|
Plagegeister aller Art und deren Bekämpfung: Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.comWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.07.2013, 13:42 | #1 |
| Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Hallo, leider habe ich mich wohl mit irgendeinem Download einen nervigen Browservirus, oder wie auch immer man das nennen mag zugezogen. Ich habe probiert dieses Problem mit diesem Video: hxxp://www.youtube.com/watch?v=pSXusqeJmEE zu lösen, leider ohne Erfolg. Vllt kann mir jmd helfen ich wäre sehr dankbar. Mit freundlichen Grüßen das Zebra |
01.07.2013, 13:51 | #2 |
/// the machine /// TB-Ausbilder | Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com HI,
__________________Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ |
01.07.2013, 15:49 | #3 |
| Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Hallo schrauber, schon mal vielen Dank für deine Hilfe
__________________FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03 Ran by Chriss (administrator) on 01-07-2013 16:44:02 Running from C:\Users\Chriss\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (337 Technology Limited.) C:\Program Files (x86)\Desk 365\deskSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (eSafe Security Co., Ltd.) C:\ProgramData\eSafe\eGdpSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Wajam) C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (DT Soft Ltd) D:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (Spotify Ltd) C:\Users\Chriss\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) C:\Users\Chriss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Logitech Inc.) D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Microsoft Corporation) C:\Windows\sysWOW64\wbem\wmiprvse.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKCU\...\Run: [DAEMON Tools Pro Agent] "D:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [x] HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19603048 2013-06-03] (Skype Technologies S.A.) HKCU\...\Run: [Spotify] "C:\Users\Chriss\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4643328 2013-06-18] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] "C:\Users\Chriss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1104384 2013-06-18] (Spotify Ltd) HKCU\...\Run: [Desk 365] "C:\Program Files (x86)\Desk 365\desk365.exe" /autorun [916048 2013-06-30] (337 Technology Limited.) MountPoints2: G - G:\AUTORUN.EXE MountPoints2: {5b0ecf0a-4624-11e2-9491-f46d04aeb530} - G:\Autorun.exe MountPoints2: {7f8b574c-7131-11e1-b7b8-806e6f6e6963} - F:\Autorun.exe MountPoints2: {a9b87efe-c170-11e1-af15-f46d04aeb530} - G:\AutoRun.exe HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [LWS] D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [x] HKLM-x32\...\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe" [x] Startup: C:\ProgramData\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 HKLM SearchScopes: DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=3407939 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=3407939 HKLM-x32 SearchScopes: DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=3407939 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=3407939 HKCU SearchScopes: DefaultScope {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb155/?search={searchTerms}&loc=IB_DS&a=6R8vzTJdvB&i=26 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=3407939 SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://mystart.incredibar.com/mb155/?search={searchTerms}&loc=IB_DS&a=6R8vzTJdvB&i=26 BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll () BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll () BHO-x32: LyricsWoofer - {73F8F433-14C8-48AA-8412-54BC6F8D3FA3} - C:\Program Files (x86)\LyricsWoofer\116.dll (Lyrics Woofer LTD) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Wajam - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default FF user.js: detected! => C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\user.js FF SearchEngine: Google FF Homepage: hxxp://www.bild.de/ FF Keyword.URL: hxxp://mystart.incredibar.com/mb155/?loc=IB_DS&a=6R8vzTJdvB&&i=26&search= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @protectdisc.com/NPMPDRM - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( ) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: youtubeunblocker - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\youtubeunblocker@unblocker.yt.xpi FF Extension: No Name - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi FF Extension: No Name - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF Extension: Web Assistant - C:\Program Files\Web Assistant\Firefox FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: No Name - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] C:\Program Files (x86)\LyricsWoofer\116.xpi FF Extension: No Name - C:\Program Files (x86)\LyricsWoofer\116.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\pdf.dll No File CHR Plugin: (Injovo Extension Plugin) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\npbrowserext.dll (Injovo) CHR Plugin: (Wajam) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll (Wajam) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (fluxDVD Browser Plugin) - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( ) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (VLC Web Plugin) - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Extension: (YouTube) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Web Assistant) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0 CHR Extension: (Wajam) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0 CHR Extension: (Gmail) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-08] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-08] (Avira Operations GmbH & Co. KG) R2 desksvc; C:\Program Files (x86)\Desk 365\deskSvc.exe [424016 2013-06-30] (337 Technology Limited.) R2 eSafeSvc; C:\ProgramData\eSafe\eGdpSvc.exe [361536 2013-06-30] (eSafe Security Co., Ltd.) R2 WajamUpdater; C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [109064 2012-06-14] (Wajam) S4 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2012-08-23] () S4 WebOptimizer; C:\Windows\system32\dmwu.exe [436344 2012-08-16] () R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-05-08] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-05-08] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2011-09-16] (Avira GmbH) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-14] (DT Soft Ltd) S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-12-14] (Duplex Secure Ltd.) U3 arevzmn0; C:\Windows\System32\Drivers\arevzmn0.sys [0 ] (Microsoft Corporation) R3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-01 16:41 - 2013-07-01 16:41 - 01933758 ____A (Farbar) C:\Users\Chriss\Desktop\FRST64.exe 2013-07-01 16:41 - 2013-07-01 16:41 - 00000000 ____D C:\FRST 2013-07-01 13:00 - 2013-07-01 16:43 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____A C:\autoexec.bat 2013-07-01 12:59 - 2013-07-01 12:59 - 00726464 ____A (Enigma Software Group USA, LLC.) C:\Users\Chriss\Desktop\SpyHunter-Installer.exe 2013-07-01 12:42 - 2013-07-01 12:43 - 00019973 ____A C:\AdwCleaner[R1].txt 2013-07-01 12:41 - 2013-07-01 12:41 - 00648201 ____A C:\Users\Chriss\Desktop\adwcleaner.exe 2013-07-01 12:30 - 2013-07-01 12:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{48372323-CE3A-4977-A3F5-96881D85C09E} 2013-07-01 03:22 - 2013-07-01 03:22 - 01888311 ____A C:\Users\Chriss\Desktop\HLOma's Gurkenfass.zip 2013-07-01 03:22 - 2013-07-01 03:22 - 01781705 ____A C:\Users\Chriss\Desktop\HLLila Pause.zip 2013-06-30 23:26 - 2013-06-30 23:28 - 00000000 ____D C:\Users\Chriss\Desktop\simssaveneu 2013-06-30 23:23 - 2013-06-30 23:24 - 00000000 ____D C:\Users\Chriss\Desktop\SimsInsel 2013-06-30 22:34 - 2013-06-30 22:34 - 00002037 ____A C:\Users\Chriss\Desktop\JDownloader.lnk 2013-06-30 22:33 - 2013-07-01 12:50 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Desk 365 2013-06-30 22:33 - 2013-07-01 12:32 - 00000000 ____D C:\ProgramData\eSafe 2013-06-30 22:33 - 2013-07-01 12:32 - 00000000 ____D C:\Program Files (x86)\Desk 365 2013-06-30 22:33 - 2013-07-01 12:30 - 00000406 ____A C:\Windows\Tasks\LyricsWoofer Update.job 2013-06-30 22:33 - 2013-06-30 22:49 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\eIntaller 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsWoofer 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsFan 2013-06-30 10:43 - 2013-06-30 22:43 - 00000000 ____D C:\Users\Chriss\AppData\Local\{1FDC18B7-3B8B-4947-BC9D-557BB0F11F47} 2013-06-29 18:35 - 2013-06-29 18:35 - 02813358 ____A C:\Users\Chriss\Desktop\Booster Maxxx G4.rar 2013-06-29 15:55 - 2013-06-29 15:55 - 00000000 ____D C:\Users\Chriss\AppData\Local\{25F5BACE-F7AE-485F-B472-2190DADAE562} 2013-06-28 15:54 - 2013-06-29 03:55 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C8AADB8F-956E-4B30-A8EB-27F3A4603B2F} 2013-06-27 13:39 - 2013-06-28 01:39 - 00000000 ____D C:\Users\Chriss\AppData\Local\{7BBCAEE7-F7DF-4D26-A1D2-ADB5F2EBE97D} 2013-06-26 15:15 - 2013-06-26 15:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{818D5577-D028-464C-9304-18F73F795493} 2013-06-25 22:27 - 2013-06-25 22:27 - 00000048 ____A C:\MyUpdateLogs.log 2013-06-25 21:51 - 2013-06-25 21:53 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister Backup 2013-06-25 15:14 - 2013-06-26 03:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AFBA7E3D-B5FE-463F-AF13-D7D87C459D00} 2013-06-25 03:14 - 2013-06-25 03:14 - 00000000 ____D C:\Users\Chriss\AppData\Local\{3CBB033C-197E-45F3-BE2A-A1F121D506D3} 2013-06-25 02:25 - 2013-06-25 02:25 - 00000000 ____D C:\Users\Chriss\Desktop\ebay 2013-06-25 01:11 - 2013-06-25 01:11 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister 2013-06-25 00:59 - 2013-06-25 01:02 - 00000402 ____A C:\InstallHelper.log 2013-06-25 00:58 - 2013-06-25 00:58 - 00001814 ____A C:\Users\Public\Desktop\eBay Turbo Lister 2.lnk 2013-06-25 00:58 - 2013-06-25 00:58 - 00000000 ____D C:\ProgramData\eBay 2013-06-24 15:13 - 2013-06-24 15:14 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AB0C323B-B8FD-457D-BF30-7944CF88E6E5} 2013-06-24 03:13 - 2013-06-24 03:13 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F40704FC-4AB7-4147-AE22-0A6CED44D1F9} 2013-06-23 15:12 - 2013-06-23 15:13 - 00000000 ____D C:\Users\Chriss\AppData\Local\{6571E687-8156-46CD-91AC-1647B2C19562} 2013-06-22 15:30 - 2013-06-22 15:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{13A6DFD8-B806-4E0F-86D1-EDC4922A3A1A} 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iTunes 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iPod 2013-06-22 03:29 - 2013-06-22 03:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{0BD82EA9-7F94-4D59-83AD-3152F40AAB40} 2013-06-21 15:29 - 2013-06-21 15:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{592D178F-4200-49BD-9831-CCF1832D6A50} 2013-06-21 03:28 - 2013-06-21 03:28 - 00000000 ____D C:\Users\Chriss\AppData\Local\{EC94FFF6-00EE-4886-82E2-380D26F95677} 2013-06-20 15:28 - 2013-06-20 15:28 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C2252097-C182-4D5A-B6FE-7918281A2406} 2013-06-20 03:27 - 2013-06-20 03:28 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C3292957-0DD3-4609-A9B7-00FA41015125} 2013-06-19 20:35 - 2013-05-17 06:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-19 20:35 - 2013-05-17 05:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-19 20:35 - 2013-05-17 05:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-19 20:35 - 2013-05-17 05:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-19 20:35 - 2013-05-17 05:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-19 20:35 - 2013-05-17 05:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-19 20:35 - 2013-05-17 05:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-19 20:35 - 2013-05-17 04:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-19 20:35 - 2013-05-17 04:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-19 20:35 - 2013-05-17 04:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-19 20:35 - 2013-05-17 04:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-19 20:35 - 2013-05-17 04:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-19 20:35 - 2013-05-17 04:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-19 20:35 - 2013-05-17 04:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-19 20:35 - 2013-05-17 04:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-19 20:35 - 2013-05-17 04:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-19 20:35 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-19 20:35 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-19 20:35 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-19 20:35 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-19 20:35 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-19 20:35 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-19 20:35 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-19 20:35 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-19 20:35 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-19 20:35 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-19 20:35 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-19 20:35 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-19 20:35 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-19 20:35 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-19 20:35 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-19 20:35 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-19 20:30 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-19 20:30 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-19 20:30 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-19 20:30 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-19 20:30 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-19 20:30 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-19 20:30 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-19 20:30 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-19 20:30 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-19 20:30 - 2013-04-12 16:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-06-19 20:30 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-06-19 20:30 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-06-19 20:30 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-06-19 20:30 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-06-19 20:30 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-06-19 20:30 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-06-19 20:30 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-06-19 20:30 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-06-19 20:30 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-06-19 20:30 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-06-19 20:30 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-06-19 20:30 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-06-19 20:30 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-06-19 20:30 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys 2013-06-19 20:30 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-06-19 15:27 - 2013-06-19 15:27 - 00000000 ____D C:\Users\Chriss\AppData\Local\{E234AE73-2AF2-49A9-9F7B-7822B0D587B0} 2013-06-18 21:49 - 2013-06-18 21:49 - 00000000 ____D C:\Users\Chriss\AppData\Local\{9D78207C-3033-4CC5-AF86-1B4FC7912652} 2013-06-17 22:09 - 2013-06-17 22:09 - 02702378 ____A C:\Users\Chriss\Desktop\Mixer.rar 2013-06-17 21:48 - 2013-06-18 09:49 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F7EF7B97-82E5-4271-9503-79207CA0DA52} 2013-06-17 09:22 - 2013-06-17 09:22 - 00000000 ____D C:\Users\Chriss\AppData\Local\{8CFDF29A-BCA3-4936-8041-F80158DBC8D6} 2013-06-16 17:15 - 2013-06-16 17:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{4F4CD7FE-51D7-408B-B686-79B44FC9EDB4} 2013-06-16 05:15 - 2013-06-16 05:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{7D67C7ED-BEE7-4232-A391-6C80F1C10FB8} 2013-06-15 15:21 - 2013-06-15 15:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\{57620BB6-C6FD-4199-9D9A-7DD3F5C4FED8} 2013-06-14 15:21 - 2013-06-15 03:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\{99495099-6E57-4F57-9FA3-B508D25306E1} 2013-06-14 03:20 - 2013-06-14 03:20 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C0B64A31-A3AE-4FE8-893C-28ECF8A57488} 2013-06-13 15:20 - 2013-06-13 15:20 - 00000000 ____D C:\Users\Chriss\AppData\Local\{59567B23-66F9-4CFB-9EE9-D1AC5BC2B2A8} 2013-06-13 03:19 - 2013-06-13 03:19 - 00000000 ____D C:\Users\Chriss\AppData\Local\{9522295F-7318-4EB6-8410-6D82EFFB3C57} 2013-06-12 15:19 - 2013-06-12 15:19 - 00000000 ____D C:\Users\Chriss\AppData\Local\{64FC34CC-B86F-49A3-BBB3-8C49B63BC099} 2013-06-11 16:22 - 2013-06-11 16:22 - 00000000 ____D C:\Users\Chriss\AppData\Local\{18234343-7ED8-4F7B-AD61-F7FD765451FB} 2013-06-11 01:04 - 2013-06-11 01:04 - 00000000 ____D C:\Users\Chriss\AppData\Local\{CDA6B3B2-C005-4965-8737-0F117529A262} 2013-06-10 15:58 - 2013-06-10 15:58 - 01044480 ___RA (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll 2013-06-10 15:58 - 2013-06-10 15:58 - 00049152 ___RA (Blue Sky Software Corporation.) C:\Windows\SysWOW64\inetwh32.dll 2013-06-10 13:03 - 2013-06-10 13:03 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F35CD770-C743-460C-AFDB-21AA1B4504E6} 2013-06-09 14:51 - 2013-06-09 14:51 - 00000000 ____D C:\Users\Chriss\AppData\Local\{3772B2D3-DC18-4AF7-B218-BD62040DD5A7} 2013-06-09 00:40 - 2013-06-09 00:40 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AF6C33C2-E2FC-4358-BE50-93B9B920273F} 2013-06-08 12:40 - 2013-06-08 12:40 - 00000000 ____D C:\Users\Chriss\AppData\Local\{5651E44F-BAF9-47D4-9E9E-B0CAB2E2D86A} 2013-06-07 23:30 - 2013-06-07 23:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C6F6D50F-D5B3-443F-BF25-530FC17A92C6} 2013-06-07 11:29 - 2013-06-07 11:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{ACEE5CA1-ABA0-4D3F-903A-FA1C66138BE7} 2013-06-06 11:29 - 2013-06-06 23:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{50AC950B-264A-4FFB-BA2E-6E2B8841E98A} 2013-06-05 15:40 - 2013-06-05 15:41 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AC96BF32-E0AA-4ECF-B4F3-7944A303D623} 2013-06-04 13:44 - 2013-06-05 01:45 - 00000000 ____D C:\Users\Chriss\AppData\Local\{B92CBFBB-E50B-4152-8E9A-DCAED2332D58} 2013-06-04 01:32 - 2013-06-04 01:32 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F1834FD1-AC9C-466E-ADCB-600413EFA1C2} 2013-06-03 13:31 - 2013-06-03 13:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{33DBE1E0-2159-4F2D-97CF-4B7273E440FD} 2013-06-03 01:31 - 2013-06-03 01:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{A697A618-E4D6-4D08-AD08-BFC771BE6FC8} 2013-06-02 13:30 - 2013-06-02 13:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{94BAD366-4392-425A-A0C1-212CCD84B82A} 2013-06-02 01:30 - 2013-06-02 01:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{FA424AF7-B71D-4DF3-AA01-C1F90443D822} 2013-06-01 13:29 - 2013-06-01 13:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{288D3AEE-99C7-4B49-BB9F-94AEE48A0A1E} ==================== One Month Modified Files and Folders ======= 2013-07-01 16:43 - 2013-07-01 13:00 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-01 16:42 - 2012-04-10 21:26 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Skype 2013-07-01 16:41 - 2013-07-01 16:41 - 01933758 ____A (Farbar) C:\Users\Chriss\Desktop\FRST64.exe 2013-07-01 16:41 - 2013-07-01 16:41 - 00000000 ____D C:\FRST 2013-07-01 16:37 - 2012-04-04 13:31 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-01 15:05 - 2012-03-21 12:02 - 00000000 ____D C:\Users\Chriss\AppData\Local\Spotify 2013-07-01 13:09 - 2012-04-04 15:17 - 00043520 ____A C:\Windows\SysWOW64\CmdLineExt03.dll 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____A C:\autoexec.bat 2013-07-01 12:59 - 2013-07-01 12:59 - 00726464 ____A (Enigma Software Group USA, LLC.) C:\Users\Chriss\Desktop\SpyHunter-Installer.exe 2013-07-01 12:50 - 2013-06-30 22:33 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Desk 365 2013-07-01 12:43 - 2013-07-01 12:42 - 00019973 ____A C:\AdwCleaner[R1].txt 2013-07-01 12:41 - 2013-07-01 12:41 - 00648201 ____A C:\Users\Chriss\Desktop\adwcleaner.exe 2013-07-01 12:40 - 2012-03-21 12:02 