ganz schön viele logfiles :D
also das symbol welches ich im ersten post beschrieben habe ist nun weg! :) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.04.2015
Suchlauf-Zeit: 19:55:27
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.22.05
Rootkit Datenbank: v2015.04.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Dominic
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 384152
Verstrichene Zeit: 16 Min, 34 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, 2180, Löschen bei Neustart, [25782c434e3c2214e497967c20e245bb]
PUP.Optional.ELEX, C:\Program Files (x86)\XTab\HPNotify.exe, 3952, Löschen bei Neustart, [396456190a800d2962fcb67d5fa36898]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, 3816, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868]
Module: 8
PUP.Optional.SearchProtect, C:\Program Files (x86)\XTab\BrowserAction.dll, Löschen bei Neustart, [8e0f74fb3951bc7a6a76a59df30fa858],
PUP.Optional.SearchProtect, C:\Program Files (x86)\XTab\IeWatchDog.dll, Löschen bei Neustart, [fba20966414969cd51af08eea2639070],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
Registrierungsschlüssel: 18
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [25782c434e3c2214e497967c20e245bb],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [3964c0af4446bc7a555d3e08748f738d],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [3964c0af4446bc7a555d3e08748f738d],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [3964c0af4446bc7a555d3e08748f738d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\delta-homesSoftware, In Quarantäne, [cbd20867c1c9b97d0bd4ab3fc142d828],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, In Quarantäne, [1984f47bf694be780adc9a3730d39e62],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\PriceMeterLiveUpdate, In Quarantäne, [c2db5b14dab02412a8c6fed5f3100cf4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [b3eac9a676141224b0779b4b44bf738d],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [930a9fd0b7d34fe7748ea9923acba35d],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [faa3e58a602ad75f6fb724c2b251946c],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [207d8be4078386b0b0befdf29c67ab55],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginService, In Quarantäne, [900d6b044347b68096414a8e679c8080],
PUP.Optional.PriceMeter.A, HKU\S-1-5-18\SOFTWARE\PriceMeterLiveUpdate, In Quarantäne, [7429b3bcabdf75c1b4b814bf8281946c],
PUP.Optional.PriceMeter.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\PriceMeterLiveUpdate, In Quarantäne, [3d607ef15337f343105c6271917240c0],
PUP.Optional.PriceMeter.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\PriceMeterUpdater, In Quarantäne, [d9c4e887cfbb9b9b6effb32055ae26da],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [b8e584ebcfbbc86e746edb3528dcd030],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\INSTALLCORE, In Quarantäne, [613c383790fa35014f633de9b055ed13],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [faa394dbd0ba191db1bc806f08fbfd03],
Registrierungswerte: 14
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.istartsurf.com/web/?type=dspp&q={searchTerms}, In Quarantäne, [e6b7cea1c5c552e4c749b3a1000516ea]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [faa3e58a602ad75f6fb724c2b251946c]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\INSTALLCORE|tb, 0H1L1J1L1S1R1N, In Quarantäne, [613c383790fa35014f633de9b055ed13]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [ecb1abc47416e3532e3c893a8e75a45c]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [633ad09f256573c31b4f1ea5ff046799]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, hxxp://do-search.com//favicon.ico, In Quarantäne, [653882ed74160a2c600a9132ca39f40c]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{24617E59-8D7F-49D9-9600-DBE8CC8BB143}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [e5b8abc4d7b3d5614e1c5d66996a41bf]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.istartsurf.com/web/?type=dspp&q={searchTerms}, In Quarantäne, [643980ef137781b59778bf95d72ed52b]
PUP.Optional.Delta.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, hxxp://search.delta-homes.com/web/?type=ds&ts=1429106301&from=ient04150&uid=ST3320820AS_9QF2B8K2XXXX9QF2B8K2&q={searchTerms}, In Quarantäne, [a5f80d62454538feed09c5fec340e917]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{D070FC2D-98F5-4708-92E9-32E85A6C8894}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [b6e707687d0da5919ecc487b00033ac6]
