Hallo Schrauber,
Eset hat so einiges gefunden
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 02:51:42
# local_time=2015-07-10 04:51:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24740
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 02:58:04
# local_time=2015-07-10 04:58:04 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# engine=24740
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-10 03:01:25
# local_time=2015-07-10 05:01:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777213 100 100 2819 68018507 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4225759 59524479 0 0
# scanned=5036
# found=2
# cleaned=0
# scan_time=200
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 03:03:49
# local_time=2015-07-10 05:03:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=53251
Update Finalize
Updated modules version: 24740
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 03:04:32
# local_time=2015-07-10 05:04:32 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# engine=24740
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-10 03:10:24
# local_time=2015-07-10 05:10:24 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777213 100 100 3358 68019046 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4226298 59525018 0 0
# scanned=17924
# found=2
# cleaned=0
# scan_time=351
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 09:10:15
# local_time=2015-07-10 11:10:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24743
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 09:10:43
# local_time=2015-07-10 11:10:43 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 10:25:31
# local_time=2015-07-11 12:25:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24746
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 10:25:58
# local_time=2015-07-11 12:25:58 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# engine=24746
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-10 11:57:32
# local_time=2015-07-11 01:57:32 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777213 100 100 5673 68050674 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4257926 59556646 0 0
# scanned=115552
# found=38
# cleaned=0
# scan_time=5493
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir"
sh=91738DC254FDC7041A3D934ED35F478BD7050C2A ft=1 fh=4f8f7046f2fcfbeb vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Desktop\TestDisk PhotoRec - CHIP-Installer.exe"
sh=80B86F2B7E604FC94778C110DD25641204D8209D ft=1 fh=88381e48320a06f7 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\mgHelperGCFB.dll"
sh=95ADC7925C2BB20FACE637E7031972F8E208FA33 ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx"
sh=4F1EC034FA273DF15EBEF1E3FA66F819DB8A1943 ft=1 fh=752909aa377c6468 vn="Variante von Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\AppData\Roaming\OpenCandy\OpenCandy_D883580E954D4BFBA1C169803F66DE1D\registrybooster(9).exe"
sh=D60F6EBE31E049C5236DBCE204F82B3CC16AE311 ft=1 fh=f1eedba83c490651 vn="Variante von Win32/SweetIM.N evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Desktop\Programme\bundlesweetimsetup.exe"
sh=5B499F87EE8B3BF2E981BBA51F4C2732EC32599C ft=1 fh=d086c7dc76977fbd vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Desktop\Programme\rcpsetup_softonic_sd.exe"
sh=457335C7D7CF3B76BDA5156BDFC9D2E55F5EB26E ft=1 fh=733834ea60493ef0 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Documents\Downloads\Integrated_CT2325506.exe"
sh=08E5233775142E9C220C190CAD3E27A549652193 ft=1 fh=1f207ee3eb72f580 vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\adusetup_ashampoo.exe"
sh=D5D8C00EA49AA0455C4507AB8FAA0B7CFF3C6FA4 ft=1 fh=ba487aeb357dec5c vn="Variante von Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\asc-setup(2).exe"
sh=38D920413DA6977CEC22A54F59C537D61FB5E3A7 ft=1 fh=1552aabc3c379211 vn="Win32/ELEX.AH evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\asc-setup.exe"
sh=5010BDDBEDDF9DF52905ECE13A54AD1831760CFC ft=1 fh=ae0f36ec463e8583 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\ashampoo_photo_commander_8_8.4.0_8416.exe"
sh=31048732171730E332CF83C59A1E9C8F87FE9D9B ft=1 fh=69d728c96126b483 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\ashampoo_photo_optimizer_4_4.0.3_12123.exe"
sh=A286C0831A97F92D5B02D4B93E86530036A8699D ft=1 fh=541a6d15877510a0 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\ashampoo_winoptimizer_6_6.60_7259.exe"
sh=DFDAF3E7ED920730B123DA30F0B1F79837B28ABE ft=1 fh=14851b481a89f9f9 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\FreeYouTubeDownload.exe"
sh=2898AC44F5B280E0A16E3ECEAED861EA6C1B122F ft=1 fh=90c5cb6befc06df7 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxx vom alten Pc\lxxxx\Downloads\FreeYouTubetoMP3Converter (1).exe"
sh=8547D1E5EACE099ECFE5EDBF6958FA077650894B ft=1 fh=61435738673b6524 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\FreeYouTubeToMP3Converter.exe"
sh=CA4465FED8127902C233876084962BE515219103 ft=1 fh=2aae4c570c2e1699 vn="Variante von Win32/ELEX.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\gusetup(1).exe"
sh=22DD19DAE5F13FC01E8768E0AF7A6916D4B56AD8 ft=1 fh=d64b1c57ab7859c7 vn="Variante von Win32/Vittalia.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\installer_abc_amber_text_converter_5_07_Deutsch.exe"
sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch (1).exe"
sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch (2).exe"
sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch.exe"
sh=6341D91DE330954BB8D497FCF8D7D50043B7F38C ft=1 fh=5fb1c7e382475525 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Magix-Foto-Designer-Setup.exe"
