Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.03.2015
Suchlauf-Zeit: 18:14:31
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.27.07
Rootkit Datenbank: v2015.03.26.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Tanja
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 362913
Verstrichene Zeit: 31 Min, 35 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 42
PUP.Optional.Snapdo.T, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [f88ba1a98604f93d28aa3532b35001ff],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [671c9ab0ccbe0432f21d86a54eb50ef2],
PUP.Optional.SearchResults.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{377e5d4d-77e5-476a-8716-7e70a9272da0}, In Quarantäne, [9ce798b2dcae3afca46658d74cb710f0],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\SmdmF, In Quarantäne, [354e6cdea9e14fe7975ee8f3c53e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9, In Quarantäne, [6e15dc6ed7b342f4c941b547020149b7],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine, In Quarantäne, [21620f3bcebcb97d5caed626fa097b85],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0, In Quarantäne, [97eca3a7d1b994a209010eee9e65dd23],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3, In Quarantäne, [acd799b1642655e16e9be418d52ec937],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync, In Quarantäne, [641faaa06a2089adb654ab51f90aae52],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0, In Quarantäne, [ef943e0cbcce25117595ee0e679cb749],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass, In Quarantäne, [7d06b7934644bb7bf218f7059172b24e],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1, In Quarantäne, [1271cc7ea3e7c0769b6fe21a1ce7ba46],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass, In Quarantäne, [d6adf456cbbf79bd8486a95330d33ac6],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1, In Quarantäne, [12719eacf496b4828c7eea123cc7b34d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine, In Quarantäne, [21627eccb1d92d0940cacb3112f123dd],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0, In Quarantäne, [fb8850fa74161323bc4e22da9073a45c],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine, In Quarantäne, [186b87c33e4c1e1827e38f6df80b6d93],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [b4cfdf6b7d0d3501f01af20aa95a738d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [bdc63e0cff8baa8c4ac0906cfe05f907],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [206377d3dab00e287595ab5158ab04fc],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc, In Quarantäne, [384be8625c2e62d467a348b45ba8ab55],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [0d762c1e1e6c9f97a7634ab28d76c739],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher, In Quarantäne, [196ad9711b6f4aecab5f857706fdca36],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0, In Quarantäne, [81020149305a6cca709ac83423e05aa6],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService, In Quarantäne, [23601d2d9eec71c57298f6069172b14f],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0, In Quarantäne, [f88b68e2414958de9d6d00fc798a837d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine, In Quarantäne, [325153f71377181eb852817bb1528080],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0, In Quarantäne, [196a33178dfd60d6ab5f09f34eb57c84],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback, In Quarantäne, [671c8ebc33578fa7709ac339c43fe61a],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [463ddf6b73178da94ebcda22ee159769],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc, In Quarantäne, [f390d773fe8c80b68a80b04c7390f907],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0, In Quarantäne, [3c47a4a6810992a445c5768648bbd729],
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}, In Quarantäne, [0380ca809eecfb3b7c4ed66d5fa6837d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3, In Quarantäne, [4f34f9517b0f8da9412ebf0712f19d63],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9, In Quarantäne, [295ad674563453e3a8c7992d57acb749],
PUP.Optional.PriceMeter.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\PriceMeterLiveUpdate, In Quarantäne, [b7ccf852d6b49e98b2bee9dd748f02fe],
PUP.Optional.Squeaky.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\Squeaky, In Quarantäne, [aad96cde1b6f280efa6a625ae61dfd03],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [dca7f65457330d29e2027755748f14ec],
PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nikpibnbobmbdbheedjfogjlikpgpnhp, In Quarantäne, [a2e1c684c5c538fe2cc351842ad9a55b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [afd425252664b1859418c54362a29b65],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\INSTALLCORE, In Quarantäne, [ee95d3779ded142297ee29f58b7af60a],