PUP.Optional.Conduit.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{D070FC2D-98F5-4708-92E9-32E85A6C8894}|SuggestionsURL_JSON, hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [e0bdc4ab8307fd39cb9edaeaf90a33cd]
PUP.Optional.Conduit.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{D070FC2D-98F5-4708-92E9-32E85A6C8894}|FaviconURL, hxxp://search.conduit.com/favicon.ico, In Quarantäne, [0c915e11c6c4b97d6dfc09bb3dc6dd23]
PUP.Optional.Conduit.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{D070FC2D-98F5-4708-92E9-32E85A6C8894}|TopResultURL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3312806&CUI=UN81228051410273074&UM=1, In Quarantäne, [a4f97bf494f6b87edc8d5d6728db60a0]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [faa379f6fb8f0135e1896d56ad569868]
Registrierungsdaten: 9
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp),Ersetzt,[5f3ed8976e1cc57112d97f792fd6d22e]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[65386708bdcdf93db72452b223e31de3]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1396005498&from=cor&uid=ST3320820AS_9QF2B8K2XXXX9QF2B8K2&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1396005498&from=cor&uid=ST3320820AS_9QF2B8K2XXXX9QF2B8K2&q={searchTerms}),Ersetzt,[d4c974fbc8c2dc5a181d11f40bfb49b7]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp),Ersetzt,[623ba7c83159de58fcef80781fe60ff1]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp),Ersetzt,[603dd6998802c3730be0cf29a95c9e62]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1396005498&from=cor&uid=ST3320820AS_9QF2B8K2XXXX9QF2B8K2&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1396005498&from=cor&uid=ST3320820AS_9QF2B8K2XXXX9QF2B8K2&q={searchTerms}),Ersetzt,[326bc0afaedc86b042f3e52047bfa45c]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[0895c1aed6b42b0b92495da77492d030]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp),Ersetzt,[67367ef1a3e736004e9b19dfcb3a40c0]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=dspp&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&q={searchTerms}),Ersetzt,[4d50c3ac4347cc6abc2d37c1e61f9b65]
Ordner: 41
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, In Quarantäne, [96074629b5d5d660bf83e3af788bfd03],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [96074629b5d5d660bf83e3af788bfd03],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Roaming\PriceMeterUpdater, In Quarantäne, [fe9fd19e92f852e430a8bbda5ba87789],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Roaming\PriceMeterUpdater\UpdateProc, In Quarantäne, [fe9fd19e92f852e430a8bbda5ba87789],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate, In Quarantäne, [f1ac66096228ae886574791c14eff808],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\CrashReports, In Quarantäne, [f1ac66096228ae886574791c14eff808],
PUP.Optional.SystemSpeedup, C:\Users\Dominic\AppData\Roaming\systweak\ssd, In Quarantäne, [afee5d12dab0092df2ffc2e19b68837d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [bbe275fa8703ae88f41313943ec5a55b],
PUP.Optional.SupTab.A, C:\Users\Dominic\AppData\Roaming\SupTab, In Quarantäne, [46570f60ed9de74ffd0b188f828108f8],
PUP.Optional.SweetPage.A, C:\Users\Dominic\AppData\Roaming\sweet-page, In Quarantäne, [e4b9aec11575e74f5eed3e6e4eb532ce],
PUP.Optional.SweetPage.A, C:\Users\Dominic\AppData\Roaming\sweet-page\images, In Quarantäne, [e4b9aec11575e74f5eed3e6e4eb532ce],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Local\PriceMeterLiveUpdate, In Quarantäne, [8e0f175892f8003680dd6a4ed52e19e7],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Local\PriceMeterLiveUpdate\CrashReports, In Quarantäne, [8e0f175892f8003680dd6a4ed52e19e7],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [138a2a45117971c5ea3ff3c6847fff01],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [138a2a45117971c5ea3ff3c6847fff01],
Dateien: 86
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, Löschen bei Neustart, [25782c434e3c2214e497967c20e245bb],
PUP.Optional.ELEX, C:\Program Files (x86)\XTab\HPNotify.exe, Löschen bei Neustart, [396456190a800d2962fcb67d5fa36898],
PUP.Optional.SearchProtect, C:\Program Files (x86)\XTab\BrowserAction.dll, Löschen bei Neustart, [8e0f74fb3951bc7a6a76a59df30fa858],
PUP.Optional.SearchProtect, C:\Program Files (x86)\XTab\IeWatchDog.dll, Löschen bei Neustart, [fba20966414969cd51af08eea2639070],
PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, In Quarantäne, [3964c0af4446bc7a555d3e08748f738d],
PUP.Optional.SupTab.A, C:\Users\Dominic\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [336a214eabdfd462efa055e2946c48b8],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [8f0eb3bc6d1d9a9cb2dda790af5121df],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, In Quarantäne, [d9c4a5ca63270f272b900d629f6128d8],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, In Quarantäne, [5e3fe08fbcce280e2695cfa021df837d],
PUP.Optional.InstallCore, C:\Users\Dominic\Downloads\CamStudio_Setup_v2.7.2_r326_(build_19Oct2013).exe, In Quarantäne, [4756f778137782b41564497f18ed926e],
PUP.Optional.Somoto, C:\Users\Dominic\Downloads\7ZipSetup-01VF74W.exe, In Quarantäne, [e7b696d9ec9e3ff7654bca6086805ca4],
PUP.Optional.RegCleanerPro, C:\Users\Dominic\Downloads\rcpsetupst_RC1_DE_L_1.exe, In Quarantäne, [edb01b54e4a66fc7b9642d0f748d56aa],
PUP.Optional.RocketFuel.A, C:\Users\Dominic\Downloads\7zip_RocketFuelInstaller.exe, In Quarantäne, [a5f8c7a8eaa06fc7f35b7635699c46ba],
PUP.Optional.Conduit.A, C:\Users\Dominic\Downloads\Microsoft_Security_E_brch.exe, In Quarantäne, [ff9ed59a7119043275118deefc052bd5],
PUP.Optional.Somoto, C:\Users\Dominic\Downloads\FLVPlayerSetup-e4uAwzK.exe, In Quarantäne, [47567ef1f19974c2951b5dcdc83e3dc3],
PUP.Optional.InstallCore, C:\Users\Dominic\Downloads\3DS0450 - Pokemon X -MULTi7-.exe, In Quarantäne, [b7e6aac575159b9b9fdf4192798806fa],
PUP.Optional.Somoto, C:\Users\Dominic\Downloads\7ZipSetup-01VF74W (1).exe, In Quarantäne, [6934abc4b4d6280ef1bf1119887ec937],
PUP.Optional.Somoto, C:\Users\Dominic\Downloads\7ZipSetup-01VF74W (2).exe, In Quarantäne, [762788e7f49641f52c84d357bc4a44bc],
PUP.Optional.Somoto, C:\Users\Dominic\Downloads\7ZipSetup-01VF74W (3).exe, In Quarantäne, [6c310a65c8c21026bcf432f83ec8d22e],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ffsearch_toolbar!1.0.0.1031.xpi, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\install.data, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\searchProvider.xml, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, In Quarantäne, [722b452ae8a294a2fceb9a37a75c9868],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [96074629b5d5d660bf83e3af788bfd03],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Roaming\PriceMeterUpdater\UpdateProc\config.dat, In Quarantäne, [fe9fd19e92f852e430a8bbda5ba87789],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Roaming\PriceMeterUpdater\UpdateProc\info.dat, In Quarantäne, [fe9fd19e92f852e430a8bbda5ba87789],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Roaming\PriceMeterUpdater\UpdateProc\STTL.DAT, In Quarantäne, [fe9fd19e92f852e430a8bbda5ba87789],
PUP.Optional.PriceMeter.A, C:\Users\Dominic\AppData\Roaming\PriceMeterUpdater\UpdateProc\TTL.DAT, In Quarantäne, [fe9fd19e92f852e430a8bbda5ba87789],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [bbe275fa8703ae88f41313943ec5a55b],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, In Quarantäne, [138a2a45117971c5ea3ff3c6847fff01],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.201 - Bericht erstellt 22/04/2015 um 20:21:19
# Aktualisiert 08/04/2015 von Xplode
# Datenbank : 2015-04-22.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : Dominic - DOMINIC-PC
# Gestarted von : G:\Browser Downloads\AdwCleaner_4.201.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files (x86)\DriverToolkit
Ordner Gelöscht : C:\Users\Dominic\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Dominic\AppData\Local\DriverToolkit
Ordner Gelöscht : C:\Users\Dominic\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Dominic\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Ordner Gelöscht : C:\Users\Dominic\AppData\Roaming\Opera Software\Opera Stable\Extensions\npnkeeiehehhefofiekoflfedgehcdhl
Datei Gelöscht : C:\Users\Dominic\AppData\Roaming\Opera Software\Opera Stable\Local Extension Settings\npnkeeiehehhefofiekoflfedgehcdhl
Datei Gelöscht : C:\Users\Dominic\Favorites\Startfenster.lnk
Datei Gelöscht : C:\Users\Dominic\Favorites\Links\Startfenster.lnk
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Dominic\daemonprocess.txt
Datei Gelöscht : C:\Users\Dominic\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk
Datei Gelöscht : C:\Users\Dominic\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Startfenster.lnk
