Addition
[CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:06-06-2015
Ran by Arne at 2015-06-09 21:49:24
Running from C:\Users\Arne\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-637948523-2288157690-423939406-500 - Administrator - Disabled)
Arne (S-1-5-21-637948523-2288157690-423939406-1000 - Administrator - Enabled) => C:\Users\Arne
Gast (S-1-5-21-637948523-2288157690-423939406-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-637948523-2288157690-423939406-1002 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
1C Company\Space Rangers 2 (HKLM-x32\...\Space Rangers 2) (Version: - 1C Company)
AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
Apple Application Support (32-Bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Assassin's Creed Rogue (HKLM-x32\...\Uplay Install 895) (Version: - Ubisoft)
ATI Catalyst Install Manager (HKLM\...\{DC9C8BC1-72CE-B5FE-EA4F-6D9127E51746}) (Version: 3.0.736.0 - ATI Technologies, Inc.)
Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
Avira (HKLM-x32\...\{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}) (Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward)
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
DMG Extractor (HKU\S-1-5-21-637948523-2288157690-423939406-1000\...\DMG Extractor) (Version: 1.3.15.0 - Reincubate Ltd)
DMG Extractor (HKU\S-1-5-21-637948523-2288157690-423939406-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\DMG Extractor) (Version: 1.3.15.0 - Reincubate Ltd)
Evolve (HKLM-x32\...\Steam App 273350) (Version: - Turtle Rock Studios)
Far Cry 4 (HKLM-x32\...\Uplay Install 420) (Version: - Ubisoft)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version: - Blizzard Entertainment)
iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Rise Of Nations (HKLM-x32\...\RiseOfNations 1.0) (Version: - Microsoft)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Middle-earth: Shadow of Mordor (HKLM-x32\...\Steam App 241930) (Version: - Monolith Productions, Inc.)
Mozilla Firefox 38.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 de)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0 - Mozilla)
Nosgoth (HKLM-x32\...\Steam App 200110) (Version: 150311.103813 - Square Enix Ltd)
NVIDIA 3D Vision Controller-Treiber 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.06 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.5.28 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.28 - NVIDIA Corporation)
NVIDIA Grafiktreiber 353.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.06 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.5.5.2850 - Electronic Arts, Inc.)
PDF Architect 3 (HKLM-x32\...\PDF Architect 3) (Version: 3.0.45.22485 - pdfforge GmbH)
PDF Architect 3 Create Module (x32 Version: 3.0.13.22993 - pdfforge GmbH) Hidden
PDF Architect 3 Edit Module (x32 Version: 3.0.13.22993 - pdfforge GmbH) Hidden
PDF Architect 3 View Module (x32 Version: 3.0.13.22993 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.1.1 - pdfforge)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek Ethernet Diagnostic Utility (HKLM-x32\...\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 1.006 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.5.28 - NVIDIA Corporation) Hidden
Skype™ 7.2 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
STEUEReasy 2015 (HKLM-x32\...\{8D59E108-081D-4F4F-84EF-0132479C25C6}) (Version: 20.34.161 - Akademische Arbeitsgemeinschaft)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
The Witcher 3 Wild Hunt Version 1.02 (HKLM-x32\...\The Witcher 3 Wild Hunt_is1) (Version: 1.02 - RFT)
Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts)
Uplay (HKLM-x32\...\Uplay) (Version: 5.0 - Ubisoft)
Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft)
WAV To MP3 V2 (HKLM-x32\...\WAV To MP3_is1) (Version: - hxxp://www.WAVMP3.net)
WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 1.0.0.0 - 1&1 Mail & Media GmbH)
WinISO (HKLM-x32\...\WinISO) (Version: 6.4.0.5170 - WinISO Computing Inc.)