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Spotify 2013-07-01 12:37 - 2009-07-14 06:45 - 00014608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-01 12:37 - 2009-07-14 06:45 - 00014608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-01 12:33 - 2012-03-18 21:47 - 02009807 ____A C:\Windows\WindowsUpdate.log 2013-07-01 12:32 - 2013-06-30 22:33 - 00000000 ____D C:\ProgramData\eSafe 2013-07-01 12:32 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\Desk 365 2013-07-01 12:30 - 2013-07-01 12:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{48372323-CE3A-4977-A3F5-96881D85C09E} 2013-07-01 12:30 - 2013-06-30 22:33 - 00000406 ____A C:\Windows\Tasks\LyricsWoofer Update.job 2013-07-01 12:30 - 2012-03-19 00:46 - 00000000 ____D C:\Users\Chriss\Tracing 2013-07-01 12:29 - 2012-04-10 22:08 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs 2013-07-01 12:29 - 2012-03-19 13:54 - 00097678 ____A C:\Windows\PFRO.log 2013-07-01 12:29 - 2012-03-18 22:24 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-01 12:29 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-01 12:29 - 2009-07-14 06:51 - 00130646 ____A C:\Windows\setupact.log 2013-07-01 12:29 - 2009-07-14 06:45 - 00269032 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-01 03:22 - 2013-07-01 03:22 - 01888311 ____A C:\Users\Chriss\Desktop\HLOma's Gurkenfass.zip 2013-07-01 03:22 - 2013-07-01 03:22 - 01781705 ____A C:\Users\Chriss\Desktop\HLLila Pause.zip 2013-06-30 23:48 - 2012-03-19 01:21 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Origin 2013-06-30 23:48 - 2012-03-19 01:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\Origin 2013-06-30 23:48 - 2012-03-19 01:20 - 00000000 ____D C:\Program Files (x86)\Origin 2013-06-30 23:43 - 2012-03-19 01:20 - 00000000 ____D C:\ProgramData\Origin 2013-06-30 23:40 - 2012-03-18 22:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-30 23:28 - 2013-06-30 23:26 - 00000000 ____D C:\Users\Chriss\Desktop\simssaveneu 2013-06-30 23:24 - 2013-06-30 23:23 - 00000000 ____D C:\Users\Chriss\Desktop\SimsInsel 2013-06-30 22:49 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-06-30 22:43 - 2013-06-30 10:43 - 00000000 ____D C:\Users\Chriss\AppData\Local\{1FDC18B7-3B8B-4947-BC9D-557BB0F11F47} 2013-06-30 22:34 - 2013-06-30 22:34 - 00002037 ____A C:\Users\Chriss\Desktop\JDownloader.lnk 2013-06-30 22:34 - 2012-03-19 00:35 - 00058016 ____A C:\Users\Chriss\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\eIntaller 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsWoofer 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsFan 2013-06-30 22:33 - 2012-04-19 13:21 - 00001368 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-06-30 22:30 - 2012-09-26 22:19 - 00000000 ____D C:\Program Files (x86)\DownloadManager 2013-06-30 15:27 - 2013-01-31 15:07 - 00000000 ____A C:\END 2013-06-29 18:35 - 2013-06-29 18:35 - 02813358 ____A C:\Users\Chriss\Desktop\Booster Maxxx G4.rar 2013-06-29 15:55 - 2013-06-29 15:55 - 00000000 ____D C:\Users\Chriss\AppData\Local\{25F5BACE-F7AE-485F-B472-2190DADAE562} 2013-06-29 03:55 - 2013-06-28 15:54 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C8AADB8F-956E-4B30-A8EB-27F3A4603B2F} 2013-06-28 01:39 - 2013-06-27 13:39 - 00000000 ____D C:\Users\Chriss\AppData\Local\{7BBCAEE7-F7DF-4D26-A1D2-ADB5F2EBE97D} 2013-06-27 20:12 - 2009-07-14 19:58 - 00697680 ____A C:\Windows\System32\perfh007.dat 2013-06-27 20:12 - 2009-07-14 19:58 - 00148976 ____A C:\Windows\System32\perfc007.dat 2013-06-27 20:12 - 2009-07-14 07:13 - 01616160 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-27 20:11 - 2012-03-18 22:39 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\vlc 2013-06-26 15:15 - 2013-06-26 15:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{818D5577-D028-464C-9304-18F73F795493} 2013-06-26 03:15 - 2013-06-25 15:14 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AFBA7E3D-B5FE-463F-AF13-D7D87C459D00} 2013-06-25 22:27 - 2013-06-25 22:27 - 00000048 ____A C:\MyUpdateLogs.log 2013-06-25 21:53 - 2013-06-25 21:51 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister Backup 2013-06-25 03:14 - 2013-06-25 03:14 - 00000000 ____D C:\Users\Chriss\AppData\Local\{3CBB033C-197E-45F3-BE2A-A1F121D506D3} 2013-06-25 02:25 - 2013-06-25 02:25 - 00000000 ____D C:\Users\Chriss\Desktop\ebay 2013-06-25 01:11 - 2013-06-25 01:11 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister 2013-06-25 01:02 - 2013-06-25 00:59 - 00000402 ____A C:\InstallHelper.log 2013-06-25 00:58 - 2013-06-25 00:58 - 00001814 ____A C:\Users\Public\Desktop\eBay Turbo Lister 2.lnk 2013-06-25 00:58 - 2013-06-25 00:58 - 00000000 ____D C:\ProgramData\eBay 2013-06-24 15:14 - 2013-06-24 15:13 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AB0C323B-B8FD-457D-BF30-7944CF88E6E5} 2013-06-24 03:13 - 2013-06-24 03:13 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F40704FC-4AB7-4147-AE22-0A6CED44D1F9} 2013-06-23 15:13 - 2013-06-23 15:12 - 00000000 ____D C:\Users\Chriss\AppData\Local\{6571E687-8156-46CD-91AC-1647B2C19562} 2013-06-22 15:30 - 2013-06-22 15:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{13A6DFD8-B806-4E0F-86D1-EDC4922A3A1A} 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iTunes 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iPod 2013-06-22 03:29 - 2013-06-22 03:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{0BD82EA9-7F94-4D59-83AD-3152F40AAB40} 2013-06-21 16:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-21 15:29 - 2013-06-21 15:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{592D178F-4200-49BD-9831-CCF1832D6A50} 2013-06-21 03:28 - 2013-06-21 03:28 - 00000000 ____D C:\Users\Chriss\AppData\Local\{EC94FFF6-00EE-4886-82E2-380D26F95677} 2013-06-20 15:28 - 2013-06-20 15:28 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C2252097-C182-4D5A-B6FE-7918281A2406} 2013-06-20 03:28 - 2013-06-20 03:27 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C3292957-0DD3-4609-A9B7-00FA41015125} 2013-06-19 15:27 - 2013-06-19 15:27 - 00000000 ____D C:\Users\Chriss\AppData\Local\{E234AE73-2AF2-49A9-9F7B-7822B0D587B0} 2013-06-18 21:49 - 2013-06-18 21:49 - 00000000 ____D C:\Users\Chriss\AppData\Local\{9D78207C-3033-4CC5-AF86-1B4FC7912652} 2013-06-18 09:49 - 2013-06-17 21:48 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F7EF7B97-82E5-4271-9503-79207CA0DA52} 2013-06-17 22:09 - 2013-06-17 22:09 - 02702378 ____A C:\Users\Chriss\Desktop\Mixer.rar 2013-06-17 09:22 - 2013-06-17 09:22 - 00000000 ____D C:\Users\Chriss\AppData\Local\{8CFDF29A-BCA3-4936-8041-F80158DBC8D6} 2013-06-16 17:15 - 2013-06-16 17:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{4F4CD7FE-51D7-408B-B686-79B44FC9EDB4} 2013-06-16 05:15 - 2013-06-16 05:15 - 00000000 ____D C:\Users\Chriss\AppData\Local\{7D67C7ED-BEE7-4232-A391-6C80F1C10FB8} 2013-06-15 15:21 - 2013-06-15 15:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\{57620BB6-C6FD-4199-9D9A-7DD3F5C4FED8} 2013-06-15 14:06 - 2012-04-04 13:31 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-15 14:06 - 2012-03-19 20:44 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-15 03:21 - 2013-06-14 15:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\{99495099-6E57-4F57-9FA3-B508D25306E1} 2013-06-14 03:20 - 2013-06-14 03:20 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C0B64A31-A3AE-4FE8-893C-28ECF8A57488} 2013-06-13 15:20 - 2013-06-13 15:20 - 00000000 ____D C:\Users\Chriss\AppData\Local\{59567B23-66F9-4CFB-9EE9-D1AC5BC2B2A8} 2013-06-13 13:03 - 2009-07-14 07:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-13 03:19 - 2013-06-13 03:19 - 00000000 ____D C:\Users\Chriss\AppData\Local\{9522295F-7318-4EB6-8410-6D82EFFB3C57} 2013-06-12 20:02 - 2013-01-23 19:29 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-12 20:02 - 2012-04-10 21:26 - 00000000 ____D C:\ProgramData\Skype 2013-06-12 15:19 - 2013-06-12 15:19 - 00000000 ____D C:\Users\Chriss\AppData\Local\{64FC34CC-B86F-49A3-BBB3-8C49B63BC099} 2013-06-11 16:22 - 2013-06-11 16:22 - 00000000 ____D C:\Users\Chriss\AppData\Local\{18234343-7ED8-4F7B-AD61-F7FD765451FB} 2013-06-11 01:04 - 2013-06-11 01:04 - 00000000 ____D C:\Users\Chriss\AppData\Local\{CDA6B3B2-C005-4965-8737-0F117529A262} 2013-06-10 15:58 - 2013-06-10 15:58 - 01044480 ___RA (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll 2013-06-10 15:58 - 2013-06-10 15:58 - 00049152 ___RA (Blue Sky Software Corporation.) C:\Windows\SysWOW64\inetwh32.dll 2013-06-10 13:03 - 2013-06-10 13:03 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F35CD770-C743-460C-AFDB-21AA1B4504E6} 2013-06-09 14:51 - 2013-06-09 14:51 - 00000000 ____D C:\Users\Chriss\AppData\Local\{3772B2D3-DC18-4AF7-B218-BD62040DD5A7} 2013-06-09 00:40 - 2013-06-09 00:40 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AF6C33C2-E2FC-4358-BE50-93B9B920273F} 2013-06-08 23:34 - 2012-04-19 15:38 - 00000000 ____D C:\Users\Chriss\AppData\Local\Deployment 2013-06-08 12:40 - 2013-06-08 12:40 - 00000000 ____D C:\Users\Chriss\AppData\Local\{5651E44F-BAF9-47D4-9E9E-B0CAB2E2D86A} 2013-06-07 23:30 - 2013-06-07 23:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{C6F6D50F-D5B3-443F-BF25-530FC17A92C6} 2013-06-07 11:30 - 2013-06-07 11:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{ACEE5CA1-ABA0-4D3F-903A-FA1C66138BE7} 2013-06-06 23:29 - 2013-06-06 11:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{50AC950B-264A-4FFB-BA2E-6E2B8841E98A} 2013-06-05 15:41 - 2013-06-05 15:40 - 00000000 ____D C:\Users\Chriss\AppData\Local\{AC96BF32-E0AA-4ECF-B4F3-7944A303D623} 2013-06-05 01:45 - 2013-06-04 13:44 - 00000000 ____D C:\Users\Chriss\AppData\Local\{B92CBFBB-E50B-4152-8E9A-DCAED2332D58} 2013-06-04 01:32 - 2013-06-04 01:32 - 00000000 ____D C:\Users\Chriss\AppData\Local\{F1834FD1-AC9C-466E-ADCB-600413EFA1C2} 2013-06-03 13:31 - 2013-06-03 13:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{33DBE1E0-2159-4F2D-97CF-4B7273E440FD} 2013-06-03 01:31 - 2013-06-03 01:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{A697A618-E4D6-4D08-AD08-BFC771BE6FC8} 2013-06-02 17:11 - 2012-03-27 21:22 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-02 13:31 - 2013-06-02 13:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{94BAD366-4392-425A-A0C1-212CCD84B82A} 2013-06-02 01:30 - 2013-06-02 01:30 - 00000000 ____D C:\Users\Chriss\AppData\Local\{FA424AF7-B71D-4DF3-AA01-C1F90443D822} 2013-06-01 13:29 - 2013-06-01 13:29 - 00000000 ____D C:\Users\Chriss\AppData\Local\{288D3AEE-99C7-4B49-BB9F-94AEE48A0A1E} 2013-06-01 01:18 - 2013-05-31 13:17 - 00000000 ____D C:\Users\Chriss\AppData\Local\{23F507A3-EB2F-458D-A650-3B36A9DFECA4} ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-23 03:30 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-06-2013 03 Ran by Chriss at 2013-07-01 16:44:28 Running from C:\Users\Chriss\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 3d KirmesworldTake Off (HKCU) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Flash Player ActiveX (x32 Version: 9.0.124.0) Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) ARMA II: Combined Operations (x32) Avira Free Antivirus (x32 Version: 12.1.9.1236) BattlEye for OA Uninstall (x32) Bonjour (Version: 3.0.0.10) Break Dancer No.2 v.5.0 (HKCU) CameraHelperMsi (x32 Version: 13.51.815.0) D3DX10 (x32 Version: 15.4.2368.0902) DAEMON Tools Pro (x32 Version: 5.2.0.0348) DayZ Commander (x32 Version: 0.9.88) Deal or No Deal DE (x32 Version: 1.0) Desk 365 (x32 Version: 1.12.16) DHTML Editing Component (x32 Version: 6.02.0001) Die Sims™ 3 (x32 Version: 1.54.95) Die Sims™ 3 70er, 80er & 90er Accessoires (x32 Version: 17.0.77) Die Sims™ 3 Design-Garten-Accessoires (x32 Version: 7.0.55) Die Sims™ 3 Diesel Accessoires (x32 Version: 14.0.48) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96) Die Sims™ 3 Gib Gas-Accessoires (x32 Version: 5.0.44) Die Sims™ 3 Inselparadies (x32 Version: 19.0.101) Die Sims™ 3 Jahreszeiten (x32 Version: 16.0.136) Die Sims™ 3 Katy Perry Süße Welt (x32 Version: 13.0.62) Die Sims™ 3 Late Night (x32 Version: 6.0.81) Die Sims™ 3 Lebensfreude (x32 Version: 8.0.152) Die Sims™ 3 Luxus-Accessoires (x32 Version: 3.0.38) Die Sims™ 3 Reiseabenteuer (x32 Version: 2.0.86) Die Sims™ 3 Showtime (x32 Version: 12.0.273) Die Sims™ 3 Stadt-Accessoires (x32 Version: 9.0.73) Die Sims™ 3 Supernatural (x32 Version: 15.0.135) Die Sims™ 3 Traumkarrieren (x32 Version: 4.0.87) Die Sims™ 3 Traumsuite-Accessoires (x32 Version: 11.0.84) Die Sims™ 3 Wildes Studentenleben (x32 Version: 18.0.126) Drop Zone Simulatie (HKCU) erLT (x32 Version: 1.20.138.34) eSafe Security Control 1.0.0.2522 (x32 Version: 1.0.0.2522) EVEREST Home Edition v2.20 (x32 Version: 2.20) Fairground Rides - MusikExpress (x32) Free Whale Version 1.0.0.0 (x32 Version: 1.0.0.0) Free YouTube to MP3 Converter version 3.11.36.1130 (x32 Version: 3.11.36.1130) Gerstlauer Sky Fly 3D-Simulation (HKCU) Grand Theft Auto IV (x32 Version: 1.0.0013.131) Grand Theft Auto IV (x32 Version: 1.00.0000) Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0003.135) Grand Theft Auto: Episodes From Liberty City (x32 Version: 1.1.0.0) GTA IV Vehicle Mod Installer v1.2 (x32) GTA IV Vehicle Mod Installer v1.3 (x32) Hospital Tycoon (x32) iTunes (Version: 11.0.4.4) Java Auto Updater (x32 Version: 2.1.6.0) Java(TM) 7 Update 5 (x32 Version: 7.0.50) JavaFX 2.1.1 (x32 Version: 2.1.1) JDownloader 0.9 (x32 Version: 0.9) Kick Down Simulatie (HKCU) Logitech Webcam-Software (x32 Version: 2.51) LWS Facebook (x32 Version: 13.50.854.0) LWS Gallery (x32 Version: 13.51.827.0) LWS Help_main (x32 Version: 13.51.828.0) LWS Launcher (x32 Version: 13.51.828.0) LWS Motion Detection (x32 Version: 13.51.815.0) LWS Pictures And Video (x32 Version: 13.51.815.0) LWS Twitter (x32 Version: 13.30.1346.0) LWS Webcam Software (x32 Version: 13.51.815.0) LWS WLM Plugin (x32 Version: 1.30.1201.0) LWS YouTube Plugin (x32 Version: 13.31.1038.0) LyricsWoofer (x32) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Games for Windows - LIVE (x32 Version: 3.1.186.0) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.1.99.0) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft XNA Framework Redistributable 1.0 Refresh (x32 Version: 1.1.10405.0) Mozilla Firefox 21.0 (x86 de) (x32 Version: 21.0) Mozilla Maintenance Service (x32 Version: 21.0) MSVCRT (x32 Version: 15.4.2862.0708) NC Launcher (GameForge) (x32) NETGEAR WNDA3100v2 wireless USB 2.0 adapter (x32 Version: 1.03.000) NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA HD-Audiotreiber 1.3.12.0 (Version: 1.3.12.0) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA PhysX (x32 Version: 9.12.0213) NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Origin (x32 Version: 9.1.15.109) oZone3D.Net FurMark v1.8.2 (x32) Pando Media Booster (x32 Version: 2.6.0.8) Power Wave Simulatie (HKCU) ProtectDisc Driver, Version 11 (x32 Version: 11.0.0.14) RCT³Trainer08 (HKCU Version: 1.0.0.0) Realtek Ethernet Controller Driver (x32 Version: 7.37.1229.2010) Rides X-Treme Harlekin-Simulation (HKCU) RollerCoaster Tycoon 3 (x32) Samsung Kies (x32 Version: 2.3.2.12064_9) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.6.0) Shake And Roll Simulatie v.1.1 (HKCU) Skype™ 6.5 (x32 Version: 6.5.158) Spotify (HKCU Version: 0.9.1.53.g876fa9df) TeamSpeak 3 Client (x32 Version: 3.0.6) T-Rex Version 1.0.0.0 (x32 Version: 1.0.0.0) Turbo Lister 2 (x32 Version: 2.00.0000) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) VLC media player 2.0.0 (x32 Version: 2.0.0) Wajam (x32 Version: 1.45) Web Assistant 2.0.0.478 (Version: 2.0.0.478) Web Optimizer (Version: 1.0.0.4) Wildlife Park 3 v1.0 (x32) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3555.0308) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) WinRAR 4.11 (64-Bit) (Version: 4.11.0) Ynor9's Control Room 1.0.0 (x32 Version: 1.0.0) ==================== Restore Points ========================= 23-06-2013 00:41:34 Installiert The Sims 3 24-06-2013 22:58:18 Turbo Lister 2 wurde installiert. 29-06-2013 01:55:28 Windows Update 30-06-2013 21:31:35 Installiert The Sims 3 30-06-2013 21:40:25 Installiert TheSims3EP10 01-07-2013 11:00:15 Installed SpyHunter 01-07-2013 14:42:16 Removed SpyHunter ==================== Scheduled Tasks (whitelisted) ============= Task: {321D9B51-33B1-4659-8790-B95554B3F207} - System32\Tasks\{FC7CE321-F99D-4D65-AEA3-FA67C5EFA7AD} => C:\program files (x86)\mozilla firefox\firefox.exe [2013-05-23] (Mozilla Corporation) Task: {4A12E6BA-9AC5-4425-ACB0-C9F2A1BAA28F} - System32\Tasks\LyricsWoofer Update => C:\Program Files (x86)\LyricsWoofer\LyricsWooferUPD.exe [2013-06-25] (Lyrics Woofer LTD) Task: {8874901F-2149-407B-A65A-66A088E64D49} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {8B90F6E0-11BB-4B90-8BB1-6B7773F8A9B9} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {8DC33E07-16AF-43C4-9845-C22DFA5F26CF} - System32\Tasks\{CD586083-1ADC-4721-9E85-89B0C5C0E959} => C:\program files (x86)\mozilla firefox\firefox.exe [2013-05-23] (Mozilla Corporation) Task: {A5F141DD-D9D7-4077-91E9-FC63B2018BC2} - System32\Tasks\{3CB1F9D7-07B2-43B3-ADFC-97E430362070} => C:\program files (x86)\mozilla firefox\firefox.exe [2013-05-23] (Mozilla Corporation) Task: {CF49F717-E46A-4A09-8B42-351C65642968} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files (x86)\Desk 365\desk365.exe [2013-06-30] (337 Technology Limited.) Task: {E588D4AC-6AB6-4556-A549-3091FD75F0B1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-15] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\LyricsWoofer Update.job => C:\Program Files (x86)\LyricsWoofer\LyricsWooferUPD.exe ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/24/2013 00:35:37 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe, Version: 11.7.700.224, Zeitstempel: 0x51a67447 Name des fehlerhaften Moduls: FlashPlayerPlugin_11_7_700_224.exe, Version: 11.7.700.224, Zeitstempel: 0x51a67447 Ausnahmecode: 0x40000015 Fehleroffset: 0x000178f0 ID des fehlerhaften Prozesses: 0x10c8 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_7_700_224.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_7_700_224.exe2 Berichtskennung: FlashPlayerPlugin_11_7_700_224.exe3 Error: (06/23/2013 02:57:36 AM) (Source: Application Hang) (User: ) Description: Programm TS3W.exe, Version 0.2.0.210 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e794 Startzeit: 01ce6fac87288fbf Endzeit: 16 Anwendungspfad: E:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exe Berichts-ID: Error: (06/23/2013 02:55:59 AM) (Source: Application Hang) (User: ) Description: Programm TS3W.exe, Version 0.2.0.210 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e7d0 Startzeit: 01ce6fac5f617be5 Endzeit: 9 Anwendungspfad: E:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exe Berichts-ID: Error: (06/23/2013 02:54:59 AM) (Source: Application Hang) (User: ) Description: Programm TS3W.exe, Version 0.2.0.188 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e354 Startzeit: 01ce6fac31fe9ff4 Endzeit: 10 Anwendungspfad: E:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exe Berichts-ID: Error: (06/23/2013 02:48:36 AM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\ProgramData\EA Core\cache\TempE0B4\{ CP_Guest_57524(4)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe Core\cache\TempE0B4\{ CP_Guest_57524(4)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe" ; Beschreibung = Installiert The Sims 3; Fehler = 0x80070514). Error: (06/23/2013 02:45:33 AM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\ProgramData\EA Core\cache\TempE194\{ CP_Guest_57748(2)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe Core\cache\TempE194\{ CP_Guest_57748(2)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe" ; Beschreibung = Installiert The Sims 3; Fehler = 0x80070514). Error: (06/23/2013 02:43:11 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: OriginLegacyCLI.exe, Version: 8.1.0.1556, Zeitstempel: 0x4de4e4d1 Name des fehlerhaften Moduls: EACore.