Datei Gelöscht : C:\Users\Dominic\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk
Datei Gelöscht : C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Dominic\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5EB0259D-AB79-4AE6-A6E6-24FFE21C3DA4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CADAF6BE-BF50-4669-8BFD-C27BD4E6181B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{24617E59-8D7F-49D9-9600-DBE8CC8BB143}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\DriverToolkit
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\DeviceVM
Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Wpm
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Google Chrome v
[C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.sm.de/?q={searchTerms}
-\\ Opera v28.0.1750.51
*************************
AdwCleaner[R1].txt - [6080 Bytes] - [22/04/2015 20:19:29]
AdwCleaner[S1].txt - [5423 Bytes] - [22/04/2015 20:21:19]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5482 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.0 (04.20.2015:1)
OS: Windows 7 Professional x64
Ran by Dominic on 22.04.2015 at 20:28:49,71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D070FC2D-98F5-4708-92E9-32E85A6C8894}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\NVIDIA Update Core Service
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Windows\syswow64\ai_recyclebin
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.04.2015 at 20:29:59,01
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2015
Ran by Dominic (administrator) on DOMINIC-PC on 22-04-2015 20:31:04
Running from G:\Browser Downloads
Loaded Profiles: Dominic (Available profiles: Dominic)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Creative Technology Ltd) C:\Windows\SysWOW64\CTHELPER.EXE
(Creative Technology Ltd) C:\Windows\SysWOW64\CTxfispi.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
() E:\programme\RocketDock\RocketDock.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
() C:\Program Files (x86)\Opera\28.0.1750.51\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
HKLM\...\Run: [AsioThk32Reg] => %SYSTEMROOT%\SYSWOW64\REGSVR32.EXE /S %SYSTEMROOT%\SYSWOW64\CTASIO.DLL
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7543000 2014-03-04] (Realtek Semiconductor)
HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-02-21] (Intel Corporation)
HKLM-x32\...\Run: [CTXFIREG] => CTXFIREG.exe /FAIL1
HKLM-x32\...\Run: [CTHelper] => CTHELPER.EXE
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => E:\programme\itunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation)
HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1047536 2014-04-08] (MSI)
HKLM-x32\...\Run: [CTxfiHlp] => CTXFIHLP.EXE
HKLM-x32\...\Run: [PDFPrint] => E:\programme\PDF24\pdf24.exe [191528 2014-07-04] (Geek Software GmbH)
HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\...\Run: [RocketDock] => E:\programme\RocketDock\RocketDock.exe [495616 2007-09-02] ()
HKU\S-1-5-18\...\Run: [CtxfiReg] => CTXFIREG.exe /FAIL1
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3027806424-3257667986-1273845368-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3027806424-3257667986-1273845368-1001 -> {24617E59-8D7F-49D9-9600-DBE8CC8BB143} URL =
SearchScopes: HKU\S-1-5-21-3027806424-3257667986-1273845368-1001 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> D:\Programme\VLC\npvlc.dll No File
FF Plugin: @videolan.org/vlc,version=2.1.3 -> E:\programme\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> E:\programme\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> E:\programme\itunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> E:\programme\DivX\DivX OVS Helper\npovshelper.dll No File
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> E:\programme\DivX\DivX Web Player\npdivx32.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.3.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll [2014-05-26] (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-02-19] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-02-19] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-05] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-17]
CHR Extension: (Google Drive) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-17]
CHR Extension: (YouTube) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-17]