WinRAR 5.21 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
X3: Albion Prelude (HKLM-x32\...\Steam App 201310) (Version: - Egosoft)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {154DCFB3-1D83-49EA-93CE-E84AC8470531} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-14] (Adobe Systems Incorporated)
Task: {277BB1C8-B8E3-473E-8F41-CC7793D29DF3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {6A3A913C-C7ED-46FA-886E-0816071B7DD7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {711DAD5C-25EF-4731-A6F6-5515A22297E7} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {91BC2880-0B81-4BA8-8EAD-9B4F3FB78BBF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)
Task: {9362C7D4-194F-43D4-887B-594F807A3485} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {A2055D9F-1392-4C7D-AA74-9C18FE427E77} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation)
Task: {A885AC7B-68BB-41AE-9A3D-DB63F2A0DA06} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {C5899D73-B87B-4B46-A6CA-B3DBA1A78705} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {ED63DE54-3918-4EE4-88BA-F9BE9FFBC344} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {FDB00FEA-04A6-40D9-A95A-3E02D89C35F8} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (Whitelisted) ==============
2015-02-25 16:08 - 2015-05-28 06:15 - 00116368 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-06-07 13:22 - 2015-06-07 13:22 - 00164352 _____ () C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\nso1D0D.tmpfs
2015-06-07 13:22 - 2015-06-07 13:22 - 00219136 _____ () C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\jnsd477C.tmp
2015-06-07 13:22 - 2015-06-07 13:22 - 00166912 _____ () C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\hnso5C27.tmp
2015-04-08 21:53 - 2015-04-08 21:53 - 00057344 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2015-03-31 17:07 - 2015-05-23 03:48 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-637948523-2288157690-423939406-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-637948523-2288157690-423939406-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 192.168.0.2
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AAV UpdateService => 2
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: Origin Client Service => 3
MSCONFIG\Services: PDF Architect 3 => 3
MSCONFIG\Services: PDF Architect 3 CrashHandler => 3
MSCONFIG\Services: PDF Architect 3 Creator => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: iTunesHelper => "F:\Itunes\iTunesHelper.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{9964BB04-747E-4E18-A98E-91CE24A649DB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{466C8F6F-5E28-4F6B-967F-FA2A50760DB0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C98C61D7-CF10-433A-B3D7-682D34521AD9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A8C97390-D60C-4AFD-ACAF-983DF4B25B55}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{5E6BACDE-B9C4-4365-BB0A-3ED6D5AA8BA4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{19ABCC53-55AE-4EC1-8C38-AFDEDEF1DEA5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{34108B78-20E7-4B22-BA5F-1AF7374CDAC8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{1CFD76CA-5938-47B5-ADDD-ECB393DEB328}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F9EC933E-D6E4-4922-8F00-764637D04801}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{E0E7BC88-D193-441C-B414-17FBBF85EF3E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{B823E04B-1822-4BBC-BCCB-B47EEA1A7F9C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{DBBD88BC-1FA7-40E5-ACD4-8A47E1B7D097}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{8E7A3C47-CF3B-46FA-994A-70504908A09D}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{E484A457-757E-4BB2-8EA4-D59EB0220B6B}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{AF6FB18B-DA23-480A-B909-26AD9B52D351}] => (Allow) F:\Programme\Hearthstone\Hearthstone.exe
FirewallRules: [{75AE00D5-B79E-4B42-A4F1-3F99B53C95B5}] => (Allow) F:\Programme\Hearthstone\Hearthstone.exe