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x4e446ab8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x5c4a0c9d ID des fehlerhaften Prozesses: 0xe100 Startzeit der fehlerhaften Anwendung: 0xOriginLegacyCLI.exe0 Pfad der fehlerhaften Anwendung: OriginLegacyCLI.exe1 Pfad des fehlerhaften Moduls: OriginLegacyCLI.exe2 Berichtskennung: OriginLegacyCLI.exe3 Error: (06/12/2013 08:00:53 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Skype.exe, Version: 6.3.0.107, Zeitstempel: 0x51715160 Name des fehlerhaften Moduls: Skype.exe, Version: 6.3.0.107, Zeitstempel: 0x51715160 Ausnahmecode: 0xc0000005 Fehleroffset: 0x01023d9f ID des fehlerhaften Prozesses: 0xa14 Startzeit der fehlerhaften Anwendung: 0xSkype.exe0 Pfad der fehlerhaften Anwendung: Skype.exe1 Pfad des fehlerhaften Moduls: Skype.exe2 Berichtskennung: Skype.exe3 Error: (06/01/2013 01:59:14 AM) (Source: Application Hang) (User: ) Description: Programm spotify.exe, Version 0.9.0.133 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a7c Startzeit: 01ce5e5ace7e3a33 Endzeit: 0 Anwendungspfad: C:\Users\Chriss\AppData\Roaming\Spotify\spotify.exe Berichts-ID: 1502d7b3-ca4e-11e2-9099-f46d04aeb530 Error: (05/29/2013 00:00:03 AM) (Source: Application Hang) (User: ) Description: Programm FlashPlayerPlugin_11_7_700_202.exe, Version 11.7.700.202 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1628 Startzeit: 01ce5be816dda897 Endzeit: 0 Anwendungspfad: C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe Berichts-ID: ee16cb5b-c7e1-11e2-a56e-f46d04aeb530 System errors: ============= Error: (07/01/2013 00:32:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (07/01/2013 00:32:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/30/2013 10:44:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/30/2013 10:44:52 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/29/2013 01:25:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/29/2013 01:25:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/28/2013 02:01:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/28/2013 02:01:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/27/2013 01:40:52 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/27/2013 01:40:52 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Microsoft Office Sessions: ========================= Error: (06/24/2013 00:35:37 AM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_7_700_224.exe11.7.700.22451a67447FlashPlayerPlugin_11_7_700_224.exe11.7.700.22451a6744740000015000178f010c801ce703a52f1a9a2C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe3927ab28-dc55-11e2-9368-f46d04aeb530 Error: (06/23/2013 02:57:36 AM) (Source: Application Hang)(User: ) Description: TS3W.exe0.2.0.210e79401ce6fac87288fbf16E:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exe Error: (06/23/2013 02:55:59 AM) (Source: Application Hang)(User: ) Description: TS3W.exe0.2.0.210e7d001ce6fac5f617be59E:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exe Error: (06/23/2013 02:54:59 AM) (Source: Application Hang)(User: ) Description: TS3W.exe0.2.0.188e35401ce6fac31fe9ff410E:\Program Files (x86)\Electronic Arts\Die Sims 3\Game\Bin\TS3W.exe Error: (06/23/2013 02:48:36 AM) (Source: System Restore)(User: ) Description: C:\ProgramData\EA Core\cache\TempE0B4\{ CP_Guest_57524(4)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe Core\cache\TempE0B4\{ CP_Guest_57524(4)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe" Installiert The Sims 30x80070514 Error: (06/23/2013 02:45:33 AM) (Source: System Restore)(User: ) Description: C:\ProgramData\EA Core\cache\TempE194\{ CP_Guest_57748(2)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe Core\cache\TempE194\{ CP_Guest_57748(2)_ver2 }\Sims3_1.55.4.022002_from_1.50.56.021002.exe" Installiert The Sims 30x80070514 Error: (06/23/2013 02:43:11 AM) (Source: Application Error)(User: ) Description: OriginLegacyCLI.exe8.1.0.15564de4e4d1EACore.dll_unloaded0.0.0.04e446ab8c00000055c4a0c9de10001ce6faaa2410b1cC:\Program Files (x86)\Origin\LegacyPM\OriginLegacyCLI.exeEACore.dlle12c6be0-db9d-11e2-a3ac-f46d04aeb530 Error: (06/12/2013 08:00:53 PM) (Source: Application Error)(User: ) Description: Skype.exe6.3.0.10751715160Skype.exe6.3.0.10751715160c000000501023d9fa1401ce6795f2e18a48C:\Program Files (x86)\Skype\Phone\Skype.exeC:\Program Files (x86)\Skype\Phone\Skype.exe0551c5cb-d38a-11e2-8581-f46d04aeb530 Error: (06/01/2013 01:59:14 AM) (Source: Application Hang)(User: ) Description: spotify.exe0.9.0.133a7c01ce5e5ace7e3a330C:\Users\Chriss\AppData\Roaming\Spotify\spotify.exe1502d7b3-ca4e-11e2-9099-f46d04aeb530 Error: (05/29/2013 00:00:03 AM) (Source: Application Hang)(User: ) Description: FlashPlayerPlugin_11_7_700_202.exe11.7.700.202162801ce5be816dda8970C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exeee16cb5b-c7e1-11e2-a56e-f46d04aeb530 CodeIntegrity Errors: =================================== Date: 2012-03-18 20:58:31.489 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Chriss\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-03-18 20:58:31.489 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Users\Chriss\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-03-18 20:58:31.318 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2012-03-18 20:58:31.318 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 36% Total physical RAM: 8168.89 MB Available physical RAM: 5221.86 MB Total Pagefile: 16335.96 MB Available Pagefile: 13218.11 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.31 GB) (Free:69.39 GB) NTFS (Disk=1 Partition=1) Drive d: () (Fixed) (Total:736.2 GB) (Free:531.76 GB) NTFS (Disk=1 Partition=2) Drive e: () (Fixed) (Total:55.8 GB) (Free:26.85 GB) NTFS (Disk=0 Partition=2) Drive f: (RCT3) (CDROM) (Total:0.66 GB) (Free:0 GB) CDFS Drive g: (Sims3EP10) (CDROM) (Total:4.37 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ==================== End Of Log ============================ |
01.07.2013, 16:17 | #4 |
/// the machine /// TB-Ausbilder | Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Hi, Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.07.2013, 20:53 | #5 |
| Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Hallo, hier die LogFiles Adw: Code:
ATTFilter # AdwCleaner v2.303 - Datei am 01/07/2013 um 17:39:22 erstellt # Aktualisiert am 08/06/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzer : Chriss - CHRISS-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Chriss\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : desksvc Gestoppt & Gelöscht : eSafeSvc Gestoppt & Gelöscht : WajamUpdater Gestoppt & Gelöscht : Web Assistant Updater Gestoppt & Gelöscht : WebOptimizer ***** [Dateien / Ordner] ***** Datei Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk Datei Desinfiziert : C:\Users\Chriss\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Datei Desinfiziert : C:\Users\Chriss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Datei Desinfiziert : C:\Users\Chriss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk Datei Desinfiziert : C:\Users\Chriss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Datei Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk Datei Gelöscht : C:\END Datei Gelöscht : C:\user.js Datei Gelöscht : C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi Datei Gelöscht : C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\searchplugins\MyStart Search.xml Gelöscht mit Neustart : C:\Program Files (x86)\Desk 365 Ordner Gelöscht : C:\Program Files (x86)\Common Files\337 Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Program Files (x86)\Wajam Ordner Gelöscht : C:\Program Files\Web Assistant Ordner Gelöscht : C:\ProgramData\eSafe Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365 Ordner Gelöscht : C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Ordner Gelöscht : C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Ordner Gelöscht : C:\Users\Chriss\AppData\Local\Temp\Desk365 Ordner Gelöscht : C:\Users\Chriss\AppData\Local\Wajam Ordner Gelöscht : C:\Users\Chriss\AppData\Roaming\Desk 365 Ordner Gelöscht : C:\Users\Chriss\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Chriss\AppData\Roaming\eIntaller Ordner Gelöscht : C:\Users\Chriss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Ordner Gelöscht : C:\Windows\SysWOW64\WNLT ***** [Registrierungsdatenbank] ***** Daten Gelöscht : HKLM\...\StartMenuInternet\FIREFOX.EXE [(Default)] = C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 Daten Gelöscht : HKLM\...\StartMenuInternet\IEXPLORE.EXE [(Default)] = C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\ImInstaller Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\Wajam Schlüssel Gelöscht : HKCU\Software\WNLT Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamBHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1 Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\Desksvc Schlüssel Gelöscht : HKLM\Software\eSafeSecControl Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS Schlüssel Gelöscht : HKLM\Software\qvo6Software Schlüssel Gelöscht : HKLM\Software\V9 Schlüssel Gelöscht : HKLM\Software\Wajam Schlüssel Gelöscht : HKLM\Software\Web Assistant Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Desk 365 Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\eSafeSecControl Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT Schlüssel Gelöscht : HKLM\SOFTWARE\Web Assistant Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Desk 365] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{acaa314b-eeba-48e4-ad47-84e31c44796c}] ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16490 Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=WDCXWD1002FAEX-00Z3A0_WD-WCATR831876218762&ts=1372624427 --> hxxp://www.google.com -\\ Mozilla Firefox v21.0 (de) Datei : C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\prefs.js C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\user.js ... Gelöscht ! Gelöscht : user_pref("browser.search.defaultenginename", "MyStart Search"); Gelöscht : user_pref("extensions.incredibar.actvtyRptTime", "1339336378538"); Gelöscht : user_pref("extensions.incredibar.admin", false); Gelöscht : user_pref("extensions.incredibar.aflt", "orgnl"); Gelöscht : user_pref("extensions.incredibar.afterInstallRpt", "sent"); Gelöscht : user_pref("extensions.incredibar.cntry", "DE"); Gelöscht : user_pref("extensions.incredibar.dfltLng", "EN"); Gelöscht : user_pref("extensions.incredibar.dfltSrch", false); Gelöscht : user_pref("extensions.incredibar.dfltlng", "EN"); Gelöscht : user_pref("extensions.incredibar.dfltsrch", "false"); Gelöscht : user_pref("extensions.incredibar.did", "10657"); Gelöscht : user_pref("extensions.incredibar.envrmnt", "production"); Gelöscht : user_pref("extensions.incredibar.excTlbr", false); Gelöscht : user_pref("extensions.incredibar.hdrMd5", "E311E2E48C202C3BA8AEDA1D89369198"); Gelöscht : user_pref("extensions.incredibar.hmpg", false); Gelöscht : user_pref("extensions.incredibar.hrdid", "0"); Gelöscht : user_pref("extensions.incredibar.id", "3c1fa532000000000000f46d04aeb530"); Gelöscht : user_pref("extensions.incredibar.installerproductid", "26"); Gelöscht : user_pref("extensions.incredibar.instlDay", "15501"); Gelöscht : user_pref("extensions.incredibar.instlRef", ""); Gelöscht : user_pref("extensions.incredibar.instlday", "15501"); Gelöscht : user_pref("extensions.incredibar.instlref", ""); Gelöscht : user_pref("extensions.incredibar.isDcmntCmplt", false); Gelöscht : user_pref("extensions.incredibar.isdcmntcmplt", "false"); Gelöscht : user_pref("extensions.incredibar.keywordurl", ""); Gelöscht : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1415:25:56"); Gelöscht : user_pref("extensions.incredibar.mntrvrsn", "1.2.0"); Gelöscht : user_pref("extensions.incredibar.newTab", false); Gelöscht : user_pref("extensions.incredibar.newtab", "false"); Gelöscht : user_pref("extensions.incredibar.newtaburl", ""); Gelöscht : user_pref("extensions.incredibar.noFFXTlbr", false); Gelöscht : user_pref("extensions.incredibar.ppd", ""); Gelöscht : user_pref("extensions.incredibar.prdct", "incredibar"); Gelöscht : user_pref("extensions.incredibar.productid", "26"); Gelöscht : user_pref("extensions.incredibar.propectorlck", 77978201); Gelöscht : user_pref("extensions.incredibar.prtkHmpg", 1); Gelöscht : user_pref("extensions.incredibar.prtnrId", "Incredibar"); Gelöscht : user_pref("extensions.incredibar.prtnrid", "Incredibar"); Gelöscht : user_pref("extensions.incredibar.sg", "none"); Gelöscht : user_pref("extensions.incredibar.smplGrp", "none"); Gelöscht : user_pref("extensions.incredibar.smplgrp", "none"); Gelöscht : user_pref("extensions.incredibar.srch", ""); Gelöscht : user_pref("extensions.incredibar.srchprvdr", ""); Gelöscht : user_pref("extensions.incredibar.tlbrId", "base"); Gelöscht : user_pref("extensions.incredibar.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8vzTJdvB&loc=IB_T[...] Gelöscht : user_pref("extensions.incredibar.tlbrid", "base"); Gelöscht : user_pref("extensions.incredibar.tlbrsrchurl", "hxxp://mystart.Incredibar.com/?a=6R8vzTJdvB&loc=IB_T[...] Gelöscht : user_pref("extensions.incredibar.upn2", "6R8vzTJdvB"); Gelöscht : user_pref("extensions.incredibar.upn2n", "92824511485857859"); Gelöscht : user_pref("extensions.incredibar.vrsn", "1.5.11.14"); Gelöscht : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1415:25:56"); Gelöscht : user_pref("extensions.incredibar.vrsni", "1.5.11.14"); Gelöscht : user_pref("extensions.incredibar.vrsnts", "1.5.11.1415:25:56"); Gelöscht : user_pref("extensions.incredibar_i.aflt", "orgnl"); Gelöscht : user_pref("extensions.incredibar_i.dfltLng", ""); Gelöscht : user_pref("extensions.incredibar_i.did", "10657"); Gelöscht : user_pref("extensions.incredibar_i.excTlbr", false); Gelöscht : user_pref("extensions.incredibar_i.id", "3c1fa532000000000000f46d04aeb530"); Gelöscht : user_pref("extensions.incredibar_i.installerproductid", "26"); Gelöscht : user_pref("extensions.incredibar_i.instlDay", "15501"); Gelöscht : user_pref("extensions.incredibar_i.instlRef", ""); Gelöscht : user_pref("extensions.incredibar_i.ms_url_id", ""); Gelöscht : user_pref("extensions.incredibar_i.newTab", false); Gelöscht : user_pref("extensions.incredibar_i.ppd", ""); Gelöscht : user_pref("extensions.incredibar_i.prdct", "incredibar"); Gelöscht : user_pref("extensions.incredibar_i.productid", "26"); Gelöscht : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Gelöscht : user_pref("extensions.incredibar_i.smplGrp", "none"); Gelöscht : user_pref("extensions.incredibar_i.tlbrId", "base"); Gelöscht : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6R8vzTJdvB&loc=IB[...] Gelöscht : user_pref("extensions.incredibar_i.upn2", "6R8vzTJdvB"); Gelöscht : user_pref("extensions.incredibar_i.upn2n", "92824511485857859"); Gelöscht : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Gelöscht : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1415:25:56"); Gelöscht : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Gelöscht : user_pref("extensions.wajam.affiliate_id", "6447"); Gelöscht : user_pref("extensions.wajam.firstrun", "false"); Gelöscht : user_pref("extensions.wajam.log_send_info", "false"); Gelöscht : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21087\",\"supported_sites\":{\[...] Gelöscht : user_pref("extensions.wajam.no_trace", "false"); Gelöscht : user_pref("extensions.wajam.server_current_mapping_version", "0.21087"); Gelöscht : user_pref("extensions.wajam.supported_sites.amazon_product.priam_se_js", "try {window['APP_LABEL_NAM[...] Gelöscht : user_pref("extensions.wajam.supported_sites.amazon_v2.wajam_se_js", "try {window['APP_LABEL_NAME'] =[...] Gelöscht : user_pref("extensions.wajam.supported_sites.ebay_product.wajam_se_js", "try {window['APP_LABEL_NAME'[...] Gelöscht : user_pref("extensions.wajam.supported_sites.ebay_v2.wajam_se_js", "try {window['APP_LABEL_NAME'] = '[...] Gelöscht : user_pref("extensions.wajam.supported_sites.encryptedgoogle.wajam_google_js", "try {window['APP_LABE[...] Gelöscht : user_pref("extensions.wajam.supported_sites.google.wajam_google_se_js", "try {window['APP_LABEL_NAME[...] Gelöscht : user_pref("extensions.wajam.supported_sites.imdb.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'waj[...] Gelöscht : user_pref("extensions.wajam.supported_sites.yahoo.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wa[...] Gelöscht : user_pref("extensions.wajam.supported_sites.youtubesearch.wajam_se_js", "try {window['APP_LABEL_NAME[...] Gelöscht : user_pref("extensions.wajam.trace_log", ""); Gelöscht : user_pref("extensions.wajam.unique_id", "624984ED3903271FE8DA433465F31974"); Gelöscht : user_pref("extensions.wajam.user_current_mapping_version", "0"); Gelöscht : user_pref("extensions.wajam.version", "1.25"); Gelöscht : user_pref("extensions.wajam.website_version", "1.00273.0"); Gelöscht : user_pref("keyword.URL", "hxxp://mystart.incredibar.com/mb155/?loc=IB_DS&a=6R8vzTJdvB&&i=26&search="[...] Gelöscht : user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...] -\\ Google Chrome v [Version kann nicht ermittelt werden] Datei : C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [19973 octets] - [01/07/2013 12:42:58] AdwCleaner[S1].txt - [18301 octets] - [01/07/2013 17:39:22] ########## EOF - C:\AdwCleaner[S1].txt - [18362 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by Chriss on 01.07.2013 at 17:44:48,41 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-506466755-524257423-1559524001-1000\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys Successfully deleted: [Registry Key] "HKEY_CURRENT_USER\Software\Microsoft\internet explorer\internetregistry\registry\user\S-1-5-21-506466755-524257423-1559524001-1000\software\web assistant" Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{00191DF3-62EE-4B14-9C93-6BAAEF21FD5C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{00C24C35-27DD-4B4D-A47D-C68BF7C46210} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{01007CA4-BABA-4C25-8337-A2D30F7B749E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{010966D5-4C13-486C-80B5-44117F9DF83D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{017A2E63-8E59-4C63-8DAC-D9F6EE75F068} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{019D4AF8-E303-426C-8766-BF019FB12513} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{01CD4684-A525-4EB5-AA72-E435EB9D9908} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{01D3FEFB-5C4C-4820-8484-5A702AAC73CF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0212858A-4BF4-4DC7-B7F6-BCCD20E2FC01} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0233B0C5-EAC7-4EBE-94FD-32F0F2F0EC16} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{024EDE84-072B-4B60-96EC-D4EF72BEAA70} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0286F635-3B7F-425D-B8C6-461BC4483588} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{029D39F7-1549-4E73-AAF3-212384416072} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{02B2879F-0ED1-4843-9C5D-FA6EA0378E30} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{02EFB06A-8EF9-4365-AD85-0DBF6E1B1EA6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{02F67167-CB1E-4A25-83B2-DC268DC79B6C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{033450F2-8E9C-467D-B6CA-01E15F68F8E3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{03FF7788-9BEF-4FCA-B32C-EB9AA56951F0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{043E43D2-BE5D-4B0E-887D-A79D35CD59D1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{04A60687-B343-4C5D-BF1D-CB19149CB533} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{04BC57FC-6E18-4DC0-A9DF-41AE6CF87981} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{04D9C7E6-F98D-4864-A40C-16483035E7EF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{059F5A77-58E2-43DE-AD88-2B6DBC8C73B5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{063C12CB-A0D5-4DD5-B2ED-BD6C432BC8D6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{06DC85BC-7AB4-41B4-8066-A21800EC06A3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{06F3DDEB-BF3C-45DE-A233-60A5A628C813} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0707F9F9-1BB2-4AB9-AA99-F8D23E3FA5F6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0806C793-9B22-41AA-A4BE-614950601117} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{08269FEF-F0A6-49EE-A443-7E0C422D5206} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{08395CD6-CCCE-40D2-A446-6E920A5AB6EF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{08BCFFEB-156A-41B3-A22D-9ABB3879D5BD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{08EF82E8-6EDE-446B-95C8-6BB19C802B03} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{094BECAF-EDF3-4115-92CE-E8CED8DABBC8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{09836D2B-EA47-4B34-8092-54DF312801D2