sh=6381C969CBF840D71B6DC7073563BE074C44BD94 ft=1 fh=4baa470ede468fd4 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Paint NET - CHIP-Downloader(1).exe"
sh=0BD5AB3AC384C83014B59DF19100D07B209C1DD8 ft=1 fh=57cb94fce1dea516 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Paint NET - CHIP-Downloader.exe"
sh=05C4561F9C8843B923104E8D275364898C53B357 ft=1 fh=77b670143b46f13b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\ranktracker643-jre-Downloader.exe"
sh=6BA3AD49D76DFB397D0FC14F0555A38353D2E662 ft=1 fh=0d40b11a59bb767f vn="Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\registryboosterplc.exe"
sh=F78E1730B2A61817987EB987CE9C7629B05F1F13 ft=1 fh=250619b73124c19c vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter (1).exe"
sh=6DF41BE2115F17EF773045825B7AD168C46FD71E ft=1 fh=250619b710cddeb8 vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter.exe"
sh=9C1B9244769611DFAA18E0ADE669C1BC275848F8 ft=1 fh=250619b75fad7c7c vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxxvom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter26.exe"
sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator(1).exe"
sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator(2).exe"
sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator.exe"
sh=BD5D8E1A532DC977499E96056023F9922A5213A1 ft=1 fh=ac2eabd5779085bf vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_koyote-free-video-converter.exe"
sh=CCD667FE196B0E1FAD991130AE214EF32169BE97 ft=1 fh=65ad072f5b9444d7 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\SoftonicDownloader_fuer_photoscape.exe"
sh=846D95D63EDE9508EFC7CEEE1D145D7CE62988C3 ft=1 fh=ec23a4ae3310ce50 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Software Downloads\FreeYouTubeToMP3Converter31132918 (1).exe"
sh=846D95D63EDE9508EFC7CEEE1D145D7CE62988C3 ft=1 fh=ec23a4ae3310ce50 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Software Downloads\FreeYouTubeToMP3Converter31132918.exe"
Security Check ist auch fertig
Results of screen317's Security Check version 1.004
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Kaspersky Internet Security
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 75
Java 8 Update 45
Adobe Flash Player 18.0.0.203
Mozilla Firefox (39.0)
Mozilla Thunderbird (31.7.0)
Google Chrome (43.0.2357.130)
Google Chrome (43.0.2357.132)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
StarMoney 9.0 ouservice StarMoneyOnlineUpdate.exe
Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe
Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
Ganz frisches FRST:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by lxxxxx (administrator) on Lxxxx-PC on 11-07-2015 02:21:04
Running from C:\Users\lxxxxx\Downloads
Loaded Profiles: lxxxx (Available Profiles: lxxxx & _supereasy_1cbackup_)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(phonostar GmbH) C:\Program Files (x86)\phonostar-Player\phonostar.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC
HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL
HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] ()
Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( )
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29]
FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10]
FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03]
Chrome:
=======
CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03]
CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03]
CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03]
CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03]
CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03]
CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03]
CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03]
CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03]
CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 supereasy_1cbackup; No ImagePath
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm))
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-11 02:16 - 2015-07-11 02:16 - 00852662 _____ C:\Users\lxxxxx\Downloads\SecurityCheck.exe
2015-07-11 02:14 - 2015-07-11 02:14 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lxxxxx
2015-07-11 02:14 - 2015-07-11 02:14 - 00000000 ____D C:\ProgramData\ProductData
2015-07-10 17:02 - 2015-07-10 17:03 - 02870984 _____ (ESET) C:\Users\lxxxxx\Downloads\esetsmartinstaller_deu (1).exe
2015-07-10 16:48 - 2015-07-10 16:49 - 02870984 _____ (ESET) C:\Users\lxxxxx\Downloads\esetsmartinstaller_deu.exe
2015-07-09 19:43 - 2015-07-09 19:43 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\ProductData
2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxxxx\Desktop\JRT.txt
2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxxx-PC-Windows-7-Home-Premium-(64-bit).dat
2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup
2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT (1).exe
2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxx\Desktop\mbam.txt
2015-07-09 16:04 - 2015-07-09 16:05 - 01981655 _____ C:\Users\lxxxxx\Downloads\u1501.zip
2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxxx\PUTTY.RND
2015-07-09 16:04 - 2015-07-09 16:04 - 01961239 _____ C:\Users\lxxxxx\Downloads\u__1304.zip
2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxxx\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxxx\Desktop\Addition.txt
2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxxx\Desktop\FRST.txt
2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe
2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe
2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe
2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit
2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe
2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe
2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys
2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe
2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe
2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe
2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe
2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe
2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure
2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe
2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure
2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe
2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys
2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat
2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg
2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml
2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys
2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys
2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys
2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys
2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg
2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe
2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2
2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI
2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg
2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\Lxxxxx\Desktop\fotoworks_setup.exe
2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxx\Desktop\bilder-27062015-0224.zip
2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von xxxxx
2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys
2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys
2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys
2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys
2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\cxxxxx.odt
2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-11 02:21 - 2014-06-12 09:00 - 00020410 _____ C:\Users\lxxxx\Downloads\FRST.txt
2015-07-11 02:21 - 2014-06-12 08:59 - 00000000 ____D C:\FRST
2015-07-11 02:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-11 02:12 - 2014-06-02 10:56 - 02043516 _____ C:\Windows\WindowsUpdate.log
2015-07-11 01:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-11 01:12 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-11 00:51 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-11 00:31 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-11 00:31 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-11 00:29 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat
2015-07-11 00:29 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat
2015-07-11 00:29 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-11 00:23 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job
2015-07-11 00:22 - 2014-06-05 15:51 - 00057198 _____ C:\Windows\setupact.log
2015-07-11 00:22 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini
2015-07-11 00:22 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-11 00:22 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner
2015-07-09 16:04 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx
2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxxx\Downloads\Addition.txt
2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia
2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log
2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_
2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk
2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxx
2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxxx\Bilder vonxxxxxx
2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxx\Bilder vonxxxxxx
2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxx
2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxx
2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxx
2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxx
2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxx
2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore
2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura
2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726
2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Formular xxxxx
2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents\xxxxxxxxxxxxxxxx.odt
2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxxx
2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxxx\AppData\Roaming\Adobe
2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxxx\AppData\Local\Adobe
2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe
2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle
2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxxx\Desktop\jxpiinstall.exe
2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google
==================== Files in the root of some directories =======
2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\lxxxxx\cc_20140606_180858.reg
Some files in TEMP:
====================
C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe
C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-04 15:15
==================== End of log ============================
--- --- ---
Das Facebookproblem in Firefox besteht weiterhin, diesmal soll wieder ein anderer Scanner runtergeladen werden.
Eset hatte ja soviele Einträge gefunden, fast 40.
Müssen die denn nicht alle gelöscht werden? Ich habe die Checkbox zum Löschen nicht angeklickt gehabt.
Bisher war Eset der einziger Scanner, der diese Einträge gefunden hat.
https://scontent-fra3-1.xx.fbcdn.net...51&oe=55A2A113 https://scontent-fra3-1.xx.fbcdn.net...55&oe=55A2B24D