FirewallRules: [{7A84CC45-274C-49C8-B4F9-632B1FF3D7DF}] => (Allow) G:\Games\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{58CE1539-B51C-415C-B7C4-0795208544A1}] => (Allow) G:\Games\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{668A09F6-F41B-4525-9E83-56DFE18E12CB}] => (Allow) G:\Games\Origin\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{C260EEE9-1F41-482C-879F-23E723DEE1F8}] => (Allow) G:\Games\Origin\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{D02B85E5-B180-49EE-83B6-8F3FC2D730AD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{A3711709-406D-4236-A8C5-A3B91E606125}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{60EDD157-1D9D-4F32-8771-7C706E87333A}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{FB79F2A4-EBF4-4991-8F4B-6D3454ECCF4F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6BA35682-EA84-4C31-A66F-0A9E974F0195}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{36BAD1E3-7D9F-415F-BA05-B75FBCDCC30C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{06988772-59B7-4893-87F4-F9602E58B614}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{1D43EB11-DE72-463B-84D3-B0BED2A022FA}] => (Allow) F:\Programme\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{D9805C53-9522-4DED-8365-E6B2FC2F9396}] => (Allow) F:\Programme\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{840BD7B8-C0D1-44D6-BBA3-B20AE6D36AE2}] => (Allow) F:\Programme\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{EF0F8DD5-1B46-42BC-AAE8-71DDCDB755BD}] => (Allow) F:\Programme\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{EAEDF3A2-38F8-4154-9D31-304ECFF807FA}] => (Allow) G:\Games\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{3A5E105E-7247-4182-8D9D-D2C85DD024DA}] => (Allow) G:\Games\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{2441B83D-98AC-4C15-AE0F-C0F67FC08D3F}] => (Allow) G:\Games\steamapps\common\x3 terran conflict\X3AP.exe
FirewallRules: [{80F9DF59-2445-407A-8F83-33CBDB8D046A}] => (Allow) G:\Games\steamapps\common\x3 terran conflict\X3AP.exe
FirewallRules: [{A6183E08-D759-407A-B2C0-4C6C44CBD924}] => (Allow) C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe
FirewallRules: [{49A904DB-3D6E-4D48-BEAA-751792047E8B}] => (Allow) C:\Program Files (x86)\Origin Games\Titanfall\Titanfall.exe
FirewallRules: [{0093FE1B-7A26-47F4-9E48-63E025DE46FB}] => (Allow) G:\Games\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{BF93BB5A-FED4-4981-BFE0-8892C3AA9C2A}] => (Allow) G:\Games\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{A8E4C0CD-56B0-4136-B58A-295C584F02AC}] => (Allow) F:\Itunes\iTunes.exe
FirewallRules: [{D3792688-8FB8-4358-83C7-502937B01543}] => (Allow) G:\Games\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
FirewallRules: [{A384ADFA-3BC3-474F-8544-886EE970EFF8}] => (Allow) G:\Games\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
FirewallRules: [{72A80647-61AE-4356-9D1C-D1AE7747ACAA}] => (Allow) G:\Games\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{8063A8B1-1D7E-4F7D-BE55-96B9EE31090F}] => (Allow) G:\Games\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
FirewallRules: [{A8725D09-4DE1-43DB-8782-05D5F3E55C85}] => (Allow) G:\Games\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{B639CF3C-257D-469B-A373-9814E2B8D78C}] => (Allow) G:\Games\steamapps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{BA9FFB04-83AB-4DB8-A5C4-86C49D92A39D}] => (Allow) G:\Games\steamapps\common\EvolveGame\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{90A7CBA2-3902-4B95-A84B-6CE9D2D69E3F}] => (Allow) G:\Games\steamapps\common\EvolveGame\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{A980EC48-2C59-495E-84C9-FAFB12CF9AF1}] => (Allow) F:\Programme\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{40BA17BD-D745-4267-A53A-B5829EF1BEF6}] => (Allow) F:\Programme\Far Cry 4\bin\FarCry4.exe
FirewallRules: [{EE2E173C-C247-472C-8CC7-E441D644354F}] => (Allow) F:\Programme\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{3BC98646-FF63-4411-8B22-C5C5746F0E0A}] => (Allow) F:\Programme\Far Cry 4\bin\IGE_WPF64.exe
FirewallRules: [{E293027F-1F25-4040-A274-D55BA3BCB99E}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{700F7114-BFE1-4E2E-8E85-022FD6FFA6A5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{CD79A842-3D18-4211-AD18-1ABA13D4C1D8}] => (Allow) F:\Programme\Assassin's Creed Rogue\ACC.exe
FirewallRules: [{D24A5907-6A5C-4BAF-B915-E830C731794A}] => (Allow) F:\Programme\Assassin's Creed Rogue\ACC.exe
FirewallRules: [TCP Query User{E9BB9C2F-A011-4BD9-A63E-144F231F8344}F:\programme\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe] => (Allow) F:\programme\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{DE422D53-8FFF-459E-91A3-A24CD05EF82F}F:\programme\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe] => (Allow) F:\programme\heroes of the storm\versions\base35702\heroesofthestorm_x64.exe
==================== Faulty Device Manager Devices =============
Name: USB (Universal Serial Bus)-Controller
Description: USB (Universal Serial Bus)-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/09/2015 09:48:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/09/2015 09:15:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/08/2015 08:02:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Der Index kann nicht initialisiert werden.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Die Anwendung kann nicht initialisiert werden.