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{09968811-81FF-4B6E-A9F0-1A8DAEF4CCD1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{09B0D10C-053B-4ED4-8AFD-5D6A7F7731B7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0A298BC6-91B5-4D3C-B04E-08C6E569B432} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0A3F8CA8-B0EE-4E7D-8F9D-0F19750E9DAB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0AFDE874-20BA-4906-A323-BED008FE1F64} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0B1A2D3A-C036-4B4F-BA1F-FE5F8EBD3343} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0B56B9C1-D27F-4F72-81C1-C2E862F50726} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0B6FED00-99F9-4250-BF95-975FA2BDCB20} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0B76BAC7-1BA2-4526-8DD4-DAA507F5AF58} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0BD5DC83-A691-4410-A98D-581A8D209885} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0BD82EA9-7F94-4D59-83AD-3152F40AAB40} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0C570CA9-CE02-47F3-AAD8-2E543C53FE53} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0D0C2A0E-E959-4C88-9EAF-A763C5F8D250} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0DFDD057-4767-4FD1-ACD1-ED68C0D5A7FC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0E9293E3-B333-41EB-9506-D1C14B070335} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0E9C7F81-D42E-4B3D-BEF5-640CCEDE97D7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0F8C1581-CBF1-4C17-9588-9436DCB00AC0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{0F95BC29-B590-4368-94A9-3A9E893CD9CA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{102D15B2-026F-46A6-8779-1A8E23BDCBEB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1032B557-2F1F-4435-948F-94F8A72DE357} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{103DE592-0139-4696-A2C6-B8F510CBBA2A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1046E998-36D6-40F8-9F99-AED8F1995AA3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{105B0BF7-A8C0-4E6D-AE14-BBDF760C208A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{10640E96-52F6-46CA-AFF0-D96108A01B2B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{10985AC2-0D0C-498A-8680-E7EF22EC8D40} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{10A160DC-B979-4FEA-A40B-7957D44919ED} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{10A99CEE-3B85-4320-9C65-CD8F3AF03DE9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{10F03D5A-8F68-4EF4-9D9F-5EFE559ACC49} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{111ECCBA-0DB6-4064-9834-995851347445} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{11284898-B9E7-404E-A7BB-F8BAC86D8E23} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{11546788-7F6A-4F50-B1FA-83FF5D8328B6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1196CDED-387B-4CB2-BC1D-6EFEF613C87E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1261B6F5-4F6E-45CF-A19B-836FF3C26B3A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1322881D-E55E-4F33-9217-B072A791F0D5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1372D759-4F03-4743-B3E9-EA8037FE45AE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{13A6DFD8-B806-4E0F-86D1-EDC4922A3A1A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{13DBE396-8A46-4C70-99E0-C23D3EC917F7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{13EA6360-AD1F-4A3B-A1FF-519DCBC51752} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{14CE244F-5536-40A4-9302-3BC11DFFF769} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1524AB45-6426-4BFF-AE8D-50BD716FB705} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{152F06C5-7EF9-4E51-99F5-BCA4240C4B99} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{15F5E9B0-AA2E-4061-9281-C8B7CA5A5CF9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{166AF88C-8700-405A-A381-6CD6D3D83BDE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{167B6DDF-07C4-4427-A961-E8E4A6C24D76} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{16C7B210-4436-4D6A-B583-E66A409A6AA2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1767D1E3-0BE1-4968-947B-6FE0756B6A6A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1770098E-2CD3-427E-8C92-03BDA33FC8F2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{17A7515A-F898-4C36-8B72-63503DB76C6A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{17E06F1C-77A8-4518-A76A-B909BECAE31C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{17FF0FB3-CD25-434D-90CF-E59FE2CED0AB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{18234343-7ED8-4F7B-AD61-F7FD765451FB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1839147B-EB1E-44C5-AC65-02B64F9A31DA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{18A6178E-32AD-4F8A-BEB9-97CCF5EA75B8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{18BA5479-45F1-48A2-A817-494D5A5250E5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{18CE0AE5-6877-4613-8BC4-BADD58EBE2CC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{196A0EEA-A608-409F-9197-132B69AAA737} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{19C7BB9B-C454-40CA-9953-18F8CBE07630} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{19F7F1A4-33F1-49A5-BA0C-DBBF83B6992D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1A7EE6FA-E224-4C83-A8E2-03811BD1772F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1B076659-636B-416F-BFF7-563248390896} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1BB87126-3B97-4B1C-B538-6CDAA433A55F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1BCE3695-2879-4395-AADA-623C6D818898} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1BDC22BF-FCE7-4341-86D1-1BA5FEB3A18B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1C699069-3711-4A3B-89BC-39C22F1425ED} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1CCF2507-E8AE-4F7E-9FA6-E31CE6D3F16B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1CE7E36F-00E4-4343-9837-FFFA2B68B1D3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1D104B97-064E-4206-BFA1-3F093D7D9BD5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1D4B569A-C677-4DCA-838F-2155094F1EDB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1D56B83A-B721-4264-9BC4-BE00A8369AA1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1D7730FB-DD7C-4B2A-9AD1-24879D217BFE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1DAB1091-58F3-48D5-B4A8-30728821735A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1DCBB7F7-85AC-4271-A1CF-6233ACD06180} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1E13D4D9-538E-4C91-A416-5DE880BA231C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1E2D89ED-4CBF-483A-8E6E-C3243B57D93F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1E4B775A-7A2B-42CF-9A28-32A0B805B734} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1EAAB2B3-049A-4667-8A56-013FAEF17764} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1EC2DEAE-00B9-4BB1-AFEF-0CF0D8495D9A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1EE2123C-B2C7-4E79-B72A-021CAD784700} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1F729511-37CC-4488-AED3-DDECED80D436} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{1FDC18B7-3B8B-4947-BC9D-557BB0F11F47} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{20ABE59B-DB1A-45AF-A3C2-4251BC7D5D8F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{20E5588F-0706-4987-B493-2BE6363FDFB7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{213DEF63-1CF3-4D0F-9577-C03B5B7F7E67} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2161F28F-691F-4363-B756-D8688F3D9AC3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{21C8D4A5-29ED-497E-9536-F5FDC8466D68} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{22275596-2B3B-44AB-8730-8FEDDBFB73E5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{22C006DC-599C-4F22-A8C9-BDE77A7FE0A8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{22D27025-B0DE-4DCF-A8E2-0B9D977FC6D5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{233FBDF4-5679-45B4-A7F6-FC8CD18F18D5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2376F651-B76E-4DD4-9DE9-E2964DE96116} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{23835C8F-CCFB-49F9-823C-14F1164297B3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{23B5B55A-E9CC-4636-A7E5-BB4F261182BC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{23F507A3-EB2F-458D-A650-3B36A9DFECA4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2478E816-AA98-41C4-A855-8C3DF0F79078} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2508EF05-80B8-4DF9-924D-EE07C02C828B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{25F5BACE-F7AE-485F-B472-2190DADAE562} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{25FCD51A-67B4-4777-9F7B-BBFF1A3AEA5E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{26314AFD-1FEE-4DC4-8BA0-21FCD82D4B8F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{26763255-5913-416B-B0A4-F68F6BD25B64} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{28557993-4DB4-4B78-B918-9063D16F3F5A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{28576011-E273-4C27-A923-F4915238A5A8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2878AC42-C73F-4028-8BDA-6C43DC522FB5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{288D3AEE-99C7-4B49-BB9F-94AEE48A0A1E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{288D6672-BEE7-431B-9343-04E3D51B6061} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2925A186-BEAC-4815-920A-84198BC51253} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{29460E6B-00D2-4B06-975F-3F45AC18A8C7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{299E0A80-48A6-4C1A-9148-98E65993300D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2A292E77-A1F4-4D08-B3DE-65905583B475} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2A632F69-892C-4785-A848-57BF1F1FDA3B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2ABA863F-6E2C-4F90-ABD5-70178ED85C34} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2B026351-7BB5-4209-BD6E-F3A89C367DA5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2B4820A7-5F2E-4F4D-8B6B-2DE3A10B5752} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2BD4A2F4-F1A3-4BFC-9A27-71506A5B6879} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2BFCC925-7B9E-441C-90E0-A77E23C745A3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2C1A6918-5B6F-48FB-8797-F7BE942BB9B2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2C3BFB34-910B-4FFD-B9F9-314CB9C88D8E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2CBA37F9-A095-430B-AC16-845D746FCE82} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2CDA376C-C268-4DC5-B742-E866DB5A14ED} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2D0A52C3-15D5-45AF-9C9D-CB69F3498B07} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2D1C4540-AE5E-4CF4-BE9D-475F85AA8AF4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2D338502-8417-44C5-AD70-9105551C16B3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2D50150A-1F32-4B8D-8D72-62329A90C227} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2D96C4FA-4BEE-4DE5-91B0-B6027E86D62E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2DD2DEF0-F7B8-4E4F-8E11-DF5943EE81CA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2DDAB696-3A74-42B2-B96C-42EB005A7160} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2DF7ED88-7631-41F2-A129-8232AE081E9D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2E30C5C5-A7CB-431F-B98D-30F9D55AB61C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2E59E75D-1BA9-42B6-9B12-7F9F92B9C385} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2F14B02F-77B5-4714-818F-25E4D111E286} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2F7F0183-77F3-4C49-8A96-0D31839F38B4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2F95F767-2192-4B6B-9B25-D822A1AE5CF7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2FBAAC1F-3250-47DE-BAB8-22617C17CE1B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{2FDCDFFA-4AE1-4477-9B40-5B4C0439F7CC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{30127CA3-10D1-4D42-B2D0-036FBAD5055F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{308F9FDA-60FB-4EE1-BFF6-1E37B484BA7B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{30F9C072-5FE3-4D6C-861C-F3DF8E24705A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{31244000-052C-4A0A-A8B3-4ECA832B9C75} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{313EC5D6-FE5D-445E-82EE-528784C3DEC9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{315D07D9-BC7A-486C-9463-7104ABED1197} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3184F804-708F-4F26-BB23-C51E9B5DE34C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{32067EF9-3D81-41BE-8865-3D1374ABD6B1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{322A8813-5895-4C59-8A45-6EFA77D431C4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{32CB5950-9E11-42C5-8FD9-9821CB2F7890} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3355BA65-1203-4D45-B859-6498F6B74539} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{33DBE1E0-2159-4F2D-97CF-4B7273E440FD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3404D9FF-F1FF-4E8C-82EF-779FC6ACA250} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3467D0E6-E248-4F8E-BB3B-C7F428E514D8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{347197D1-A6C9-4DE4-A974-03B7A9E6931A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{349C0CEF-548B-4E3D-9849-4A373ED6654E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{34CF2994-3AA1-4D86-A003-21F0656D28E6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{35843DBD-CFC1-4AD2-9A84-09984CFA585E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{36835D37-9B86-49C2-9E66-EF33ADE1BBE3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{369C45C8-A9E4-49AE-B115-660D94E70396} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{36B22346-9434-4D65-B128-ECE6FB86AD13} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{36CCDE7D-23A9-4D4F-9EE2-A72DF8774579} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{376A5301-1D9A-4204-8293-EDA2FF32F3E2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3772B2D3-DC18-4AF7-B218-BD62040DD5A7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{38BA5863-FE24-4091-BFA5-8A516BDFF031} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{39A74C74-E9E3-48E4-83D1-2EAC4553B689} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3AA76943-D100-4EE7-97F1-D00C4444910C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3B5A1CDA-DD11-4DF0-8AF5-E5F23E27CE51} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3B8CAAF4-EF82-417F-9B35-009AA45F84D3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3B972F37-3EF0-4771-9D9B-60514A793728} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3B9C4EAE-847F-4399-AB8A-17C0B36E0723} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3BFEFA0D-CEAB-4CD2-A820-601D797A41C3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3C44BAFD-8069-441F-8AED-1C4522A0DD99} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3CBB033C-197E-45F3-BE2A-A1F121D506D3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3CCD6857-F0D9-480A-B4D9-CAA177C7E5E2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3CF59F8C-86A7-4125-A3B3-DB6930576048} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3D4225B5-E6CB-4180-81E2-359B91AB246B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3DEBB15F-58A5-4B8F-9964-66B789A87373} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3E02F023-B8E0-498D-B187-5C8AE1B7A35F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3E611A42-F2C1-4009-9A1E-1D10FC28BC73} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3EAFDEC5-EEE5-451F-824E-451D37C3518E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3ECCC80A-788B-41F6-AFA3-AAD02AEE1079} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3F62924B-4A2E-44A1-BB39-5C0B2CF7FEA3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3FD5F7C9-EFE7-4417-8573-603943ECA567} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{3FE5C151-B57E-4526-BFA5-5236713017C5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4097C5C4-487D-4F47-9D53-78D0566134CE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{40EA23B4-8D8F-4291-9105-D83EE7B0917F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4117826B-76CE-49BD-B44D-9401777ED51A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{418A9508-E2B1-4A75-9E33-635F7914EDA4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{41FAE8D9-B1AA-4B46-8EBD-BBA2BED4204B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{433ABB8F-D49B-4601-92B1-5B1C5DF350BB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4354C726-3984-4559-9D92-8A9ADAC4AC26} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{439E7C8C-6056-49DE-A19A-F1CA9FF08E6B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{43B6B59B-8966-494D-B6BD-94FBD8CA77EE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{447D726F-7F6A-4CB2-8991-94DDDB1FA4D2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{454357DB-AA3A-4993-9F62-5587972B15A9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{459718AC-73C0-4CDE-870E-CF673B06F90A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{462CA187-0DEE-4C4B-AE26-B0A995777848} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4657B749-14E2-49B0-86F3-4C8C776BC8D7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{46E1D331-0E79-46A2-9997-9B34E5FC8784} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{477AA90F-3B6D-4634-A2EE-C4D4C1B435B4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{47B3200F-19D8-47EB-A4E2-5CEFC5C2EDB8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{47E5A0C1-0F5C-45D6-85B5-231EF5173721} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{480026E8-D5F7-467B-B04E-C4619B6A1F3A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{48204BFB-6B67-4F2F-AD88-BFAE3F5D5917} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{48372323-CE3A-4977-A3F5-96881D85C09E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{488257ED-169E-49EF-B9E5-23213E8D0CF9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4970F7A3-59B5-42E9-A411-ACE2D1121EC9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4A393EDF-26BA-4FC3-8282-A03AC83D27B1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4A52DAE8-D282-4668-A001-206DBA816FC7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4A7E2BBB-F33C-44A6-AA2A-BD0D9A1C73AB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4B6F2375-F13B-43D1-958C-C5B02FD13FEB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4B7BA00A-0F6F-4E67-BD78-C9CF9C7B187D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4B958085-60E3-4CA7-9C91-F821596A1502} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4BBC1868-91CD-49AF-B8CB-C02C7BB5AB32} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4C500986-A8C5-4F6B-8C7F-65D17B2C22FC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4C8AF44D-C440-4636-9DD2-26E38EDC4C46} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4CAC9472-D0E1-4BF3-9180-0C5350535B06} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4CBD73AD-686C-4256-8D64-00750DD4EA8C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4CE8E173-3780-469E-A25C-3321FEC5CD17} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4D5FFE6C-37E7-4F45-9593-A847C0646D49} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4D625526-F6BB-4591-9E9B-8C3AFC55D365} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4D7C2B25-1BD3-43E2-86E8-85841E7F3746} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4D8F380E-CADA-44E8-805E-74540DC6AE40} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4DCC0E21-1FBC-46FD-8A42-8B4E509530BE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4EED5E48-78F8-4BFD-9C36-1EF49DA09FDB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4F068B15-2A10-4C54-8537-60741D0083E9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4F4976CA-E25B-40D1-A36E-9BEB2DB697EC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4F4CD7FE-51D7-408B-B686-79B44FC9EDB4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4F5AD5B0-FA6D-4857-AB9A-28627017C822} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{4FDCE05C-B353-4E9F-BC2C-0F7C03A0DA25} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{50AC950B-264A-4FFB-BA2E-6E2B8841E98A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{516DFF72-DC67-4A25-8F72-F2C187D8F6A3