PUP.Optional.DefaultSearch, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}, In Quarantäne, [d6ada2a895f540f65774a0a3a263d22e],
Registrierungswerte: 6
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}|DisplayName, default-search.net, In Quarantäne, [0380ca809eecfb3b7c4ed66d5fa6837d]
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [9ce78ac0f2983105fe1b86530ff4817f]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\INSTALLCORE|tb, 0H1L1J1L1S1R1N, In Quarantäne, [ee95d3779ded142297ee29f58b7af60a]
PUP.Optional.DefaultSearch, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2503}|DisplayName, default-search.net, In Quarantäne, [d6ada2a895f540f65774a0a3a263d22e]
PUP.Optional.Conduit.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, hxxp://search.conduit.com/Results.aspx?ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPE80FDB81-A2F1-4213-9629-95B7B32DB764&q={searchTerms}&SSPV=, In Quarantäne, [7d062d1d701aef472f915c58b64d7987]
PUP.Optional.Trovi.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|DisplayName, Trovi search, In Quarantäne, [e1a2ea60dbafb383b00781cccb3a8f71]
Registrierungsdaten: 5
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000),Ersetzt,[0c77ef5b0e7cc2741c1c66898c790af6]
PUP.Optional.Conduit.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPE80FDB81-A2F1-4213-9629-95B7B32DB764&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://search.conduit.com/?ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPE80FDB81-A2F1-4213-9629-95B7B32DB764&SSPV=),Ersetzt,[d5aed674e5a5de58acca4ca3a95ccb35]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000),Ersetzt,[7a09dd6db7d32214a09cfdf2c73e56aa]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000),Ersetzt,[e69df05a3a50ac8a57e5b33c16ef6b95]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=1ae3c580-95a1-9e4e-b745-8e0295f88f4b&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=05/02/2014&type=hp1000),Ersetzt,[493a29218703e05657e2826df21310f0]
Ordner: 18
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\48DFFFEEAA9B47588E7F09C239D41B62, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\5F83585EA07749CCAE659376F9F481AB, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\67D7F802E53F45C49DE239CC4E698DB2, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\921321EEC1AF4D2D9739EDF9E0E77E90, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\954C30C7D6EC42E4BE02E292CE789D08, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\96D61B66C5BA432EA6003A9104CEA45A, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\AE0FDCBB438E4C9FAF201DF94EB82B2B, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\DA8501F22FF14E62B8C7C88D89A7FF37, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.Datamngr.A, C:\Users\Tanja\AppData\LocalLow\DataMngr, In Quarantäne, [463dad9d3654e551d5dcb9c5000332ce],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect, In Quarantäne, [aed5004a0c7e84b290babad315ee9967],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [aed5004a0c7e84b290babad315ee9967],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [aed5004a0c7e84b290babad315ee9967],
PUP.Optional.PriceMeter.A, C:\Users\Tanja\AppData\Local\PriceMeterLiveUpdate, In Quarantäne, [265dc08a8dfd6bcb60baeac16b988b75],
PUP.Optional.PriceMeter.A, C:\Users\Tanja\AppData\Local\PriceMeterLiveUpdate\CrashReports, In Quarantäne, [265dc08a8dfd6bcb60baeac16b988b75],
PUP.Optional.SearchProtect.A, C:\Users\Tanja\AppData\Local\avaxvyyvyf, In Quarantäne, [add6351523674cea02b39b153cc7bb45],
Dateien: 48
PUP.Optional.Conduit.A, C:\Users\Tanja\AppData\Roaming\OpenCandy\67D7F802E53F45C49DE239CC4E698DB2\SSStub_SearchProtect_p1v0.exe, In Quarantäne, [9be8a0aaa1e938fe0c4e99b016eb3fc1],
PUP.Optional.OpenCandy.A, C:\Users\Tanja\AppData\Roaming\OpenCandy\954C30C7D6EC42E4BE02E292CE789D08\LatestDLMgr.exe, In Quarantäne, [30534802cbbfc27417245fda9d6423dd],
PUP.Optional.SearchProtect.A, C:\Users\Tanja\AppData\Roaming\OpenCandy\96D61B66C5BA432EA6003A9104CEA45A\sp-downloader.exe, In Quarantäne, [fd86c08ab1d97fb7561fc5e948b9ea16],
PUP.Optional.Linkury.A, C:\Users\Tanja\AppData\Roaming\OpenCandy\DA8501F22FF14E62B8C7C88D89A7FF37\Installer.exe, In Quarantäne, [602359f1226848ee916c3665a5607d83],
PUP.Optional.PriceMeter.A, C:\Users\Tanja\AppData\Roaming\RHEng\0980BCC9F6404631A581F9397D399287\pm.exe, In Quarantäne, [81023d0d7e0c1c1abd38a8edac559d63],
PUP.Optional.OpenCandy, C:\Users\Tanja\Downloads\cdbxp_setup_4.5.2.4214_minimal.exe, In Quarantäne, [5e253d0d98f2fa3c50acee31aa5650b0],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Local\OpenCandy\OpenCandy_{22565755-FEC4-4F2F-98E6-354974D6CB93}.dll, In Quarantäne, [443f58f2503af83e083d0d1216f0a759],
PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemeterdownloader, In Quarantäne, [562dbf8b1476b77f62492fb338cb916f],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\48DFFFEEAA9B47588E7F09C239D41B62\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\5F83585EA07749CCAE659376F9F481AB\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\921321EEC1AF4D2D9739EDF9E0E77E90\TuneUp2014GER15day-de-DE-p4v1.exe, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\954C30C7D6EC42E4BE02E292CE789D08\3135.ico, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\954C30C7D6EC42E4BE02E292CE789D08\TuneUpUtilities2013-2200218_de-DE.exe, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.OpenCandy, C:\Users\Tanja\AppData\Roaming\OpenCandy\AE0FDCBB438E4C9FAF201DF94EB82B2B\SkypeSetupFull(590)trackable-6.18.0.105.exe, In Quarantäne, [7c07a6a4a9e1f145bdcdd99fc2410bf5],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\1.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\a.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\b.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\c.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\d.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\e.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\f.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\g.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\h.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\i.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\J.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\k.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\l.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\m.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\mru.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\n.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\o.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\p.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\q.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\r.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\s.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\t.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\u.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\v.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\w.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\x.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\y.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.PriceGong.A, C:\Users\Tanja\AppData\LocalLow\PriceGong\Data\z.xml, In Quarantäne, [c8bba3a701891b1bf7f6e7942bd80cf4],
PUP.Optional.Datamngr.A, C:\Users\Tanja\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}64, In Quarantäne, [463dad9d3654e551d5dcb9c5000332ce],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [aed5004a0c7e84b290babad315ee9967],
PUP.Optional.SearchProtect.A, C:\Users\Tanja\AppData\Local\avaxvyyvyf\pvpqbjobmlpfqlovvawq, In Quarantäne, [add6351523674cea02b39b153cc7bb45],
PUP.Optional.SearchProtect.A, C:\Users\Tanja\AppData\Local\avaxvyyvyf\rfobmlpfqlovvawq, In Quarantäne, [add6351523674cea02b39b153cc7bb45],
PUP.Optional.SearchProtect.A, C:\Users\Tanja\AppData\Local\avaxvyyvyf\rpboobmlpfqlovvawq, In Quarantäne, [add6351523674cea02b39b153cc7bb45],
PUP.Optional.SearchProtect.A, C:\Users\Tanja\AppData\Local\avaxvyyvyf\stb.dat, In Quarantäne, [add6351523674cea02b39b153cc7bb45],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.113 - Bericht erstellt 27/03/2015 um 19:15:27
# Aktualisiert 22/03/2015 von Xplode
# Datenbank : 2015-03-27.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : Tanja - TANJA-PC
# Gestarted von : C:\Users\Tanja\Downloads\AdwCleaner_4.113.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : APNMCP
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\Program Files\AskPartnerNetwork
Ordner Gelöscht : C:\Program Files\VNT
Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Program Files\Common Files\ParetoLogic
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\Temp\apn
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\apn
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\AskPartnerNetwork
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\FileTypeAssistant
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\OpenCandy
Ordner Gelöscht : C:\Users\Tanja\AppData\Local\VNT
Ordner Gelöscht : C:\Users\Tanja\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\Tanja\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Tanja\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\Tanja\AppData\Roaming\RHEng
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
Datei Gelöscht : C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
Datei Gelöscht : C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage
Datei Gelöscht : C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.metrolyrics.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
Task Gelöscht : paretologic registration3