Kontext: Windows Anwendung
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden.
Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
System errors:
=============
Error: (06/09/2015 09:49:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (06/09/2015 09:46:58 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Template Flatbed Scanner" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (06/09/2015 09:16:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (06/09/2015 09:13:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Template Flatbed Scanner" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (06/08/2015 08:03:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (06/08/2015 08:01:03 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/08/2015 08:01:03 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535.
Error: (06/08/2015 08:00:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Template Flatbed Scanner" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (06/07/2015 06:34:14 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Error: (06/07/2015 06:34:03 PM) (Source: cdrom) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\CdRom0.
Microsoft Office:
=========================
Error: (06/09/2015 09:48:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/09/2015 09:15:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/08/2015 08:02:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description:
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Kontext: Windows Anwendung
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490)
Search.TripoliIndexer
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
Search.JetPropStore
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Kontext: Windows Anwendung, SystemIndex Katalog
Details:
Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800)
Error: (06/08/2015 08:01:03 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description:
Details:
Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801)
The catalog is corrupt
==================== Memory info ===========================
Processor: AMD FX(tm)-8350 Eight-Core Processor
Percentage of memory in use: 26%
Total physical RAM: 8173.53 MB
Available physical RAM: 6014.99 MB
Total Pagefile: 16345.26 MB
Available Pagefile: 13938.33 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.69 GB) (Free:6.08 GB) NTFS
Drive d: (WLP2) (CDROM) (Total:7.62 GB) (Free:0 GB) UDF
Drive f: () (Fixed) (Total:688.95 GB) (Free:438.25 GB) NTFS
Drive g: () (Fixed) (Total:689.21 GB) (Free:585.05 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 6C8FF413)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1397.3 GB) (Disk ID: D1FCA753)
Partition 1: (Not Active) - (Size=19 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=689 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=689.2 GB) - (Type=07 NTFS)
==================== End of log ============================ --- --- ---
ADWCleaner Code:
# AdwCleaner v4.206 - Bericht erstellt 09/06/2015 um 21:57:29
# Aktualisiert 01/06/2015 von Xplode
# Datenbank : 2015-06-09.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : Arne - ARNE-PC
# Gestarted von : C:\Users\Arne\Downloads\AdwCleaner_4.206.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gefunden : C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\AnyProtect
Schlüssel Gefunden : HKCU\Software\HomeTab
Schlüssel Gefunden : HKCU\Software\Linkey
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Schlüssel Gefunden : HKCU\Software\Mozilla\Extends
Schlüssel Gefunden : HKCU\Software\SearchProtectWS
Schlüssel Gefunden : HKCU\Software\simplytech
Schlüssel Gefunden : HKCU\Software\Simplytech\HomeTab
Schlüssel Gefunden : HKCU\Software\TNT2
Schlüssel Gefunden : HKCU\Software\WajIEnhance
Schlüssel Gefunden : HKCU\Software\WajIntEnhance
Schlüssel Gefunden : [x64] HKCU\Software\AnyProtect
Schlüssel Gefunden : [x64] HKCU\Software\HomeTab
Schlüssel Gefunden : [x64] HKCU\Software\Linkey