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{51D091EA-CEC5-4AAA-8E26-8AE314C2653E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{521E996C-FD00-4099-B197-53EDDB95D113} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{529287D7-A1E2-463C-AECF-BAE70AFC8D21} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{529AFF4C-AB1C-4F1A-8BE7-8F5E512DA2AA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{52FD16EE-1DC1-4EF4-83B6-8A23155210D7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5359EEAA-F34D-4814-8B6B-CB9E697FBB9F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5398FC72-303A-4FCA-BDB5-81A4846C0894} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{544CC74F-E047-4F2E-8B17-21AB5656AEE2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{554B99AB-9D46-4F3F-BDE1-F81798011F57} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{55E8E9F5-5A0C-4A11-B982-E23FA3246609} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5608A35E-D127-4177-9A9D-B2DA14124363} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5630E7F0-5C79-4D27-9744-E8B74F3351A6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{563185B8-C2FC-4A13-873B-9B21C185F0C9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5648D9EC-1784-4C4F-8C40-527155D76869} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{564EEB50-DD19-4745-AF2F-D8179D513658} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5651E44F-BAF9-47D4-9E9E-B0CAB2E2D86A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{569E9BD6-ED96-47EB-9609-2263E97D0C38} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{56F46408-D7CD-4290-BB11-8C6246BDC3F5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{57620BB6-C6FD-4199-9D9A-7DD3F5C4FED8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{57A06ACA-D136-4A91-9C37-FAFD3E8C597D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{57FED0F0-48D6-4A32-969D-B6BB1CC556CD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{58141009-EAB2-4BF1-BFF2-F289CFB43720} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{58FC2EA2-7BA5-403F-96FA-F2D93B114327} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{58FF8683-F956-4E46-A179-9008AD56B9E7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{592D178F-4200-49BD-9831-CCF1832D6A50} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5949A48F-2116-4728-BAA7-CDCECC8EB2BD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{59567B23-66F9-4CFB-9EE9-D1AC5BC2B2A8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{596B3972-9371-4139-8133-EBC1ED91D7DE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{59BE8235-50DA-4CEF-9F37-8354EF5572EE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5A50999E-583D-4E6E-A6A2-D4E33A6D8796} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5A898BCC-B3CE-46F9-AC9D-5653DFF75EEE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5AD1EC4D-20FE-44A0-8E61-2A14BBB58B7D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5B61E476-6578-4749-9056-D891251185B8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5BF90E5E-5A6A-4D0A-B0E4-F20B0564B2F7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5C5CC953-13FB-49C4-BD70-AD27EB672190} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5CB51F7C-6C39-42A7-8959-A61434228374} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5D03D9A2-F17E-4073-ADEF-45BC4ED2272A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5D523E6E-2BE8-4BD1-BEC7-4B24E3707478} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5D93A1C5-9BAE-4BE4-908D-E5D854994589} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5D9F4421-003D-42FC-A314-876969B6358E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5E446118-A104-42E8-8850-F80E1BDF305D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5E4EB600-2696-4F65-ABC2-8239A4FB3EB1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5E78464D-5C61-4112-90E8-22EE4F6A5FF1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5EFE49D9-4ECF-42A3-8CA2-A9097D5660FD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5F021333-C7C8-47AA-9592-5F23BE64225A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{5FDF937B-25A5-465E-8C9A-7D88A186A50A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{601B969F-4D26-42D0-A490-530F0E09A990} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6115A21C-2B76-4907-AFEF-042042B47595} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{613010C0-316A-41A6-871F-10DF339E8371} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{61355CBD-A361-409B-8812-BFE4A04AA00A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{613C9D8F-0835-4D9D-B8AF-6F1DA6E19684} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{61577884-1385-4D83-B15D-C7FE22EAB003} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{619EDECB-1FF7-4895-BDA0-6D71735BAABC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6212ECF2-2CA3-4221-8841-AF89C7ABC8B2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6218E093-5629-438E-859C-BD563C64CF86} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{62477CB2-973B-4CC7-B2AB-E2E91C42C99B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6272ADE1-04E8-4F1E-B538-FA894BD08946} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6281CA68-A6F4-410F-909F-53FB3F76A233} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6286A3F2-FD26-4406-AF44-D843A33C7846} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{62B65952-D299-4077-B49D-877E8F1C4771} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{63602A98-071A-41A3-B154-9F8270D62064} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{637FC0CE-19CB-40D1-A904-0D03A82B3538} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{63E46392-E45B-4ADA-A3C6-52FD7A68D0AA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{642A8CA4-3510-4050-9A05-B3D8403160C8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6473F54F-3341-4359-9C24-F45D28E5DAE7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6475530A-17D2-43FF-974B-B06A8C1B2480} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{64E045EC-BBF3-495C-8AEE-73864708A9EE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{64FC34CC-B86F-49A3-BBB3-8C49B63BC099} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6571E687-8156-46CD-91AC-1647B2C19562} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{658F37D6-FEFD-482D-84D8-E6A011F028AB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6590B01B-2137-41D5-AB23-D1988437F742} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{65B4EC0A-D489-4684-ABD5-A01E0287CA39} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{663A30B4-9B8E-4ED6-BADA-BB5F0D9D4D8C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{66AD5AE7-6390-4D46-99E3-384EB89003DC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{66C15E41-CEDD-4159-ADF5-16CCE30CEB94} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{66F08CDF-ADAB-4D6E-B487-19E8A543C46D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6716255E-EA61-446F-BF9B-6621ACBD36F1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{672CF1E4-610A-45A5-A5EA-3CA3476611A6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6781C587-4B86-48C9-93C8-30F16E237648} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{679DB12E-3A26-4A7B-9483-BCD3846C035B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{67CDA758-C522-4420-B6A1-D25DD8B578E0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6881FFC8-0171-4655-9419-DF6D43637CFF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{68A5DAA3-0641-493B-8DD4-C2A9596D1646} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{68FD52FA-71E5-475E-AF78-A429276011BE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{69A84D1E-6635-4915-829A-8D60DE0919A7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6A12E5CF-3BC8-46F3-9AB3-CC799E99B500} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6A1EDE35-9F31-4D1B-A176-36246A45F9D5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6A2D46C0-F8C0-4832-87E0-E23B208FAA4B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6A6C2DDA-01DA-4B68-B75F-6CD6574D3A09} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6AACC971-8638-4A37-AC40-131A8474E46D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6ABD6AE8-73B8-4F72-9EB2-F3FE7833DB74} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6B5C8E3A-A3D7-4AE2-932F-3DF8CA24D6F0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6B715D08-3CC3-4B04-84ED-4D8842C4653A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6BC51986-7EA8-4E0F-8023-B6468E0722BB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6BDCE8CE-4E6B-4EE9-82C6-4FC3F5C3F8AD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6C9EBE24-8739-4B3F-84F2-49B2F8870F08} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6D7F90FE-9FEA-46E1-BB47-2C132895E065} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6DC2E79E-BBD2-4E6A-9718-1311E445B056} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6E1D9019-9BAE-4E67-A421-FC0D006BD760} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6EA5AFE2-F9EF-4AEB-8A2A-BCDF757132D5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{6F60632D-8E16-4C8F-8270-2469072E898C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7038F7F6-6178-419F-8B33-5DCCFEA49CA5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{70C32BE5-1C62-4021-85F1-E80E37CC3EB4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{71172B7B-7EF3-47E4-BEDA-554B6A487C4B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{71AF1A23-E106-4352-8470-547B44C98ABC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{71BD1DD5-657F-4515-9026-A4E189275705} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7207E673-584F-4656-AFBE-E6A70C08502E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7258C097-4E5F-4668-AE87-CFF6BE0B0A34} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7274E65E-5C10-438A-A2D5-104F65145DFA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{72A70AC5-AE95-470B-AC34-7A7EBF1F38F2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{72F135F6-DAE6-4291-BC87-2A7D5251B4B3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{72F2C335-4636-4982-8CF9-DB85E68E8EE7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{72F91FC3-F65F-4C3C-92D8-6BB397B97A2C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{733361FA-24A4-4AF1-83EE-DA08A754FEF3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7342B247-261D-40D0-8517-FE00AA570034} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{734A6A87-E440-4CB0-BB8D-D05A601C99A9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{73A06A78-D634-41D7-BEC4-12D3F6FA1E8B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{73DCE9EA-E1CE-47F8-96FF-C35B75998AB8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{742371B8-004E-448F-84B0-69087F139806} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{74F5845E-DC43-4052-822A-82CA45EC14A5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{75778706-9CF8-4700-B848-5E74E0A3220C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7692CE27-9C3A-42E2-ADA8-947799890C7B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{76DD0190-B191-485B-9202-4F619E711A02} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{777B2EED-F15C-4343-B73D-01777E7CE80C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{784E5191-7A12-4614-820D-80FB849199F5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{78FD9056-19DF-4EB6-A871-3EE1FDC7CFE6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{795AD5A0-3F1E-441C-8AD8-471A7BBFFF2B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{797EDFC3-8209-4DF3-BA9E-B3FA38A71B16} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7B320857-8AD9-4172-9096-B42B141BB471} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7B9AB857-519D-4EAD-85DA-ECE4079EB87E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7BBCAEE7-F7DF-4D26-A1D2-ADB5F2EBE97D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7C504759-B625-4FB0-9447-55C5E0A95BCE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7C6037F1-1704-400D-A9C7-4F28AFF7988F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7C951765-8E6F-44C2-82D8-1DDD0D5FB230} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7D05DC0D-5C81-4C4B-8AE4-5047D7C159DE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7D6674FB-6F65-4A1A-898A-E4AA36BA91CF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7D67C7ED-BEE7-4232-A391-6C80F1C10FB8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7E5D7C9C-3109-454B-A05D-D7DA74864BEE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7E886E31-6857-4194-8049-B7253F7ACF55} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7EE20408-E43A-40FE-9260-7C72E6437E0F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7F5A708C-15DE-497B-B107-C654529E97DB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{7F6320AB-7759-4617-BEE7-D15F98B389EA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8088E006-0FCE-4DCE-A11C-8F8A54914407} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{818D5577-D028-464C-9304-18F73F795493} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{81BEAC39-B19A-41D0-8A92-2C17FBDF0B6A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{81FB16F4-C986-475F-89B4-473CD32E10B4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{822D3565-FE94-4F7E-B6E5-89D6C95EFB0E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8264CCAE-CA67-425B-BEB4-3F11F41443CA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{82B0CDB3-5721-46EE-B54C-51FC37518310} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{83A520EE-5403-4AE0-B420-80A42A2FB685} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{84616EA1-D5A0-4D33-A7E7-13F9AF11C0B7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{848B4ABC-2F12-470C-85DA-43E17D297BD5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{84A8590D-22E1-44A3-890F-13D48DA63AA3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{84C43C99-A9D3-48C2-8486-A90203AB23C8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{84E3ACEC-5A1D-48FA-B371-40DFDD09A562} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{85A00E69-69F0-41A6-A99D-05C029159F27} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{85D13E7F-99FC-48AA-984D-66D64BCFEA03} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{85FE202E-0B35-4014-81E0-E218AA8B67B1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{86E72CCD-74B2-4E29-8C9A-119E6B18EC5B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{87762D53-FD0A-43FB-BD6B-FA9C34EBD496} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{88141E7B-AF4D-4822-8843-0590A4550EF4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{88398B6C-1CB8-4964-B320-2467296098DC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8912F327-910C-4A34-8200-CF18D63936A8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{89896447-78F5-41A3-907C-CE356DA47044} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{89980135-1199-42E6-A35C-3609C8B8E5EF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{89F15F78-6204-4248-9B91-BB5F8253F555} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{89F6ACCA-5792-4CD6-9E4C-0ED89C40BC19} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8AAD33D4-B0B1-416A-80DF-5D8DB10167C3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8AC6440B-2C58-4699-9B95-98180C3618D4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8AD690E1-33CD-4084-AEA5-72002330E189} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8CFDF29A-BCA3-4936-8041-F80158DBC8D6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8D2968CB-4438-4336-854E-68E53C653D64} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8DA7ACD7-E848-478D-84C7-03833248606C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8EB6563D-EEF1-49AF-B446-F73AC4E1B7B8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8EBDB8D6-8890-440A-93BD-5AB90C02AA7E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8EE5B6B4-EDD0-435D-94E0-AA27802817AF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8F75C408-BF37-40CE-92C1-799853D94996} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{8F953FAC-7F53-449C-8851-6B0F69C83811} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{903D0480-8BA4-4449-A1C8-81D2384D5226} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{90589F6F-F622-4028-96DA-414A20A41A4C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{909F9862-6192-42D6-8F63-622FAB53DC14} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{921E2E16-43A6-499C-9C1D-2023B8E1CBDD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{93DB9878-BD69-4B2F-BCBA-DA8BE7CAEE0C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{93F3949E-B17C-4F6C-9956-2BB036F4F015} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{94BAD366-4392-425A-A0C1-212CCD84B82A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{94DE1654-EECC-4C4B-B8F4-E3BC8C2CE9FF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9522295F-7318-4EB6-8410-6D82EFFB3C57} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9553E008-CC5A-490A-837C-49F94733BD75} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{95FD3963-1EC8-445F-A5F5-D97CCF815EC0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{960404BC-964A-45FD-9EC5-ECA1D7CAC770} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9635AFBA-2B5B-4417-9FA6-ACF8D08E6F9A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9650E8BF-8772-48B0-BC78-694F76ECE74E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{96675948-8ACF-4698-B34D-2600298CE9BA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9715672C-800D-4DA7-AD72-9C8224A124A5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9740D992-C0EE-4316-88C2-6D2A68930BBF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{97548C7B-57F4-4A87-A282-D2AD2C21F506} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{975861CB-0B4E-4F96-B88E-FF183DCC08FC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{97A1A338-8A1C-4347-A9FD-BCD0162B515E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{97A6220C-754E-4955-9FB8-4E5BED5E99AA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{97D19870-10D7-4C3C-B4E7-93C0A3CD29AE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{98448CEF-3FA9-4BFC-9C64-642E24EC066E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{98745C26-A2F1-4B92-93B0-3D2AEDD634B5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{98B8933B-142A-4FF4-9489-12ED819540FE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{98C1268A-311D-48ED-9B6F-D2036047A1DD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{98D3F06C-D2AC-41ED-8242-C5E40113F404} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{991BDB0F-B62E-483D-BA2C-C610F5BA2B2B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9941385C-10B4-44B9-90EE-CCE5EC5C62E7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{99495099-6E57-4F57-9FA3-B508D25306E1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{99CA3940-1842-41AE-B7B3-97046DF93DE4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{99D3793C-68FC-4DA8-9FB3-8BF92663D2F2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9A5006AA-A7B1-4A02-8D2D-9B502B2387CE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9A889C44-BFD8-4275-8CB6-6D11E0D85C04} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9B42D455-ACAE-4AA4-962A-F5D154D2BC0C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9BB50B61-76D6-48DD-AAD1-3DB6EE502DE3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9C4F29DB-4A5E-4352-B628-83065D58A225} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9CA033EC-0332-456A-86A6-2EDA30E9B2FE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9CB261BD-F3CD-479E-B84E-7AF99B9F64AC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9CCCCD3E-81FD-43E6-820F-6F6E8D7BFBC2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9CFAFA18-0CDE-4933-9C0C-9D7102A16D79} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9D3B0850-7A50-476F-A2AE-66D4D97CC35A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9D78207C-3033-4CC5-AF86-1B4FC7912652} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9DCCBE1B-AB1B-441E-A0ED-D882FDDA78AF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9E0097E7-3A29-4E55-83B0-D2A4D1766E50} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9E3E7ABA-9933-4441-B0D1-AB134DD9FFC0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{9FF8C7DB-9337-4958-A2A9-2453BF113864} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A06B966D-2E36-4183-9F52-303