Task Gelöscht : paretologic update version3
Task Gelöscht : pricemeterdownloader
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaabfjnbeinlpljodiajipidiompfl
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pcoohmdcpejoeggdnihdfhohjgdbllgm
Schlüssel Gelöscht : HKCU\Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VNT]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2438727
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2857572
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{45F8961E-1314-421E-9F00-BDDE18CF8EA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4825ACAD-F495-4CDD-9603-9C91BABB2B88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5B60D1C0-453A-485D-AE91-61FAC9203719}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D1C6444C-CC06-4060-A486-736DEAFD9C16}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8746A3A-A372-4C8B-96E5-B58F6474EB19}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F509ADC2-B40E-470F-A7B7-45191486B5CB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{89449F37-4AB2-46ED-A566-BB3A7797701B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7B13EC3E-999A-4B70-B9CB-2617B8323822}]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork
Schlüssel Gelöscht : HKCU\Software\Bitberry Software
Schlüssel Gelöscht : HKCU\Software\Bitberry
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\MGShareware
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\AskPartnerNetwork
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\iLividSRTB
Schlüssel Gelöscht : HKLM\SOFTWARE\MGShareware
Schlüssel Gelöscht : HKLM\SOFTWARE\ParetoLogic
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{657187F0-8B08-41D3-8468-813BB85AE09E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v
-\\ Google Chrome v41.0.2272.101
*************************
AdwCleaner[R0].txt - [7865 Bytes] - [27/03/2015 19:12:44]
AdwCleaner[S0].txt - [7787 Bytes] - [27/03/2015 19:15:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7846 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.6 (03.22.2015:1)
OS: Windows 7 Home Premium x86
Ran by Tanja on 27.03.2015 at 19:26:49,45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\freerip"
Successfully deleted: [Folder] "C:\Program Files\freerip3"
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Tanja\appdata\local\Google\Chrome\User Data\Default\Extensions\fanogbnclpilemkifpjeglokomebpnef
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.03.2015 at 19:31:48,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Tanja (administrator) on TANJA-PC on 27-03-2015 19:36:06
Running from C:\Users\Tanja\Downloads
Loaded Profiles: Tanja (Available profiles: Tanja)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Users\Tanja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
() C:\Users\Tanja\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7711264 2009-08-19] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [UCam_Menu] => C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-02-13] (Apple Inc.)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-19] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [978520 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [QuickTime Plugin Install] => C:\Program Files\QuickTime\Plugins\DeleteMe1.exe [86016 2014-11-10] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-02-13] (Apple Inc.)
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-09-22] (Google Inc.)
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Tanja\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [Amazon Cloud Player] => C:\Users\Tanja\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] ()
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [GoogleChromeAutoLaunch_FB2E67EEF5904AC634A7B3DA98460BC7] => C:\Program Files\Google\Chrome\Application\chrome.exe [809288 2015-03-14] (Google Inc.)
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [ApplePhotoStreams] => C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Run: [iCloudDrive] => C:\Program Files\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
Startup: C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-771618654-3341757510-301361698-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=de-DE&Src=MSE&Tid=0003295F&OHP=about%3Ablank&OSP=
HKU\S-1-5-21-771618654-3341757510-301361698-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-771618654-3341757510-301361698-1000 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
BHO: Avira SearchFree Toolbar -> {41564952-412D-5637-4300-7A786E7484D7} -> "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll" No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
Toolbar: HKU\S-1-5-21-771618654-3341757510-301361698-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.)
DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} hxxp://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20100826144410
DPF: {D27CDB6E-AE6D-11CF-96B8-444555540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-771618654-3341757510-301361698-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Tanja\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2014-07-21] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2014-07-21] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2014-07-21] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2014-07-21] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2014-07-21] (Apple Inc.)
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-23]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-23]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-02-23]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-10]
FF HKU\S-1-5-21-771618654-3341757510-301361698-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2014-07-19]
Chrome:
=======
CHR HomePage: Default -> chrome://apps/
CHR StartupUrls: Default -> "chrome://apps/"
CHR DefaultSearchKeyword: Default -> google.com_
CHR DefaultSearchURL: Default -> hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
CHR DefaultSuggestURL: Default ->
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\41.0.2272.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\41.0.2272.101\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\41.0.2272.101\pdf.dll ()
CHR Plugin: (registryAccess) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabfjnbeinlpljodiajipidiompfl\7.15.10.0_0\background/registryAccess.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\windows\system32\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Profile: C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Mein Ebay) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\amppmommjclmlfdjmfiblififijpigmd [2013-07-08]
CHR Extension: (Wetter von wetter.com) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgapkfcninhaogfjjoohaleiclbhjmnp [2013-06-25]
CHR Extension: (YouTube) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-16]
CHR Extension: (Facebook) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2013-06-25]
CHR Extension: (Google Search) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-16]
CHR Extension: (Color Tunnel) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\epkoakmabaognokfndhfaebaknjgnpgg [2013-06-25]
CHR Extension: (HopToShop Offers for Amazon.de) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgaibgbcnfjfjmnaclddkdkadlplcknb [2014-12-10]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (Google Wallet) - C:\Users\Tanja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2015-03-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [992560 2015-03-19] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22184 2015-01-30] (Microsoft Corporation)
S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [284472 2015-01-30] (Microsoft Corporation)
R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2015-03-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-09] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-04] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-03-27] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [239224 2014-11-15] (Microsoft Corporation)
R1 MpKslb05b225f; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{98D33103-AD53-4BEB-B891-2D4E7123F73F}\MpKslb05b225f.sys [39464 2015-03-27] (Microsoft Corporation)
R0 PxHelp20; C:\windows\System32\Drivers\PxHelp20.sys [46096 2012-08-10] (Corel Corporation)
R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-09] (Avira GmbH)
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Tanja\AppData\Local\Temp\catchme.sys [X]
S3 StarOpen; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-27 19:31 - 2015-03-27 19:31 - 00001192 _____ () C:\Users\Tanja\Desktop\JRT.txt
2015-03-27 19:25 - 2015-03-27 19:26 - 01388782 _____ (Thisisu) C:\Users\Tanja\Downloads\JRT (1).exe
2015-03-27 19:24 - 2015-03-27 19:25 - 01388782 _____ (Thisisu) C:\Users\Tanja\Downloads\JRT.exe
2015-03-27 19:12 - 2015-03-27 19:16 - 00000000 ____D () C:\AdwCleaner
2015-03-27 19:11 - 2015-03-27 19:11 - 02168320 _____ () C:\Users\Tanja\Downloads\AdwCleaner_4.113.exe
2015-03-27 19:06 - 2015-03-27 19:06 - 00021570 _____ () C:\Users\Tanja\Desktop\mbam.txt
2015-03-27 18:14 - 2015-03-27 19:21 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-27 18:13 - 2015-03-27 18:13 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-27 18:13 - 2015-03-27 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-27 18:12 - 2015-03-27 18:13 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-27 18:12 - 2015-03-27 18:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-27 18:12 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-03-27 18:12 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-03-27 18:12 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-03-27 18:10 - 2015-03-27 18:10 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Tanja\Downloads\mbam-setup-2.1.4.1018.exe