CHR Extension: (Google Search) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-17]
CHR Extension: (Gmail) - C:\Users\Dominic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-17]
Opera:
=======
OPR Extension: (AdBlock) - C:\Users\Dominic\AppData\Roaming\Opera Software\Opera Stable\Extensions\aobdicepooefnbaeokijohmhjlleamfj [2014-04-15]
OPR Extension: (Adblock Plus) - C:\Users\Dominic\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2013-11-16]
StartMenuInternet: (HKLM) OperaStable - C:\Program Files (x86)\Opera\Launcher.exe hxxp://www.delta-homes.com/?type=sc&ts=1429106301&from=ient04150&uid=ST3320820AS_9QF2B8K2XXXX9QF2B8K2
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-03-28] () [File not signed]
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-01-23] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2013-12-03] (Creative Labs) [File not signed]
S2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed]
S2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [315392 2009-06-05] (DeviceVM, Inc.) [File not signed]
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [614624 2014-11-25] (Futuremark)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-02-21] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-02-19] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [162800 2014-03-17] (MSI)
S2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833544 2015-01-16] (NVIDIA Corporation)
S3 Origin Client Service; E:\programme\Origin\OriginClientService.exe [1900400 2014-12-08] (Electronic Arts)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-21] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 nlsvc; "D:\Programme\Netlimiter 3\nlsvc.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [14392 2007-12-17] ()
R3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2014-01-29] (AVM Berlin)
S3 COMMONFX.DLL; C:\Windows\System32\COMMONFX.DLL [151552 2006-05-24] (Creative Technology Ltd) [File not signed]
S3 CTAUDFX.DLL; C:\Windows\System32\CTAUDFX.DLL [695808 2006-05-24] (Creative Technology Ltd) [File not signed]
S3 CTEAPSFX.DLL; C:\Windows\System32\CTEAPSFX.DLL [212992 2006-05-24] (Creative Technology Ltd) [File not signed]
S3 CTEDSPFX.DLL; C:\Windows\System32\CTEDSPFX.DLL [316928 2006-05-24] (Creative Technology Ltd) [File not signed]
S3 CTEDSPIO.DLL; C:\Windows\System32\CTEDSPIO.DLL [168960 2006-05-24] (Creative Technology Ltd) [File not signed]
S3 CTEDSPSY.DLL; C:\Windows\System32\CTEDSPSY.DLL [356864 2006-05-24] (Creative Technology Ltd) [File not signed]
S3 CTSBLFX.DLL; C:\Windows\System32\CTSBLFX.DLL [676864 2006-05-24] (Creative Technology Ltd) [File not signed]
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [22216 2014-02-03] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [22728 2014-02-03] ()
R3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [23936 2014-02-03] ()
S3 ipadtst; C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [20464 2013-11-11] (Windows (R) Win 7 DDK provider)
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD.sys [44744 2014-02-03] ()
S3 L1E; C:\Windows\System32\DRIVERS\L1E60x64.sys [63016 2010-03-29] (Atheros Communications, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [116736 2014-02-19] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-05-14] ()
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 ALSysIO; \??\C:\Users\Dominic\AppData\Local\Temp\ALSysIO64.sys [X]
S2 ASInsHelp; \??\C:\Windows\SysWow64\drivers\AsInsHelp64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\Windows\TEMP\cpuz138\cpuz138_x64.sys [X]
S3 CT20XUT.DLL; \SystemRoot\System32\CT20XUT.DLL [X]
S3 CTEXFIFX.DLL; \SystemRoot\System32\CTEXFIFX.DLL [X]
S3 CTHWIUT.DLL; \SystemRoot\System32\CTHWIUT.DLL [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 MSICDSetup; \??\F:\CDriver64.sys [X]
S1 nltdi; \??\D:\Programme\Netlimiter 3\nltdi.sys [X]
S3 NTIOLib_1_0_C; \??\F:\NTIOLib_X64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-22 20:29 - 2015-04-22 20:29 - 00001247 _____ () C:\Users\Dominic\Desktop\JRT.txt
2015-04-22 20:28 - 2015-04-22 20:28 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DOMINIC-PC-Windows-7-Professional-(64-bit).dat
2015-04-22 20:28 - 2015-04-22 20:28 - 00000000 ____D () C:\RegBackup
2015-04-22 20:21 - 2015-04-22 20:21 - 00005598 _____ () C:\Users\Dominic\Desktop\AdwCleaner[S1].txt
2015-04-22 20:19 - 2015-04-22 20:30 - 00000000 ____D () C:\AdwCleaner