317E9B23A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A0D2076E-C236-434B-A730-5B96561900E6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A1424276-6EBF-417E-8708-4E74BCF44489} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A16FD516-F545-488A-B962-DB8F130F4257} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A18A7AB9-6D9E-4D43-8F20-4125C6C4E281} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A18E8EB2-3B76-4C30-832A-118F30CB99E8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A1929CD4-0A56-4E62-B5FB-93428F4C47F6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A1A15AEB-4A7A-4045-B73E-83E1AF343E52} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A2DF53E7-A7E8-4600-A0E0-154AC2C43E7A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A394B049-04A8-404E-91E6-4CE82364BF83} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A39CF977-7C88-4399-AA9F-DDE57C3A8A52} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A3E21A6E-C2E3-4318-BEF3-DFCF09BF97D3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A3EEA0CC-C793-47D0-9BB7-C069EEBAECA7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A42409CD-1E3D-422C-A9C9-D62815CCD2FF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A553090C-7B78-435C-AC1F-CB4722DA9DEF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A64EACAD-7080-4242-A2A3-8B363CEB4484} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A66962C2-4D50-4744-B7C1-7DB252C03983} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A697A618-E4D6-4D08-AD08-BFC771BE6FC8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A6A5E5BB-2CBB-4D22-A82B-B8539A6B933A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A6D0C982-521D-429F-9BC3-1A49CC8638E1} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A6D685F6-5679-458C-B57B-6977688D0ECE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A78826EB-F642-4A47-A717-57C418C73436} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A896CB1D-64AF-4AC7-B872-6962E78B8A48} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A963347A-CD9B-4EE2-B464-00D57033583E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A9B69D38-7386-4927-B22F-78D3A6D8FFE3} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{A9E2313D-81D4-4DDE-BA7B-6239759F5F5D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AA6831A2-0E2C-4751-82D8-8F18008D7A3E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AAEA9F99-62B6-4364-B45F-010EDFFB4912} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AB0C323B-B8FD-457D-BF30-7944CF88E6E5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{ABC8EEB2-04F8-48FE-8FC9-5CFF5B911617} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AC7E09AA-C7B7-4D0E-91F6-4EBEF476E8DB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AC96BF32-E0AA-4ECF-B4F3-7944A303D623} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{ACEE5CA1-ABA0-4D3F-903A-FA1C66138BE7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AD3432F9-DC02-4169-B851-335DEF42B978} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{ADAE8711-B25C-4014-82D9-9684CF7534F5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{ADFF44E9-734A-442D-8EDD-EB69511306C6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AE2827F6-6AE3-472F-81B0-F60F75327ABF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AE646AFE-D0CD-4B84-80C0-168FA926A5AF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AE809B6B-9DC8-42A0-A31D-A2D476801BBA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AEA1E776-6894-44A3-B2DB-CECE7DBBF126} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AF3117A2-43FC-4755-8797-23F3C38ABB5F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AF4A5BF6-6ACB-49BC-9F72-B414A848447A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AF6C33C2-E2FC-4358-BE50-93B9B920273F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AFBA7E3D-B5FE-463F-AF13-D7D87C459D00} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{AFFCAC52-B05F-4EF5-8196-704162AF5A99} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B0E61938-B1C3-4462-93BF-034328AB492D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B1184378-12FB-405A-8A81-D9E1BAF01075} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B16BBC38-35BE-4564-A2BD-0B247B157313} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B193BF59-58DD-427D-842A-D4028AE8B06F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B21DE4D1-297E-4222-AA9B-10CDA6619E77} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B23AE1C4-42CD-4736-9DF0-1A3D4BDCCA97} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B23CB4A1-8968-4EDF-8326-738E2BF1F976} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B283B878-FD68-4BA8-96A4-B8ED0DE52ED4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B2B7A5AF-9FBF-45C3-B9FA-44CBC422EC74} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B2C42D0F-947C-4A50-9AED-0D8BFBBF513A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B2FFC51F-FB55-4AD5-96F9-AA68D9DF9A89} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B36D5F04-480E-4E76-8B50-A72E557FC65B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B41E9F13-3A3A-4AE8-8FA7-35B60F803B3C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B423F432-52B5-4541-AC5F-63CA7BD13871} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B43F2854-8542-4FA5-8EFD-7AA307BD7B48} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B45AEA48-52DA-42E2-983D-1D000AA6EBB9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B4B6D7F1-AFFC-42C0-BC8F-89C35715DF34} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B4C4C5EB-FCD3-4792-9A52-ADD8AA239944} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B4D5E129-4A71-434B-A1D1-6D73C0C7E95F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B592F87E-11B4-477D-B9CC-28684365B80C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B5A909B7-3D58-444A-92F5-E6A239E57CAD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B5AC5FF4-E396-4D8E-A0CF-EBC113881EA4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B5B96D51-000F-41D2-990B-7B5A4E30A6E2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B6440A2F-3F47-4585-900B-A58EFB0C9137} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B64F264D-E847-4D46-A60C-A0B2BB8F8A57} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B653E6FB-742E-41DD-B9E3-4203978E58E0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B6EEDFD5-2DBF-4148-A03B-E7267881E08A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B6F94CBB-9C5D-4861-B862-C563631AA21F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B7EF242E-F637-46F0-ABA7-828FAECB5D0B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B837DC40-7591-4D52-8A5C-DD10DB9F4E6D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B8C939CE-C105-49E9-8341-EF549DE3B465} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B92CBFBB-E50B-4152-8E9A-DCAED2332D58} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B932AE30-6663-4E0A-89A8-464E76B2789A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B94F1A6A-3D45-4B15-B703-A7AF9790E970} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B9CD166D-F07C-4844-9A22-0B28F44DE50C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B9E97011-7F95-4006-A0DA-7CF7D4C36CD7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{B9FA446E-546D-4157-BA08-101B7B92298E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BA376A7A-240E-43F8-B768-02BE10FA37A4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BA7FE9F6-B9A0-4E35-BFD1-A319728629CA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BAA69543-4D26-4286-B5AD-CB96C65C7FC4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BB08FEF0-ED77-48A3-80FD-08C4E820B432} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BB618610-FC57-49DE-8780-099E0DCE6228} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BBC13E6B-9A96-4C08-B9D9-709F2B09F8F0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BBDCC1EC-8A6F-4C6C-ADCE-D58E46C489ED} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BD072D3C-1AC8-4EA1-8036-C58FE654C334} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BD10552B-3CDC-4FC2-94FC-15FC2BCE16A9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BD2907F4-6C96-4A9E-B286-1B7562379363} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BD38F196-B8A4-4763-9EFB-B9F5DC90BC0F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BD9B2849-2DB0-4F4B-85AF-FAEB719A11EB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BDAA09CA-097F-417F-A0D2-1C08339B3570} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BE252F08-B2F3-404C-B508-9C133ADCD016} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BE4DE3F1-A1A2-422D-9320-FA833F19FF1F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BE58377B-2A7D-409D-9203-1391ACA75892} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BE930E0C-CF3F-44D1-B835-B1AAD206E182} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BEB3AB36-4C62-4B2C-8B93-32E374CDE4C5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BFD9A283-C8CA-4E18-9C13-03F6C96142C9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{BFE16075-D4D4-4D36-8124-D25E4676FC9C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C0304E9B-E619-4F39-AD47-72BECBB42847} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C08DE830-A1D8-4BAF-8792-26889FCD3663} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C0B64A31-A3AE-4FE8-893C-28ECF8A57488} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C13DC488-6204-4187-AB83-635139284C4D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C1575741-6B2B-4AE3-ADDE-8AA70E9A1647} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C19D9841-A8A0-492E-B80C-918E79FD0AAA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C2027AE5-8FFD-49D5-889D-5B6293B94136} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C2252097-C182-4D5A-B6FE-7918281A2406} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C29A8D44-4E56-456A-B5F3-CB44005E50A6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C3054291-93D5-4436-9F4D-3A77AE980FCD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C3292957-0DD3-4609-A9B7-00FA41015125} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C37043CB-AC26-49BE-A939-0ACB96E71293} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C3C3E8D3-43DB-4405-9E76-DB121B902885} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C3C9EF0F-BD32-4FF7-B07C-E7DCD8FC6C34} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C4168D9F-05D0-4161-B1E3-8B6443B3E68B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C4801CD5-57E4-4925-BAB4-3D9A0C2C818F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C4E5322F-0B12-49EA-B9B9-1C7AE391FCC9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C4EA1615-42C4-4D5B-81F8-4C4C9D11B78F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C5191118-05EE-430F-90C9-22786166426A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C58D8478-FD79-44AE-9FDA-913EC31016F2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C5A25C3A-D49B-4050-A23F-C2F116719C9E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C632F813-DB65-49D6-ABA9-AFFD3C870B61} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C6F6D50F-D5B3-443F-BF25-530FC17A92C6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C709B6A1-F2F6-4B12-A9F7-CBE10CC0DE69} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C71EFAD3-A34F-4BCA-8EEF-BE0D24870DF4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C769915C-D779-4E92-80F2-6F04A5506DDD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C7793009-FA55-4A6E-AE67-C3D4E3AFA888} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C781386F-8BF8-4CDC-9C13-00A7DF209885} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C88F6D86-D1C0-43EE-8B9A-284500F64553} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C890E3BB-4540-41DC-B607-F1C899565CD2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C8986E03-D59D-4B0B-8904-E5FA2FDC2369} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C8AADB8F-956E-4B30-A8EB-27F3A4603B2F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C90A0007-713F-4C9A-9319-D7D9028C5DB4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{C965588F-0936-4C94-970D-07197DD57642} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CA2D445A-9509-4597-B37D-B7DBA0BBA58D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CA438878-C1AE-4C51-905D-F1913D471759} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CAAE2865-319D-4C79-9481-4776CD92E733} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CB2F295C-9AD2-476B-B6D0-B37E8FBECB46} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CB63ECA2-05E9-4166-B38B-82C5523D4DFA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CB688883-C413-4096-A954-EAB1F678A505} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CB90FCE6-438C-42CF-9F09-8B8BD4EDECA7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CD1CCC0A-E31A-4A56-A145-0E23D14EC019} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CD3AB510-086C-4C51-9587-139DF65EF12F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CD8D885E-77CC-4992-A937-48F108753354} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CDA6B3B2-C005-4965-8737-0F117529A262} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CDC4A1DF-662C-452A-A4D9-49331044DB61} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CDEF412A-B8F2-41E3-B8E9-D96151C2D694} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CE035A8F-1EB6-4FD0-83DE-3370BE437691} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CE32A5D1-38C2-4547-A278-6AA8BA57F59E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CE6F9BDA-73D4-49B5-B00E-CBFD08A3AB60} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CEADDEE2-D4D7-49D6-9511-8CCEB9F1A540} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CF5BE778-D3A0-4774-BA40-90127E894E89} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CF6EBD6B-CFBA-437B-81B8-A4EC5AACE578} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CF6F7DFB-E797-4962-B28E-C3367F5145A7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{CF94520C-A238-4623-9BC5-CABDA49D5690} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D0013FDA-9403-497C-B000-F25EC1F7B8BC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D0051D34-443C-4A6E-861D-010395C33C53} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D00B0E3A-91F5-49CD-839F-5D53E7881284} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D0548C51-4B50-4207-8D0F-C4311DD2CD1B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D0C78356-559D-47E8-BA67-1D4754AFD908} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D0FCEF99-719E-405F-A20F-D894D1EB814A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D15D99D3-D412-4C28-8B15-E53B04A132CD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D17900E6-4BB7-403F-BAD9-AC86EF247B24} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D1FFEEDE-80D8-4C0B-A6F9-8286F87C1708} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D2BC515B-28AF-4111-A577-F4E0F0663852} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D2E7CEFD-0480-45E4-A2FA-052B1784DFC4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D31DC9B3-6EBB-42E3-9AA9-2E15F04F97F4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D32D6D6E-81CD-49C8-BDEF-F8CC9FA97212} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D3A1CE33-C205-4AF1-B557-5380EF530E13} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D4476C8C-058D-48C8-BADE-06E8A5FF7589} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D4571EE9-A9CB-4C2D-B133-C9C0CF79E67D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D468608B-284B-4D4C-8677-5960899F10A2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D5924327-0A8C-4B7B-8E07-4D34E82569C7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D6B95F17-242C-4B29-8827-4F92E1BC4A54} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D73B899B-6B22-499E-88F5-94A1DF800310} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D7AC3498-AFF1-49D1-BB70-55565EA95D10} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D7FEA31B-475F-472B-B28A-37AA55F2D50A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D841DC0C-3D2B-4DF4-A7BF-FBF3F90FC3CC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D8CC7979-916C-41C1-9F74-9B2D4A41A023} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D922BB52-A21C-4483-8ED9-F4D2F036FF9A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D94948E7-AD5A-43B0-A1A1-0DF6A7E9BBBF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{D9F22CFB-2C9F-46FE-AFA0-8CE7FD2C2EAF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DAE67A13-7CC0-4429-A152-2CAECF1FF8E9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DB0C8D8B-3FE2-440B-BCA6-42918809AB8C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DB39C54E-07FC-4517-8803-BF9D64354975} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DB5D8AD8-EF86-4B7A-B500-AF6397003BF8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DBC12758-9358-4ACB-8B81-A6B430B68011} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DBC273CB-8C59-42F9-968C-06E9AA407FDA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DBCC3EC9-39E4-4541-85B4-9530FEA39604} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DC038595-1B52-41AF-B0E0-13325C363190} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DC5CC0AA-760C-42CD-B7DB-BB1E82FADC7F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DC97D1BA-E8CC-43DD-9751-DA8AE1C28F86} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DCC13C52-CA53-4213-B4F6-CA70231AAF37} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DCC8274E-994F-4B46-B2C5-2EC10B19C5C0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DD074526-345F-415C-AF3B-DC7679991368} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DD0B1F69-58C5-4496-81DA-CBFD4C37D8AA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DD497EE1-1B51-46EE-8C11-9FBD4F8AB181} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DE7248B7-74D3-4DE9-A2D3-2BA010E9FFF7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DE9F1604-0235-4DA0-8249-019832121AFD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DEBC07F0-FAFE-4439-A0CA-8BE0EA33B36C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DEFE9AF7-F483-438E-8949-EAF4B45A0FFC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DF3C9FC9-BA82-40D6-83DB-78BD91FE6A98} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DF661ED4-15F3-4846-BEC9-6511BB1890BF} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DF73ED5F-DC89-4ED9-9322-1AA644F0A41C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DF7927A1-7EEF-4230-8D54-B8B61A443B15} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DFC59D37-601E-4BAA-BDC5-C0E8064921C2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DFD25839-C9C8-43D0-A375-4F775AF77502} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{DFFA81CD-04BA-4462-9064-7A3A0FEEB4F5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E04F5010-2761-49DA-A476-3ED004E3CB18} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E0820080-E5FC-4214-B122-E13AAA78719C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E1100440-CF5E-4D92-9369-E79AA46DA5BD} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E1150B2A-6D07-4C3F-A593-B8B0F7096186} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E13D84CE-F95A-4A52-8471-D8ED4F829B40} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E1648D6F-4F0F-4E4C-8760-833CED134212} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E203CEA3-5001-4A28-B9D5-CE31BAD3316B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E2108C46-D378-4160-B683-C8656C99514E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E234AE73-2AF2-49A9-9F7B-7822B0D587B0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E2C7ACBB-2DE0-4605-9A2D-FED470216251} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E32751AA-1A1D-419F-9670-D530839AC637} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E3371934-3586-4B87-88C4-A13F5B14877A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E3531D42-46A3-4973-81E0-CD3A2A63A462} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E4EBFF2A-FD5B-43E4-A728-AE30731A46B2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E6B05316-7501-41BA-AB5E-F41C4FF862B5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E749AFF6-B897-433D-99D8-C4040B1E9F7F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E878A41F-AF0B-41D7-98D2-880D68F056F9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E