Schlüssel Gefunden : [x64] HKCU\Software\SearchProtectWS
Schlüssel Gefunden : [x64] HKCU\Software\simplytech
Schlüssel Gefunden : [x64] HKCU\Software\Simplytech\HomeTab
Schlüssel Gefunden : [x64] HKCU\Software\TNT2
Schlüssel Gefunden : [x64] HKCU\Software\WajIEnhance
Schlüssel Gefunden : [x64] HKCU\Software\WajIntEnhance
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Schlüssel Gefunden : HKLM\SOFTWARE\searchult
Schlüssel Gefunden : HKLM\SOFTWARE\SpeedBit
Schlüssel Gefunden : HKLM\SOFTWARE\WajIntEnhance
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}
Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}
Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P
-\\ Mozilla Firefox v38.0.5 (x86 de)
-\\ Google Chrome v43.0.2357.81
[C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Gefunden [Homepage] : hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P
[C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Gefunden [Startup_URLs] : hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P
-\\ Opera v0.0.0.0
*************************
AdwCleaner[R0].txt - [12917 Bytes] - [07/06/2015 13:31:43]
AdwCleaner[R1].txt - [12748 Bytes] - [07/06/2015 13:35:58]
AdwCleaner[R2].txt - [4429 Bytes] - [09/06/2015 21:57:29]
AdwCleaner[S0].txt - [9660 Bytes] - [07/06/2015 13:36:39]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [4547 Bytes] ########## MalewareBytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 09.06.2015
Suchlauf-Zeit: 21:51:38
Logdatei:
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.09.05
Rootkit Datenbank: v2015.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Arne
Suchlauf-Art: Benutzerdefinierter Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 495562
Verstrichene Zeit: 47 Min, 9 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
Trojan.Agent, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\jnsd477C.tmp, 2104, Löschen bei Neustart, [2e7b58604347e5516186b1b911f1f30d]
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\nso1D0D.tmpfs, 240, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030]
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\hnso5C27.tmp, 2136, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030]
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\jnsd477C.tmp, 2104, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 23
Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xoperoze, In Quarantäne, [2e7b58604347e5516186b1b911f1f30d],
PUP.Optional.MultiPlug.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\quburuzi, In Quarantäne, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.MultiPlug.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\zedepory, In Quarantäne, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.MultiPlug.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xoperoze, In Quarantäne, [07a23c7cf298bb7b4403a4da52b3d030],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [a2073286b4d60036a51cf39354b1ef11],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WajIntEnhance, In Quarantäne, [f1b8c2f6bcce53e39d46c137cf34b749],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [aafff8c03c4e85b178493e4834d159a7],
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\KYSYKITI, In Quarantäne, [f6b35a5efb8fac8ae8e653292cd9d52b],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\HomeTab, In Quarantäne, [4d5c5b5d1f6bcf6709f7f8290afa13ed],
PUP.Optional.ProPCCleaner.C, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\Pro PC Cleaner, In Quarantäne, [a20791273555f73ffb29c6c25aab966a],
PUP.Optional.ProPCCleaner.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\ProPCCleanerLanguage, In Quarantäne, [e4c5caee6228c571a148ef93c83d24dc],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\SearchProtectWS, In Quarantäne, [8029199f167474c2e61d5b9bcd36a45c],
PUP.Optional.TNT.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\TNT2, In Quarantäne, [9613685047431224674ab83fa26112ee],