2015-04-22 20:17 - 2015-04-22 20:17 - 00028008 _____ () C:\Users\Dominic\Desktop\mbam.txt
2015-04-22 19:54 - 2015-04-22 20:15 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-22 19:54 - 2015-04-22 19:54 - 00001112 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-22 19:54 - 2015-04-22 19:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-22 19:54 - 2015-04-22 19:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-22 19:54 - 2015-04-22 19:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-22 19:54 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-22 19:54 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-22 19:54 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-22 10:43 - 2015-04-22 10:43 - 00022025 _____ () C:\ComboFix.txt
2015-04-22 10:37 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-22 10:37 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-22 10:37 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-22 10:37 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-22 10:37 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-22 10:37 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-22 10:37 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-22 10:37 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-22 10:32 - 2015-04-22 10:43 - 00000000 ____D () C:\Qoobox
2015-04-22 10:31 - 2015-04-22 10:42 - 00000000 ____D () C:\Windows\erdnt
2015-04-21 18:26 - 2015-04-22 20:31 - 00000000 ____D () C:\FRST
2015-04-21 18:01 - 2015-04-21 18:01 - 00050477 _____ () C:\Users\Dominic\Downloads\Defogger.exe
2015-04-20 22:32 - 2015-04-20 22:32 - 00077468 _____ () C:\Users\Dominic\Downloads\EDDK.htm
2015-04-20 19:56 - 2015-04-20 19:56 - 00000000 ____D () C:\Users\Dominic\Tracing
2015-04-20 19:55 - 2015-04-21 17:18 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Skype
2015-04-20 19:55 - 2015-04-20 19:55 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-04-20 19:55 - 2015-04-20 19:55 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Skype
2015-04-20 19:55 - 2015-04-20 19:55 - 00000000 ____D () C:\ProgramData\Skype
2015-04-20 19:55 - 2015-04-20 19:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-20 19:54 - 2015-04-20 19:54 - 01380960 _____ (Skype Technologies S.A.) C:\Users\Dominic\Downloads\SkypeSetup.exe
2015-04-18 22:36 - 2015-04-18 22:36 - 00000095 _____ () C:\Users\Dominic\Downloads\lszh_radar.pls
2015-04-16 21:39 - 2015-04-16 21:39 - 00000363 _____ () C:\Users\Dominic\Downloads\viewer.htm
2015-04-15 22:04 - 2015-04-15 22:04 - 00114313 _____ () C:\Users\Dominic\Downloads\Download (2).htm
2015-04-08 22:06 - 2015-04-08 22:06 - 00119753 _____ () C:\Users\Dominic\Downloads\Download (1).htm
2015-04-07 18:58 - 2015-04-07 18:59 - 12439102 _____ () C:\Users\Dominic\Downloads\ES_config_files (1).zip
2015-04-03 14:17 - 2015-04-03 14:17 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\.mono
2015-04-03 14:17 - 2015-04-03 14:17 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Colossal Order
2015-04-03 14:17 - 2015-04-03 14:17 - 00000000 ____D () C:\ProgramData\.mono
2015-04-02 09:46 - 2015-04-02 09:46 - 00000000 ____D () C:\Users\Dominic\Documents\VoxKey
2015-04-02 09:46 - 2015-04-02 09:46 - 00000000 ____D () C:\Users\Dominic\Documents\Multi Crew Experience
2015-04-02 09:46 - 2015-04-02 09:46 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Obsidium
2015-04-02 09:46 - 2015-04-02 09:46 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Multi Crew Experience
2015-04-02 09:25 - 2015-04-02 09:38 - 578166395 _____ () C:\Users\Dominic\Downloads\mce.zip
2015-04-01 21:47 - 2015-04-01 21:47 - 17259715 _____ () C:\Users\Dominic\Downloads\PMDG_737NGXF_ Fedex.zip
2015-03-30 21:53 - 2015-03-30 21:53 - 00114307 _____ () C:\Users\Dominic\Downloads\Download.htm
2015-03-28 12:17 - 2015-03-28 12:17 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\InstallShield
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-22 20:29 - 2013-11-16 11:33 - 01968934 _____ () C:\Windows\WindowsUpdate.log
2015-04-22 20:29 - 2009-07-14 06:45 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-22 20:29 - 2009-07-14 06:45 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-22 20:25 - 2015-03-09 23:07 - 00006462 _____ () C:\Windows\SysWOW64\Gms.log
2015-04-22 20:23 - 2014-01-22 23:44 - 00135714 _____ () C:\Windows\setupact.log