8B46517-23FE-4DE4-B08B-7E4962E93F88} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E8BA46A6-6FBC-4429-8E04-C9CC9E85BC7F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E907FE5E-E5DB-4463-AD95-4E082584501F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{E9DF8E52-79D3-4D65-B9C7-60EF658CD6A6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EA4E41B6-DAE7-447C-880E-C1DB4437C55A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EA9133A2-BB74-4AC7-9BCA-7AEA7F63AEB0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EAE88A74-4254-484C-92CD-80803595807F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EB82A75F-870C-461E-AA3B-896696E90FD8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EBC71943-7070-4F99-81DF-04F333A61953} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EC231682-D67A-4AFD-AD4B-85F5594FD94F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EC42510C-4C26-4B14-B3DB-4202FCD21510} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EC94FFF6-00EE-4886-82E2-380D26F95677} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{ECA55248-32AF-4628-9752-9D51DA49F0DB} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EDCAF4E1-6255-4CD5-9CD4-2DDD50F8183C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EDFD781B-42A9-4FA0-A4F3-D3A2758BBB15} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EE10842C-4CF9-4DB2-B440-753C8469EB1E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EE46A95E-9379-482A-B4F6-A26649DBE6C4} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EEF4E7DF-7941-4BD5-A600-8EC2EA92A570} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EF034668-006C-492F-B4D1-0A71FDCC35A5} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EF1585A7-A068-471F-86D5-ACBEF5EE1A66} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EF31E1AB-B539-4A3A-8B8B-8AC5E208064C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{EFBA796F-5CBF-40C9-8A79-D66A3C2D269F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F073F17B-406A-4F8A-A122-043A6FC35ED7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F0C96F7B-BC0B-4266-86B0-542BE9D81980} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F0F6D033-CC74-464F-A741-DD43863CE057} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F0F82509-8D95-432A-9431-6EAA3B51137A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F150448A-5898-4E07-8F9D-EE0E339A927D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F15DDF81-A6D2-45D3-B956-C15DC6EE9E0B} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F1834FD1-AC9C-466E-ADCB-600413EFA1C2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F1A32BE4-401D-4E49-A338-51B7DD5C58B6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F20D8078-2C17-430E-B3A8-9E9FA0D41E0F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F22CE5B2-8FFA-446D-ACCF-A344C0A28DEE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F26C91BD-5F41-403B-AD15-5112BF79BCC0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F32F08E8-E0E1-4C7F-BFB0-AD9D70D34567} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F35CD770-C743-460C-AFDB-21AA1B4504E6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F3A381A3-89C0-4142-BFEE-734312A8DED0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F3CEA216-0519-470E-86B1-D74389220531} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F40704FC-4AB7-4147-AE22-0A6CED44D1F9} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F4C539EA-4A63-4D38-84CE-15EEFF1C6496} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F4C9644D-6081-4184-89FF-B751D2ED0F43} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F4F47E0C-3BD1-4D0E-9726-473B0CE2E876} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F5174655-1D01-49C7-B096-8AF0D611202F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F592DEB0-9520-48F0-B99C-8628D68FDE96} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F63D8D37-6D19-4FF0-9A5D-0672A826D7C8} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F7279D0F-77BB-403D-B3E2-82F4720E42B0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F7C235A4-815B-43E2-8907-21F5750B77BA} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F7EF7B97-82E5-4271-9503-79207CA0DA52} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F8022F30-1D88-47CC-A9B8-F2C9535C178D} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F85C2B86-9174-46D0-8E33-25A53A72CF52} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F88D0730-51FB-4ACD-92BA-B3128CC63E0C} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F8D6506B-BCBF-41BD-A8CB-9E641AF12668} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F8E83DA1-3E7B-4148-A331-F646F6E9543E} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F8ED4855-30F3-48F1-A6D0-9F09FC23FF30} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F9179C1D-2369-45BE-8C56-4E6AE793FE25} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F91EB198-B63F-4D53-A983-D08258E42849} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F9AAA2A9-69DF-43C5-9A9E-A91EDE2CDCFE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{F9BFC602-3712-4476-B0DB-A1DD9719ED6F} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FA0BD6D0-7F44-45A1-9B77-D79DBA479FCC} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FA35E098-CE5D-4E3A-BDFC-7955A3CF5124} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FA424AF7-B71D-4DF3-AA01-C1F90443D822} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FB42E418-2E32-4A06-8814-C749F9618C50} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FBCC5DF7-7EDC-45A1-97EA-AF50E940F0A6} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FC2FBD9C-848C-443B-BFFA-2F23D5A7E736} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FCBB085E-0118-4E7E-9B87-582F73E6C430} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FD85E813-F9F0-4D13-8BEB-282595F45964} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FDB11359-1A74-4C5B-9106-E847AAAEC9B7} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FE0BB99D-EE45-4C6A-8A49-3E6E02015B2A} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FE524906-7626-49A6-95B3-153F47DD52AE} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FEC51D60-67B6-45AC-A222-92ADE8B59C26} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FEFD5985-E6AF-4F4C-B4D0-327BB0CF8ED2} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FF5A8918-190B-4AE8-AF57-14D84301A8C0} Successfully deleted: [Empty Folder] C:\Users\Chriss\appdata\local\{FFE89A93-5467-4623-B8A1-D5D940F3B50E} ~~~ FireFox Successfully deleted the following from C:\Users\Chriss\AppData\Roaming\mozilla\firefox\profiles\8k26syj7.default\prefs.js user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_referrer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://www.tvtivkets.de/tickets user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_temp_referer", "hxxp://us.yhs4.search.yahoo.com/yhs/search?fr=altavista&itag=ody&q=hxxp://www.tvtivkets.de/tic Emptied folder: C:\Users\Chriss\AppData\Roaming\mozilla\firefox\profiles\8k26syj7.default\minidumps [538 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01.07.2013 at 17:46:42,34 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
01.07.2013, 20:55 | #6 |
| Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com neue FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03 Ran by Chriss (administrator) on 01-07-2013 18:18:58 Running from C:\Users\Chriss\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (DT Soft Ltd) D:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Spotify Ltd) C:\Users\Chriss\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) C:\Users\Chriss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Logitech Inc.) D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKCU\...\Run: [DAEMON Tools Pro Agent] "D:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [x] HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19603048 2013-06-03] (Skype Technologies S.A.) HKCU\...\Run: [Spotify] "C:\Users\Chriss\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4643328 2013-06-18] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] "C:\Users\Chriss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1104384 2013-06-18] (Spotify Ltd) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 MountPoints2: G - G:\AUTORUN.EXE MountPoints2: {5b0ecf0a-4624-11e2-9491-f46d04aeb530} - G:\Autorun.exe MountPoints2: {7f8b574c-7131-11e1-b7b8-806e6f6e6963} - F:\Autorun.exe MountPoints2: {a9b87efe-c170-11e1-af15-f46d04aeb530} - G:\AutoRun.exe HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [LWS] D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [x] HKLM-x32\...\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe" [x] Startup: C:\ProgramData\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: LyricsWoofer - {73F8F433-14C8-48AA-8412-54BC6F8D3FA3} - C:\Program Files (x86)\LyricsWoofer\116.dll (Lyrics Woofer LTD) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default FF SearchEngine: Google FF Homepage: hxxp://www.bild.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @protectdisc.com/NPMPDRM - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( ) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: youtubeunblocker - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\youtubeunblocker@unblocker.yt.xpi FF Extension: No Name - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] C:\Program Files (x86)\LyricsWoofer\116.xpi FF Extension: No Name - C:\Program Files (x86)\LyricsWoofer\116.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\pdf.dll No File CHR Plugin: (Injovo Extension Plugin) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\npbrowserext.dll No File CHR Plugin: (Wajam) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (fluxDVD Browser Plugin) - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( ) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (VLC Web Plugin) - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Extension: (YouTube) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Gmail) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-08] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-08] (Avira Operations GmbH & Co. KG) R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-05-08] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-05-08] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2011-09-16] (Avira GmbH) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-14] (DT Soft Ltd) S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-12-14] (Duplex Secure Ltd.) U3 axkyq7r9; C:\Windows\System32\Drivers\axkyq7r9.sys [0 ] (Microsoft Corporation) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-01 17:46 - 2013-07-01 17:46 - 00086127 ____A C:\Users\Chriss\Desktop\JRT.txt 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\Windows\ERUNT 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\JRT 2013-07-01 17:43 - 2013-07-01 17:43 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Chriss\Desktop\JRT.exe 2013-07-01 17:41 - 2013-07-01 17:41 - 00018404 ____A C:\Users\Chriss\Desktop\AdwCleaner[S1].txt 2013-07-01 17:39 - 2013-07-01 17:39 - 00018404 ____A C:\AdwCleaner[S1].txt 2013-07-01 16:41 - 2013-07-01 16:41 - 01933758 ____A (Farbar) C:\Users\Chriss\Desktop\FRST64.exe 2013-07-01 16:41 - 2013-07-01 16:41 - 00000000 ____D C:\FRST 2013-07-01 13:00 - 2013-07-01 16:43 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____A C:\autoexec.bat 2013-07-01 12:59 - 2013-07-01 12:59 - 00726464 ____A (Enigma Software Group USA, LLC.) C:\Users\Chriss\Desktop\SpyHunter-Installer.exe 2013-07-01 12:42 - 2013-07-01 12:43 - 00019973 ____A C:\AdwCleaner[R1].txt 2013-07-01 12:41 - 2013-07-01 12:41 - 00648201 ____A C:\Users\Chriss\Desktop\adwcleaner.exe 2013-07-01 03:22 - 2013-07-01 03:22 - 01888311 ____A C:\Users\Chriss\Desktop\HLOma's Gurkenfass.zip 2013-07-01 03:22 - 2013-07-01 03:22 - 01781705 ____A C:\Users\Chriss\Desktop\HLLila Pause.zip 2013-06-30 23:26 - 2013-06-30 23:28 - 00000000 ____D C:\Users\Chriss\Desktop\simssaveneu 2013-06-30 23:23 - 2013-06-30 23:24 - 00000000 ____D C:\Users\Chriss\Desktop\SimsInsel 2013-06-30 22:34 - 2013-06-30 22:34 - 00002037 ____A C:\Users\Chriss\Desktop\JDownloader.lnk 2013-06-30 22:33 - 2013-07-01 17:41 - 00000406 ____A C:\Windows\Tasks\LyricsWoofer Update.job 2013-06-30 22:33 - 2013-06-30 22:49 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsWoofer 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsFan 2013-06-29 18:35 - 2013-06-29 18:35 - 02813358 ____A C:\Users\Chriss\Desktop\Booster Maxxx G4.rar 2013-06-25 22:27 - 2013-06-25 22:27 - 00000048 ____A C:\MyUpdateLogs.log 2013-06-25 21:51 - 2013-06-25 21:53 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister Backup 2013-06-25 02:25 - 2013-06-25 02:25 - 00000000 ____D C:\Users\Chriss\Desktop\ebay 2013-06-25 01:11 - 2013-06-25 01:11 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister 2013-06-25 00:59 - 2013-06-25 01:02 - 00000402 ____A C:\InstallHelper.log 2013-06-25 00:58 - 2013-06-25 00:58 - 00001814 ____A C:\Users\Public\Desktop\eBay Turbo Lister 2.lnk 2013-06-25 00:58 - 2013-06-25 00:58 - 00000000 ____D C:\ProgramData\eBay 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iTunes 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iPod 2013-06-19 20:35 - 2013-05-17 06:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-19 20:35 - 2013-05-17 05:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-19 20:35 - 2013-05-17 05:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-19 20:35 - 2013-05-17 05:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-19 20:35 - 2013-05-17 05:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-19 20:35 - 2013-05-17 05:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-19 20:35 - 2013-05-17 05:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-19 20:35 - 2013-05-17 04:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-19 20:35 - 2013-05-17 04:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-19 20:35 - 2013-05-17 04:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-19 20:35 - 2013-05-17 04:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-19 20:35 - 2013-05-17 04:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-19 20:35 - 2013-05-17 04:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-19 20:35 - 2013-05-17 04:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-19 20:35 - 2013-05-17 04:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-19 20:35 - 2013-05-17 04:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-19 20:35 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-19 20:35 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-19 20:35 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-19 20:35 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-19 20:35 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-19 20:35 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-19 20:35 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-19 20:35 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-19 20:35 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-19 20:35 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-19 20:35 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-19 20:35 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-19 20:35 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-19 20:35 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-19 20:35 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-19 20:35 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-19 20:30 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-19 20:30 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-19 20:30 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-19 20:30 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-19 20:30 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-19 20:30 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-19 20:30 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-19 20:30 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-19 20:30 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-19 20:30 - 2013-04-12 16:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-06-19 20:30 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-06-19 20:30 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-06-19 20:30 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-06-19 20:30 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-06-19 20:30 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-06-19 20:30 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-06-19 20:30 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-06-19 20:30 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-06-19 20:30 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-06-19 20:30 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-06-19 20:30 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-06-19 20:30 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-06-19 20:30 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-06-19 20:30 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys 2013-06-19 20:30 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-06-17 22:09 - 2013-06-17 22:09 - 02702378 ____A C:\Users\Chriss\Desktop\Mixer.rar 2013-06-10 15:58 - 2013-06-10 15:58 - 01044480 ___RA (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll 2013-06-10 15:58 - 2013-06-10 15:58 - 00049152 ___RA (Blue Sky Software Corporation.) C:\Windows\SysWOW64\inetwh32.dll ==================== One Month Modified Files and Folders ======= 2013-07-01 18:16 - 2012-04-10 21:26 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Skype 2013-07-01 17:48 - 2009-07-14 06:45 - 00014608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-01 17:48 - 2009-07-14 06:45 - 00014608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-01 17:46 - 2013-07-01 17:46 - 00086127 ____A C:\Users\Chriss\Desktop\JRT.txt 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\Windows\ERUNT 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\JRT 2013-07-01 17:44 - 2012-03-18 21:47 - 02029916 ____A C:\Windows\WindowsUpdate.log 2013-07-01 17:43 - 2013-07-01 17:43 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Chriss\Desktop\JRT.exe 2013-07-01 17:41 - 2013-07-01 17:41 - 00018404 ____A C:\Users\Chriss\Desktop\AdwCleaner[S1].txt 2013-07-01 17:41 - 2013-06-30 22:33 - 00000406 ____A C:\Windows\Tasks\LyricsWoofer Update.job 2013-07-01 17:41 - 2012-03-21 12:02 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Spotify 2013-07-01 17:41 - 2012-03-19 00:46 - 00000000 ____D C:\Users\Chriss\Tracing 2013-07-01 17:40 - 2012-04-10 22:08 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs 2013-07-01 17:40 - 2012-03-18 22:24 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-01 17:40 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-01 17:40 - 2009-07-14 06:51 - 00130814 ____A C:\Windows\setupact.log 2013-07-01 17:39 - 2013-07-01 17:39 - 00018404 ____A C:\AdwCleaner[S1].txt 2013-07-01 17:39 - 2012-04-19 13:21 - 00001049 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-01 17:28 - 2012-04-04 13:31 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-01 17:14 - 2012-04-04 15:17 - 00043520 ____A C:\Windows\SysWOW64\CmdLineExt03.dll 2013-07-01 16:43 - 2013-07-01 13:00 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-01 16:41 - 2013-07-01 16:41 - 01933758 ____A (Farbar) C:\Users\Chriss\Desktop\FRST64.exe 2013-07-01 16:41 - 2013-07-01 16:41 - 00000000 ____D C:\FRST 2013-07-01 15:05 - 2012-03-21 12:02 - 00000000 ____D C:\Users\Chriss\AppData\Local\Spotify 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____A C:\autoexec.bat 2013-07-01 12:59 - 2013-07-01 12:59 - 00726464 ____A (Enigma Software Group USA, LLC.) C:\Users\Chriss\Desktop\SpyHunter-Installer.exe 2013-07-01 12:43 - 2013-07-01 12:42 - 00019973 ____A C:\AdwCleaner[R1].txt 2013-07-01 12:41 - 2013-07-01 12:41 - 00648201 ____A C:\Users\Chriss\Desktop\adwcleaner.exe 2013-07-01 12:29 - 2012-03-19 13:54 - 00097678 ____A C:\Windows\PFRO.log 2013-07-01 12:29 - 2009-07-14 06:45 - 00269032 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-01 03:22 - 2013-07-01 03:22 - 01888311 ____A C:\Users\Chriss\Desktop\HLOma's Gurkenfass.zip 2013-07-01 03:22 - 2013-07-01 03:22 - 01781705 ____A C:\Users\Chriss\Desktop\HLLila Pause.zip 2013-06-30 23:48 - 2012-03-19 