2015-03-27 06:57 - 2015-03-27 06:57 - 00013817 _____ () C:\ComboFix.txt
2015-03-26 21:06 - 2015-03-26 21:06 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-26 20:35 - 2011-06-26 07:45 - 00256000 _____ () C:\windows\PEV.exe
2015-03-26 20:35 - 2010-11-07 18:20 - 00208896 _____ () C:\windows\MBR.exe
2015-03-26 20:35 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2015-03-26 20:35 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2015-03-26 20:35 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2015-03-26 20:35 - 2000-08-31 01:00 - 00098816 _____ () C:\windows\sed.exe
2015-03-26 20:35 - 2000-08-31 01:00 - 00080412 _____ () C:\windows\grep.exe
2015-03-26 20:35 - 2000-08-31 01:00 - 00068096 _____ () C:\windows\zip.exe
2015-03-26 20:31 - 2015-03-27 06:57 - 00000000 ____D () C:\Qoobox
2015-03-26 20:30 - 2015-03-26 21:14 - 00000000 ____D () C:\windows\erdnt
2015-03-26 20:26 - 2015-03-27 06:26 - 05615749 ____R (Swearware) C:\Users\Tanja\Downloads\ComboFix.exe
2015-03-26 20:08 - 2015-03-26 20:08 - 00001222 _____ () C:\Users\Tanja\Desktop\Revo Uninstaller.lnk
2015-03-26 20:08 - 2015-03-26 20:08 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-03-26 20:07 - 2015-03-26 20:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tanja\Downloads\revosetup95.exe
2015-03-26 16:00 - 2009-06-18 02:15 - 00214024 _____ (McAfee, Inc.) C:\windows\system32\Drivers\mfehidk.sys
2015-03-26 16:00 - 2009-06-18 02:15 - 00079816 _____ (McAfee, Inc.) C:\windows\system32\Drivers\mfeavfk.sys
2015-03-26 16:00 - 2009-06-18 02:15 - 00040552 _____ (McAfee, Inc.) C:\windows\system32\Drivers\mfesmfk.sys
2015-03-26 16:00 - 2009-06-18 02:15 - 00035272 _____ (McAfee, Inc.) C:\windows\system32\Drivers\mfebopk.sys
2015-03-26 16:00 - 2009-06-18 02:14 - 00034248 _____ (McAfee, Inc.) C:\windows\system32\Drivers\mferkdk.sys
2015-03-26 16:00 - 2009-06-10 22:27 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
2015-03-26 16:00 - 2009-04-09 06:23 - 00130424 _____ (McAfee, Inc.) C:\windows\system32\Drivers\Mpfp.sys
2015-03-26 15:59 - 2009-07-14 02:15 - 00606208 _____ (Microsoft Corporation) C:\windows\system32\mstime.dll
2015-03-26 15:59 - 2009-07-14 02:15 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\ieaksie.dll
2015-03-26 15:59 - 2009-07-14 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\system32\ieakeng.dll
2015-03-26 15:59 - 2009-07-14 02:15 - 00018432 _____ (Microsoft Corporation) C:\windows\system32\corpol.dll
2015-03-26 15:59 - 2009-07-14 02:14 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\admparse.dll
2015-03-26 15:59 - 2009-07-14 02:05 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\ieakui.dll
2015-03-26 13:26 - 2015-03-26 13:28 - 00036091 _____ () C:\Users\Tanja\Downloads\Addition.txt
2015-03-26 13:23 - 2015-03-27 19:36 - 00020984 _____ () C:\Users\Tanja\Downloads\FRST.txt
2015-03-26 13:22 - 2015-03-27 19:36 - 00000000 ____D () C:\FRST
2015-03-26 13:22 - 2015-03-26 13:22 - 01135104 _____ (Farbar) C:\Users\Tanja\Downloads\FRST.exe
2015-03-26 07:39 - 2015-03-26 07:39 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\Tanja\Downloads\SpyHunter-Installer.exe
2015-03-25 08:06 - 2015-03-25 08:06 - 05813872 _____ (ParetoLogic Inc.) C:\Users\Tanja\Downloads\ParetoLogic PC Health Advisor_de (1).exe
2015-03-25 08:01 - 2015-03-27 19:21 - 00000470 _____ () C:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
2015-03-25 07:59 - 2015-03-25 07:59 - 05813872 _____ (ParetoLogic Inc.) C:\Users\Tanja\Downloads\ParetoLogic PC Health Advisor_de.exe
2015-03-25 07:25 - 2015-03-11 04:30 - 00623616 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-03-25 07:25 - 2015-03-11 04:30 - 00534528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-03-25 07:25 - 2015-03-11 04:29 - 00818176 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-03-25 07:25 - 2015-03-11 04:29 - 00327168 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-03-25 07:25 - 2015-03-11 04:29 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-03-25 07:25 - 2015-03-11 04:29 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-03-25 07:25 - 2015-03-11 04:29 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-03-25 07:25 - 2015-03-11 04:26 - 00892928 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-03-14 22:07 - 2015-03-14 22:07 - 00131072 ____N () C:\windows\Minidump\031415-24273-01.dmp