PUP.Optional.Wajam.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\WajIEnhance, In Quarantäne, [416802b645450d295d62c43970938e72],
PUP.Optional.Wajam.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\WajIntEnhance, In Quarantäne, [24853a7e6a201d1916ced3255ba89769],
PUP.Optional.Iminent.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IMBoosterARP, In Quarantäne, [664340789ceef640bbdedc168281f20e],
PUP.Optional.Iminent.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IminentToolbar, In Quarantäne, [5554bbfda7e358de05952dc53fc408f8],
PUP.Optional.Linkey.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Linkey, In Quarantäne, [4168388024668babacef52a0ef149a66],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, In Quarantäne, [852423955d2d0c2a56bb1968bf4637c9],
PUP.Optional.Vosteran.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Vosteran.com, In Quarantäne, [e8c1a414deacec4af3a9b33f2cd76a96],
PUP.Optional.Wajam.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WajIntEnhance, In Quarantäne, [f8b12f89dfabf54186176092e023e31d],
PUP.Optional.FastSearch.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [82270aae2c5e1a1cde0d2cbe5fa41ce4],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\SIMPLYTECH\HomeTab, In Quarantäne, [1c8d6d4bec9ef343cf5993a325df3ac6],
Registrierungswerte: 7
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [a2073286b4d60036a51cf39354b1ef11]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [aafff8c03c4e85b178493e4834d159a7]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\kysykiti|ImagePath, C:\Users\Arne\AppData\Local\41414346-1433683500-3138-3935-4236FFFFFFFF\snsfBE25.tmp, In Quarantäne, [f6b35a5efb8fac8ae8e653292cd9d52b]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\quburuzi|ImagePath, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\nso1D0D.tmpfs, In Quarantäne, [3871b800f3977fb7913cc8b418edee12]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xoperoze|ImagePath, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\jnsd477C.tmp, In Quarantäne, [6346e7d17d0d2016e4ea770534d18e72]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\zedepory|ImagePath, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\hnso5C27.tmp, In Quarantäne, [d5d4f0c8fb8f7db97d518bf1729354ac]
PUP.Optional.FastSearch.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MOZILLA\EXTENDS|appid, searchffv2@gmail.com, In Quarantäne, [82270aae2c5e1a1cde0d2cbe5fa41ce4]
Registrierungsdaten: 5
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P),Ersetzt,[b0f920984842bc7ae0a4a68954b212ee]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P),Ersetzt,[6c3dfbbdd9b165d12b59959ac0463bc5]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}),Ersetzt,[941597212c5e56e0a8dcb27db650c838]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}),Ersetzt,[d2d7c1f78dfd61d5c6bedd529f67e719]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-637948523-2288157690-423939406-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=ds&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P&q={searchTerms}),Ersetzt,[beeb03b5b1d96cca11711916ce38b14f]
Ordner: 2
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.ProPCCleaner.A, C:\Windows\Installer\{C3060724-6AC7-4BEF-B516-4F6B1D90887D}, In Quarantäne, [1990fcbcb8d2da5c6dcaceb79372a45c],
Dateien: 25
Trojan.Agent, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\jnsd477C.tmp, Löschen bei Neustart, [2e7b58604347e5516186b1b911f1f30d],
PUP.Optional.IStartSurf.A, C:\Users\Arne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7M337JG1\face_istartsurf[1].exe, In Quarantäne, [e1c8d8e0d4b6122479986e08cd39b34d],
PUP.Optional.Infonaut.A, C:\Users\Arne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7M337JG1\infonaut-setup-1.10.0.14[1].exe, In Quarantäne, [1891ebcd7812033358fdadcaed1924dc],
PUP.Optional.AnyProtect, C:\Users\Arne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O285Y9ZM\AnyProtectSetup[1].exe, In Quarantäne, [9d0c9a1efb8fb97d2436b6aa986b1fe1],