2015-04-22 20:22 - 2013-11-16 12:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-22 20:22 - 2010-11-21 05:47 - 00211070 _____ () C:\Windows\PFRO.log
2015-04-22 20:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-22 20:21 - 2013-11-16 11:39 - 00001005 _____ () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-22 20:21 - 2013-11-16 11:38 - 00000000 ____D () C:\Users\Dominic
2015-04-22 20:12 - 2013-11-16 18:10 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\TS3Client
2015-04-22 20:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2015-04-22 19:59 - 2014-01-23 02:59 - 00000012 ____H () C:\dvmexp.idx
2015-04-22 19:51 - 2014-01-29 18:51 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Deployment
2015-04-22 17:38 - 2013-11-16 17:03 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-22 10:46 - 2014-01-29 18:51 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Apps\2.0
2015-04-22 10:43 - 2014-01-17 02:35 - 00000000 ____D () C:\Users\cfg
2015-04-22 10:42 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-04-22 10:19 - 2014-01-29 18:52 - 03307460 _____ () C:\Windows\avmacc.log
2015-04-21 19:43 - 2014-12-10 17:41 - 00000000 ____D () C:\Users\Dominic\Documents\EuroScope
2015-04-18 22:37 - 2013-11-17 14:04 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\vlc
2015-04-15 17:38 - 2013-11-16 17:03 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-15 17:38 - 2013-11-16 17:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-15 17:38 - 2013-11-16 17:03 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-12 20:35 - 2014-12-10 13:05 - 00000000 ____D () C:\Users\Dominic\Documents\Flight Simulator X-Dateien
2015-04-08 20:30 - 2014-06-03 21:03 - 00003856 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1384598566
2015-04-08 20:30 - 2013-11-16 12:42 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-06 22:15 - 2014-12-10 18:47 - 00000000 ____D () C:\REX Essential Plus Overdrive
2015-04-06 20:05 - 2013-11-16 17:33 - 00000000 ____D () C:\Users\Dominic\AppData\Local\Spotify
2015-04-06 20:03 - 2011-04-12 09:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2015-04-06 20:03 - 2011-04-12 09:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2015-04-06 20:03 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-06 20:02 - 2013-11-16 17:32 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Spotify
2015-04-03 12:47 - 2015-03-18 14:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aerosoft
2015-04-03 12:47 - 2013-11-16 12:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-04-02 19:46 - 2013-11-16 17:33 - 00001811 _____ () C:\Users\Dominic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-02 09:46 - 2009-07-14 04:34 - 00000564 _____ () C:\Windows\win.ini
2015-03-29 21:36 - 2014-06-04 14:48 - 00000000 ____D () C:\Users\Dominic\AppData\Roaming\Apple Computer
2015-03-29 21:32 - 2014-01-23 03:17 - 00321784 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-28 13:35 - 2014-01-23 03:18 - 00073872 _____ () C:\Users\Dominic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-28 12:19 - 2015-03-04 21:13 - 00000000 ____D () C:\Users\Dominic\Documents\Flight Simulator X Files
2015-03-28 12:19 - 2015-03-04 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations
==================== Files in the root of some directories =======
2014-03-28 13:25 - 2014-03-28 13:27 - 0000093 _____ () C:\Users\Dominic\AppData\Roaming\Camdata.ini
2014-03-28 13:25 - 2014-03-28 13:27 - 0000408 _____ () C:\Users\Dominic\AppData\Roaming\CamLayout.ini
2014-03-28 13:25 - 2014-03-28 13:27 - 0000408 _____ () C:\Users\Dominic\AppData\Roaming\CamShapes.ini
2014-03-28 13:25 - 2014-03-28 13:27 - 0004544 _____ () C:\Users\Dominic\AppData\Roaming\CamStudio.cfg
2014-10-21 16:31 - 2014-10-21 16:31 - 0000201 _____ () C:\Users\Dominic\AppData\Roaming\SpotifyRecorderSettings.ini
2014-03-28 13:22 - 2014-03-28 13:25 - 0000096 _____ () C:\Users\Dominic\AppData\Roaming\version2.xml
2014-03-28 14:17 - 2014-03-31 16:17 - 0000084 _____ () C:\Users\Dominic\AppData\Roaming\WB.CFG
2014-10-21 18:30 - 2014-10-21 18:30 - 0001429 _____ () C:\Users\Dominic\AppData\Local\RecConfig.xml
2015-03-09 22:57 - 2015-03-09 22:57 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\Dominic\AppData\Local\Temp\Quarantine.exe
C:\Users\Dominic\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-19 21:49
==================== End Of Log ============================ --- --- --- |