2015-03-11 07:05 - 2015-02-26 04:11 - 02381312 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-03-11 07:05 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-03-11 07:05 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-03-11 07:05 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-03-11 07:05 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-03-11 07:05 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-03-11 07:05 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-03-11 07:05 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-03-11 07:05 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-03-11 07:05 - 2015-02-20 02:56 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-03-11 07:05 - 2015-02-20 02:50 - 00667648 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-03-11 07:05 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 07:05 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-03-11 07:05 - 2015-02-20 02:24 - 00684544 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-03-11 07:05 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-03-11 07:05 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-03-11 07:05 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-03-11 07:05 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-03-11 07:05 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2015-03-11 07:04 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-03-11 07:04 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-03-11 07:04 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-03-11 07:04 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-03-11 07:04 - 2015-02-20 03:22 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-03-11 07:04 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-03-11 07:04 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-03-11 07:04 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-03-11 07:04 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-03-11 07:04 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-03-11 07:04 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-03-11 07:04 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-03-11 07:04 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-03-11 07:04 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-03-11 07:04 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-03-11 07:04 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2015-03-11 07:03 - 2015-03-06 06:15 - 00137656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-03-11 07:03 - 2015-03-06 06:15 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-03-11 07:03 - 2015-03-06 06:10 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-03-11 07:03 - 2015-03-06 06:10 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-03-11 07:03 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-03-11 07:03 - 2015-03-06 06:09 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-03-11 07:03 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-03-11 07:03 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-03-11 07:03 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-03-11 07:03 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2015-03-11 07:03 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-03-11 07:03 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2015-03-11 07:03 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2015-03-11 07:03 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-03-11 07:03 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2015-03-11 07:03 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2015-03-11 07:03 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2015-03-11 07:03 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2015-03-11 07:03 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2015-03-11 07:03 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2015-03-11 07:02 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-03-11 07:02 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-03-11 07:02 - 2015-02-03 04:16 - 00078784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-03-11 07:02 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00475136 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00157184 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-03-11 07:02 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2015-03-11 07:02 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2015-03-11 07:02 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2015-03-11 07:02 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2015-03-11 07:02 - 2015-02-03 04:11 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe
2015-03-11 07:02 - 2015-02-03 04:11 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe
2015-03-11 07:02 - 2015-02-03 04:10 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll
2015-03-11 07:02 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2015-03-11 07:02 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-03-11 07:02 - 2015-02-03 04:00 - 00593920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2015-03-11 07:02 - 2015-02-03 03:26 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2015-03-11 07:02 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-03-11 07:02 - 2014-10-31 23:22 - 00521384 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2015-03-11 07:02 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2015-03-11 07:02 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2015-02-25 19:50 - 2015-01-09 00:44 - 00419936 _____ () C:\windows\system32\locale.nls
2015-02-25 19:14 - 2015-01-09 03:48 - 00635904 _____ (Microsoft Corporation) C:\windows\system32\perftrack.dll
2015-02-25 19:14 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\wdi.dll
2015-02-25 19:14 - 2015-01-09 03:48 - 00027136 _____ (Microsoft Corporation) C:\windows\system32\powertracker.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-27 19:28 - 2009-07-14 05:34 - 00023328 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-27 19:28 - 2009-07-14 05:34 - 00023328 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-27 19:27 - 2010-01-30 09:57 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-27 19:21 - 2015-02-22 21:35 - 00000000 ___RD () C:\Users\Tanja\iCloudDrive
2015-03-27 19:21 - 2010-01-30 09:57 - 00001094 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-27 19:18 - 2009-09-22 06:48 - 01475832 _____ () C:\windows\PFRO.log
2015-03-27 19:18 - 2009-07-14 05:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-27 19:18 - 2009-07-14 05:39 - 00299103 _____ () C:\windows\setupact.log
2015-03-27 19:17 - 2009-09-22 06:23 - 01074971 _____ () C:\windows\WindowsUpdate.log
2015-03-27 19:16 - 2009-12-08 00:59 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2015-03-27 19:05 - 2012-03-31 06:34 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-27 06:55 - 2009-07-14 03:04 - 00000215 _____ () C:\windows\system.ini
2015-03-26 21:15 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2015-03-26 21:15 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-03-26 13:10 - 2009-07-14 05:33 - 00508192 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-25 13:27 - 2009-07-26 21:06 - 01768124 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-25 08:12 - 2013-05-27 12:20 - 00000000 ____D () C:\ProgramData\tmp
2015-03-25 08:02 - 2010-08-16 14:00 - 00000792 _____ () C:\Users\Tanja\Desktop\Tanja Bilder.lnk
2015-03-25 08:02 - 2009-12-14 17:35 - 00000830 _____ () C:\Users\Tanja\Desktop\Tanja Mukke.lnk
2015-03-25 07:32 - 2014-12-10 19:31 - 00000000 ____D () C:\windows\system32\appraiser
2015-03-25 07:32 - 2014-05-06 06:42 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-03-21 03:29 - 2013-06-04 19:24 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-17 19:31 - 2009-07-14 05:53 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2015-03-14 22:07 - 2010-05-30 07:42 - 00000000 ____D () C:\windows\Minidump
2015-03-11 19:19 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\system32\de-DE
2015-03-11 14:14 - 2009-12-07 17:13 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-11 14:13 - 2013-08-14 06:24 - 00000000 ____D () C:\windows\system32\MRT
2015-03-11 14:03 - 2009-12-13 12:01 - 119837696 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-03-04 12:51 - 2014-02-06 13:36 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2015-03-04 12:51 - 2014-02-06 13:36 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2015-03-04 12:51 - 2014-02-06 13:36 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2015-03-03 14:16 - 2009-12-10 20:17 - 00246920 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-02-26 06:48 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\tracing
==================== Files in the root of some directories =======
2014-02-10 22:53 - 2014-02-10 22:53 - 49940480 _____ () C:\Program Files\GUTE0B6.tmp
2009-12-10 23:38 - 2009-12-10 23:38 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2009-12-07 17:09 - 2009-08-17 06:54 - 0131368 _____ () C:\ProgramData\FullRemove.exe
2011-01-14 23:16 - 2011-01-14 23:16 - 0001302 _____ () C:\ProgramData\ss.ini
2011-01-14 23:40 - 2011-01-14 23:40 - 0000033 _____ () C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
Some content of TEMP:
====================
C:\Users\Tanja\AppData\Local\Temp\avgnt.exe
C:\Users\Tanja\AppData\Local\Temp\Quarantine.exe
C:\Users\Tanja\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-04 20:34
==================== End Of Log ============================ --- --- ---
--- --- --- |