PUP.Optional.CheckOffer, C:\Users\Arne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SIXHTGNQ\VuuPC_VO2_8907[1].exe, In Quarantäne, [c2e7dddb2664f24466fcacb7cb3726da],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nsnA338.tmp, In Quarantäne, [763342768406a88ec19b6c0b63a3bd43],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nss9737.tmp, In Quarantäne, [53560bad1377e2548ad21f5857af738d],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nsw17D.tmp, In Quarantäne, [17923385addd67cfb8a4caadc640f709],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nsxA7DA.tmp, In Quarantäne, [9b0e18a0503a54e2db81284f9175c33d],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nsb796A.tmp, In Quarantäne, [54556e4aa6e4c571015bbabd39cd1ee2],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nscF33B.tmp, In Quarantäne, [e2c76b4d9feb56e072eab8bf15f1ec14],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nsd3C4C.tmp, In Quarantäne, [1b8eb0080a8003332c304a2d6b9b29d7],
PUP.Optional.AnyProtect, C:\Users\Arne\AppData\Local\Temp\nsh8622.tmp, In Quarantäne, [703950687a1071c5bb9fe27e45be20e0],
PUP.Optional.Somoto.SID.A, C:\Users\Arne\AppData\Local\Temp\nsiFD49.tmp, In Quarantäne, [a0093e7a028844f2500c26514abc4cb4],
PUP.Optional.IStartSurf.A, C:\Users\Arne\AppData\Local\Temp\nsl60B9.tmp, In Quarantäne, [476211a75931ec4a7d94d0a620e60ff1],
PUP.Optional.Vitruvian.A, C:\Users\Arne\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, In Quarantäne, [2c7de1d793f7a88e02388dea25e012ee],
PUP.Optional.Vitruvian.A, C:\Users\Arne\AppData\Local\Temp\vitruvian-installer-install-v0003, In Quarantäne, [bdec10a8305a56e0a496c0b746bf0af6],
PUP.Optional.Vitruvian.A, C:\Users\Arne\AppData\Local\Temp\vitruvian-installer-processes-v0002, In Quarantäne, [6247bcfc93f7bb7be258185fda2bc040],
PUP.Optional.Vitruvian.A, C:\Users\Arne\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, In Quarantäne, [edbcdbdd0f7bd6609e9c0176877ea35d],
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\nso1D0D.tmpfs, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\hnso5C27.tmp, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\jnsd477C.tmp, Löschen bei Neustart, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\rnsj4576.exe, In Quarantäne, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.MultiPlug.Gen, C:\Users\Arne\AppData\Roaming\41414346-1433676126-3138-3935-4236FFFFFFFF\Uninstall.exe, In Quarantäne, [07a23c7cf298bb7b4403a4da52b3d030],
PUP.Optional.ProPCCleaner.A, C:\Windows\Installer\{C3060724-6AC7-4BEF-B516-4F6B1D90887D}\Pro_PC_Cleaner_Icon.exe, In Quarantäne, [1990fcbcb8d2da5c6dcaceb79372a45c],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) adwCleaner Code:
# AdwCleaner v4.206 - Bericht erstellt 09/06/2015 um 22:39:42
# Aktualisiert 01/06/2015 von Xplode
# Datenbank : 2015-06-09.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : Arne - ARNE-PC
# Gestarted von : C:\Users\Arne\Downloads\AdwCleaner_4.206.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\Linkey
Schlüssel Gelöscht : HKLM\SOFTWARE\SpeedBit
Schlüssel Gelöscht : HKLM\SOFTWARE\searchult
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v38.0.5 (x86 de)
-\\ Google Chrome v43.0.2357.81
[C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Gelöscht [Homepage] : hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P
[C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Gelöscht [Startup_URLs] : hxxp://www.istartsurf.com/?type=hp&ts=1433879084&z=ed8af75e0a3e12d5788841fg4z7c8c4b6m7tbe2mfb&from=face&uid=SamsungXSSDX840XEVOX120GB_S1D5NSAFA32675P
-\\ Opera v0.0.0.0
*************************
AdwCleaner[R0].txt - [12917 Bytes] - [07/06/2015 13:31:43]
AdwCleaner[R1].txt - [12748 Bytes] - [07/06/2015 13:35:58]
AdwCleaner[R2].txt - [4670 Bytes] - [09/06/2015 21:57:29]
AdwCleaner[R3].txt - [4729 Bytes] - [09/06/2015 21:59:18]
AdwCleaner[S0].txt - [9660 Bytes] - [07/06/2015 13:36:39]
AdwCleaner[S1].txt - [2443 Bytes] - [09/06/2015 22:39:42]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2502 Bytes] ########## |