C:\Users\Tabea\AppData\Local\Facebook\Update\FacebookUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2013-12-24 20:59 - 2013-08-23 14:45 - 00386216 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2rui.dll
2013-12-24 20:59 - 2013-10-31 09:08 - 00520872 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2r64.dll
2013-12-24 20:59 - 2013-10-31 09:07 - 00618152 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll
2013-08-30 09:51 - 2013-08-30 09:51 - 00757048 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll
2011-03-22 09:17 - 2011-03-22 09:17 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-05-25 23:25 - 2011-05-25 23:25 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-04-24 02:29 - 2011-04-24 02:29 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-11-28 14:13 - 2012-11-28 14:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-11-28 14:13 - 2012-11-28 14:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-04-24 02:29 - 2011-04-24 02:29 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2011-04-24 02:29 - 2011-04-24 02:29 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:C5831B98
AlternateDataStreams: C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Acer MSN.website:TASKICON_0FA6946226F21BD7E8F75BBFA031461487075638
AlternateDataStreams: C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Acer MSN.website:TASKICON_1FA6946226F21BD7E8F75BBFA031461135116317
AlternateDataStreams: C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Acer MSN.website:TASKICON_2FA6946226F21BD7E8F75BBFA03146-12823272
AlternateDataStreams: C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Acer MSN.website:TASKICON_3FA6946226F21BD7E8F75BBFA03146-1180859722
AlternateDataStreams: C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Start Menu\Acer MSN.website:TASKICON_4FA6946226F21BD7E8F75BBFA031461739172809
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1293511207-2862067052-4015422231-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Tabea\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-1293511207-2862067052-4015422231-500 - Administrator - Disabled)
Gast (S-1-5-21-1293511207-2862067052-4015422231-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1293511207-2862067052-4015422231-1002 - Limited - Enabled)
Tabea (S-1-5-21-1293511207-2862067052-4015422231-1000 - Administrator - Enabled) => C:\Users\Tabea
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Symantec Iron Driver
Description: Symantec Iron Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SymIRON
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Symantec Network Security WFP Driver
Description: Symantec Network Security WFP Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SymNetS
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: BHDrvx64
Description: BHDrvx64
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: BHDrvx64
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Norton Internet Security Settings Manager
Description: Norton Internet Security Settings Manager
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: ccSet_NIS
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (03/09/2015 05:08:23 PM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (03/09/2015 05:07:56 PM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (03/09/2015 05:07:28 PM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Error: (03/09/2015 05:07:28 PM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2015-03-08 10:47:55.246
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-03-08 10:47:54.973
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:48.111
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:47.913
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:44.661
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:44.463
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:40.873
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:40.677
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:37.251
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-08 20:00:37.053
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: AMD A8-3500M APU with Radeon(tm) HD Graphics
Percentage of memory in use: 29%
Total physical RAM: 7658.9 MB
Available physical RAM: 5389.89 MB
Total Pagefile: 15315.99 MB
Available Pagefile: 12614.38 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:581.07 GB) (Free:499.57 GB) NTFS
Drive e: (USB DISK) (Removable) (Total:3.73 GB) (Free:3.68 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: 74B1C40F)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=581.1 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
==================== End Of Log ============================ MfG |