01:21 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Origin 2013-06-30 23:48 - 2012-03-19 01:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\Origin 2013-06-30 23:48 - 2012-03-19 01:20 - 00000000 ____D C:\Program Files (x86)\Origin 2013-06-30 23:43 - 2012-03-19 01:20 - 00000000 ____D C:\ProgramData\Origin 2013-06-30 23:40 - 2012-03-18 22:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-30 23:28 - 2013-06-30 23:26 - 00000000 ____D C:\Users\Chriss\Desktop\simssaveneu 2013-06-30 23:24 - 2013-06-30 23:23 - 00000000 ____D C:\Users\Chriss\Desktop\SimsInsel 2013-06-30 22:49 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-06-30 22:34 - 2013-06-30 22:34 - 00002037 ____A C:\Users\Chriss\Desktop\JDownloader.lnk 2013-06-30 22:34 - 2012-03-19 00:35 - 00058016 ____A C:\Users\Chriss\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsWoofer 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsFan 2013-06-30 22:30 - 2012-09-26 22:19 - 00000000 ____D C:\Program Files (x86)\DownloadManager 2013-06-29 18:35 - 2013-06-29 18:35 - 02813358 ____A C:\Users\Chriss\Desktop\Booster Maxxx G4.rar 2013-06-27 20:12 - 2009-07-14 19:58 - 00697680 ____A C:\Windows\System32\perfh007.dat 2013-06-27 20:12 - 2009-07-14 19:58 - 00148976 ____A C:\Windows\System32\perfc007.dat 2013-06-27 20:12 - 2009-07-14 07:13 - 01616160 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-27 20:11 - 2012-03-18 22:39 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\vlc 2013-06-25 22:27 - 2013-06-25 22:27 - 00000048 ____A C:\MyUpdateLogs.log 2013-06-25 21:53 - 2013-06-25 21:51 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister Backup 2013-06-25 02:25 - 2013-06-25 02:25 - 00000000 ____D C:\Users\Chriss\Desktop\ebay 2013-06-25 01:11 - 2013-06-25 01:11 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister 2013-06-25 01:02 - 2013-06-25 00:59 - 00000402 ____A C:\InstallHelper.log 2013-06-25 00:58 - 2013-06-25 00:58 - 00001814 ____A C:\Users\Public\Desktop\eBay Turbo Lister 2.lnk 2013-06-25 00:58 - 2013-06-25 00:58 - 00000000 ____D C:\ProgramData\eBay 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iTunes 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iPod 2013-06-21 16:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-17 22:09 - 2013-06-17 22:09 - 02702378 ____A C:\Users\Chriss\Desktop\Mixer.rar 2013-06-15 14:06 - 2012-04-04 13:31 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-15 14:06 - 2012-03-19 20:44 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-13 13:03 - 2009-07-14 07:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-12 20:02 - 2013-01-23 19:29 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-12 20:02 - 2012-04-10 21:26 - 00000000 ____D C:\ProgramData\Skype 2013-06-10 15:58 - 2013-06-10 15:58 - 01044480 ___RA (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll 2013-06-10 15:58 - 2013-06-10 15:58 - 00049152 ___RA (Blue Sky Software Corporation.) C:\Windows\SysWOW64\inetwh32.dll 2013-06-08 23:34 - 2012-04-19 15:38 - 00000000 ____D C:\Users\Chriss\AppData\Local\Deployment 2013-06-02 17:11 - 2012-03-27 21:22 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-23 03:30 ==================== End Of Log ============================ Vielen Dank nochmals für die Mühen |
02.07.2013, 07:57 | #7 |
/// the machine /// TB-Ausbilder | Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Onlinescan, dann Reste entfernen ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST Log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.07.2013, 12:44 | #8 |
| Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Hallo, hier die LogFiles ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ceeaae9bdc9d1c48b9565835f635722a # engine=14231 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-02 11:28:02 # local_time=2013-07-02 01:28:02 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 99 75023 118531365 67813 0 # compatibility_mode=5893 16776573 100 94 0 124394332 0 0 # scanned=470171 # found=3 # cleaned=0 # scan_time=4805 sh=E104758CDD238A5F0EB5A6EE503F8FB38BFCD127 ft=1 fh=90530f0251eda9e2 vn="multiple threats" ac=I fn="C:\Users\Chriss\AppData\Local\Temp\is357113909\ezLookerSilent_DDD_FTT_BG_BD_BVD.exe" sh=70669EF03D5F84D7CB8193CF8C48BE39140E2EB1 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.Y trojan" ac=I fn="C:\Users\Chriss\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\7f3136d1-24446b52" sh=BEFB244F14AFE861F92936202AD8DDB1B12A260D ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.DR trojan" ac=I fn="C:\Users\Chriss\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\7f883755-668b9141" Code:
ATTFilter Results of screen317's Security Check version 0.99.68 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` JavaFX 2.1.1 Java(TM) 7 Update 5 Java version out of Date! Adobe Flash Player 11.7.700.224 Adobe Reader 10.1.7 Adobe Reader out of Date! Mozilla Firefox 21.0 Firefox out of Date! ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-06-2013 03 Ran by Chriss (administrator) on 02-07-2013 13:40:43 Running from C:\Users\Chriss\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (DT Soft Ltd) D:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Spotify Ltd) C:\Users\Chriss\AppData\Roaming\Spotify\spotify.exe (Spotify Ltd) C:\Users\Chriss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Logitech Inc.) D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe () C:\Program Files\WinRAR\WinRAR.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKCU\...\Run: [DAEMON Tools Pro Agent] "D:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun [x] HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19603048 2013-06-03] (Skype Technologies S.A.) HKCU\...\Run: [Spotify] "C:\Users\Chriss\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart [4643328 2013-06-18] (Spotify Ltd) HKCU\...\Run: [Spotify Web Helper] "C:\Users\Chriss\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1104384 2013-06-18] (Spotify Ltd) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 MountPoints2: G - G:\AUTORUN.EXE MountPoints2: {5b0ecf0a-4624-11e2-9491-f46d04aeb530} - G:\Autorun.exe MountPoints2: {7f8b574c-7131-11e1-b7b8-806e6f6e6963} - F:\Autorun.exe MountPoints2: {a9b87efe-c170-11e1-af15-f46d04aeb530} - G:\AutoRun.exe HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [LWS] D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide [x] HKLM-x32\...\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe" [x] Startup: C:\ProgramData\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: LyricsWoofer - {73F8F433-14C8-48AA-8412-54BC6F8D3FA3} - C:\Program Files (x86)\LyricsWoofer\116.dll (Lyrics Woofer LTD) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default FF SearchEngine: Google FF Homepage: hxxp://www.bild.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @protectdisc.com/NPMPDRM - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( ) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: youtubeunblocker - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\youtubeunblocker@unblocker.yt.xpi FF Extension: No Name - C:\Users\Chriss\AppData\Roaming\Mozilla\Firefox\Profiles\8k26syj7.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] C:\Program Files\Web Assistant\Firefox FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] C:\Program Files (x86)\LyricsWoofer\116.xpi FF Extension: No Name - C:\Program Files (x86)\LyricsWoofer\116.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\pdf.dll No File CHR Plugin: (Injovo Extension Plugin) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\npbrowserext.dll No File CHR Plugin: (Wajam) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (fluxDVD Browser Plugin) - C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( ) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Java(TM) Platform SE 7 U5) - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (VLC Web Plugin) - D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Extension: (YouTube) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Gmail) - C:\Users\Chriss\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-08] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-08] (Avira Operations GmbH & Co. KG) R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-05-08] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-05-08] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2011-09-16] (Avira GmbH) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-14] (DT Soft Ltd) S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2012-12-14] (Duplex Secure Ltd.) U3 akurhsjb; C:\Windows\System32\Drivers\akurhsjb.sys [0 ] (Advanced Micro Devices) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-02 13:39 - 2013-07-02 13:39 - 00000930 ____A C:\Users\Chriss\Desktop\checkup.txt 2013-07-02 12:56 - 2012-11-30 00:32 - 00037343 ____A C:\Users\Chriss\Desktop\Flume.rar 2013-07-02 12:55 - 2013-07-02 12:55 - 00662776 ____A C:\Users\Chriss\Desktop\Barth Olympialooping.zip 2013-07-02 12:31 - 2013-07-02 12:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{B74DB985-17A0-4C89-BEDD-A703502912F4} 2013-07-02 12:09 - 2013-07-02 12:09 - 00890988 ____A C:\Users\Chriss\Desktop\SecurityCheck.exe 2013-07-02 00:31 - 2013-07-02 00:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{6EA4CB38-E797-4993-9EE4-D6BFAB84B2ED} 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\Windows\ERUNT 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\JRT 2013-07-01 17:43 - 2013-07-01 17:43 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Chriss\Desktop\JRT.exe 2013-07-01 17:39 - 2013-07-01 17:39 - 00018404 ____A C:\AdwCleaner[S1].txt 2013-07-01 16:41 - 2013-07-01 16:41 - 01933758 ____A (Farbar) C:\Users\Chriss\Desktop\FRST64.exe 2013-07-01 16:41 - 2013-07-01 16:41 - 00000000 ____D C:\FRST 2013-07-01 13:00 - 2013-07-01 16:43 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____A C:\autoexec.bat 2013-07-01 12:59 - 2013-07-01 12:59 - 00726464 ____A (Enigma Software Group USA, LLC.) C:\Users\Chriss\Desktop\SpyHunter-Installer.exe 2013-07-01 12:42 - 2013-07-01 12:43 - 00019973 ____A C:\AdwCleaner[R1].txt 2013-07-01 12:41 - 2013-07-01 12:41 - 00648201 ____A C:\Users\Chriss\Desktop\adwcleaner.exe 2013-06-30 23:26 - 2013-06-30 23:28 - 00000000 ____D C:\Users\Chriss\Desktop\simssaveneu 2013-06-30 23:23 - 2013-06-30 23:24 - 00000000 ____D C:\Users\Chriss\Desktop\SimsInsel 2013-06-30 22:34 - 2013-06-30 22:34 - 00002037 ____A C:\Users\Chriss\Desktop\JDownloader.lnk 2013-06-30 22:33 - 2013-07-02 11:49 - 00000406 ____A C:\Windows\Tasks\LyricsWoofer Update.job 2013-06-30 22:33 - 2013-06-30 22:49 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsWoofer 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsFan 2013-06-25 22:27 - 2013-06-25 22:27 - 00000048 ____A C:\MyUpdateLogs.log 2013-06-25 21:51 - 2013-06-25 21:53 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister Backup 2013-06-25 02:25 - 2013-06-25 02:25 - 00000000 ____D C:\Users\Chriss\Desktop\ebay 2013-06-25 01:11 - 2013-06-25 01:11 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister 2013-06-25 00:59 - 2013-06-25 01:02 - 00000402 ____A C:\InstallHelper.log 2013-06-25 00:58 - 2013-06-25 00:58 - 00001814 ____A C:\Users\Public\Desktop\eBay Turbo Lister 2.lnk 2013-06-25 00:58 - 2013-06-25 00:58 - 00000000 ____D C:\ProgramData\eBay 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iTunes 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iPod 2013-06-19 20:35 - 2013-05-17 06:05 - 17824768 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-19 20:35 - 2013-05-17 05:27 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-19 20:35 - 2013-05-17 05:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-19 20:35 - 2013-05-17 05:02 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-19 20:35 - 2013-05-17 05:02 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-19 20:35 - 2013-05-17 05:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-06-19 20:35 - 2013-05-17 05:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-06-19 20:35 - 2013-05-17 04:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-19 20:35 - 2013-05-17 04:56 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-06-19 20:35 - 2013-05-17 04:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-06-19 20:35 - 2013-05-17 04:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-19 20:35 - 2013-05-17 04:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-19 20:35 - 2013-05-17 04:53 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-19 20:35 - 2013-05-17 04:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-19 20:35 - 2013-05-17 04:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-06-19 20:35 - 2013-05-17 04:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-19 20:35 - 2013-05-17 01:08 - 12329984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-19 20:35 - 2013-05-17 00:49 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-19 20:35 - 2013-05-17 00:39 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-19 20:35 - 2013-05-17 00:28 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-19 20:35 - 2013-05-17 00:28 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-19 20:35 - 2013-05-17 00:27 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-06-19 20:35 - 2013-05-17 00:26 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-06-19 20:35 - 2013-05-17 00:23 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-19 20:35 - 2013-05-17 00:21 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-19 20:35 - 2013-05-17 00:21 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-06-19 20:35 - 2013-05-17 00:20 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-06-19 20:35 - 2013-05-17 00:19 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-19 20:35 - 2013-05-17 00:17 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-19 20:35 - 2013-05-17 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-06-19 20:35 - 2013-05-17 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-19 20:35 - 2013-05-17 00:12 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-19 20:30 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-19 20:30 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-19 20:30 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-19 20:30 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-19 20:30 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-19 20:30 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-19 20:30 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-19 20:30 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-19 20:30 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-19 20:30 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-19 20:30 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-19 20:30 - 2013-04-12 16:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys 2013-06-19 20:30 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-06-19 20:30 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-06-19 20:30 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-06-19 20:30 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-06-19 20:30 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-06-19 20:30 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-06-19 20:30 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-06-19 20:30 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-06-19 20:30 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-06-19 20:30 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-06-19 20:30 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-06-19 20:30 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-06-19 20:30 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-06-19 20:30 - 2013-02-12 06:12 - 00019968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys 2013-06-19 20:30 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-06-17 22:09 - 2013-06-17 22:09 - 02702378 ____A C:\Users\Chriss\Desktop\Mixer.rar 2013-06-10 15:58 - 2013-06-10 15:58 - 01044480 ___RA (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll 2013-06-10 15:58 - 2013-06-10 15:58 - 00049152 ___RA (Blue Sky Software Corporation.) C:\Windows\SysWOW64\inetwh32.dll ==================== One Month Modified Files and Folders ======= 2013-07-02 13:39 - 2013-07-02 13:39 - 00000930 ____A C:\Users\Chriss\Desktop\checkup.txt 2013-07-02 13:34 - 2012-04-10 21:26 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Skype 2013-07-02 13:28 - 2012-04-04 13:31 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-02 13:20 - 2012-03-21 12:02 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Spotify 2013-07-02 12:55 - 2013-07-02 12:55 - 00662776 ____A C:\Users\Chriss\Desktop\Barth Olympialooping.zip 2013-07-02 12:31 - 2013-07-02 12:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{B74DB985-17A0-4C89-BEDD-A703502912F4} 2013-07-02 12:19 - 2012-04-04 15:17 - 00043520 ____A C:\Windows\SysWOW64\CmdLineExt03.dll 2013-07-02 12:09 - 2013-07-02 12:09 - 00890988 ____A C:\Users\Chriss\Desktop\SecurityCheck.exe 2013-07-02 11:50 - 2012-03-18 21:47 - 02045719 ____A C:\Windows\WindowsUpdate.log 2013-07-02 11:49 - 2013-06-30 22:33 - 00000406 ____A C:\Windows\Tasks\LyricsWoofer Update.job 2013-07-02 11:49 - 2012-03-19 00:46 - 00000000 ____D C:\Users\Chriss\Tracing 2013-07-02 10:54 - 2009-07-14 06:45 - 00014608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-02 10:54 - 2009-07-14 06:45 - 00014608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-02 10:45 - 2012-04-10 22:08 - 00000000 ____A C:\Windows\System32\Drivers\lvuvc.hs 2013-07-02 10:45 - 2012-03-18 22:24 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-02 10:45 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-02 10:45 - 2009-07-14 06:51 - 00130926 ____A C:\Windows\setupact.log 2013-07-02 00:31 - 2013-07-02 00:31 - 00000000 ____D C:\Users\Chriss\AppData\Local\{6EA4CB38-E797-4993-9EE4-D6BFAB84B2ED} 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\Windows\ERUNT 2013-07-01 17:44 - 2013-07-01 17:44 - 00000000 ____D C:\JRT 2013-07-01 17:43 - 2013-07-01 17:43 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Chriss\Desktop\JRT.exe 2013-07-01 17:39 - 2013-07-01 17:39 - 00018404 ____A C:\AdwCleaner[S1].txt 2013-07-01 17:39 - 2012-04-19 13:21 - 00001049 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-01 16:43 - 2013-07-01 13:00 - 00000000 ____D C:\Windows\BCD5545077AC4347B24F654B1189F8D4.TMP 2013-07-01 16:41 - 2013-07-01 16:41 - 01933758 ____A (Farbar) C:\Users\Chriss\Desktop\FRST64.exe 2013-07-01 16:41 - 2013-07-01 16:41 - 00000000 ____D C:\FRST 2013-07-01 15:05 - 2012-03-21 12:02 - 00000000 ____D C:\Users\Chriss\AppData\Local\Spotify 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-07-01 13:00 - 2013-07-01 13:00 - 00000000 ____A C:\autoexec.bat 2013-07-01 12:59 - 2013-07-01 12:59 - 00726464 ____A (Enigma Software Group USA, LLC.) C:\Users\Chriss\Desktop\SpyHunter-Installer.exe 2013-07-01 12:43 - 2013-07-01 12:42 - 00019973 ____A C:\AdwCleaner[R1].txt 2013-07-01 12:41 - 2013-07-01 12:41 - 00648201 ____A C:\Users\Chriss\Desktop\adwcleaner.exe 2013-07-01 12:29 - 2012-03-19 13:54 - 00097678 ____A C:\Windows\PFRO.log 2013-07-01 12:29 - 2009-07-14 06:45 - 00269032 ____A C:\Windows\System32\FNTCACHE.DAT 2013-06-30 23:48 - 2012-03-19 01:21 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\Origin 2013-06-30 23:48 - 2012-03-19 01:21 - 00000000 ____D C:\Users\Chriss\AppData\Local\Origin 2013-06-30 23:48 - 2012-03-19 01:20 - 00000000 ____D C:\Program Files (x86)\Origin 2013-06-30 23:43 - 2012-03-19 01:20 - 00000000 ____D C:\ProgramData\Origin 2013-06-30 23:40 - 2012-03-18 22:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-30 23:28 - 2013-06-30 23:26 - 00000000 ____D C:\Users\Chriss\Desktop\simssaveneu 2013-06-30 23:24 - 2013-06-30 23:23 - 00000000 ____D C:\Users\Chriss\Desktop\SimsInsel 2013-06-30 22:49 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\JDownloader 2013-06-30 22:34 - 2013-06-30 22:34 - 00002037 ____A C:\Users\Chriss\Desktop\JDownloader.lnk 2013-06-30 22:34 - 2012-03-19 00:35 - 00058016 ____A C:\Users\Chriss\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsWoofer 2013-06-30 22:33 - 2013-06-30 22:33 - 00000000 ____D C:\Program Files (x86)\LyricsFan 2013-06-30 22:30 - 2012-09-26 22:19 - 00000000 ____D C:\Program Files (x86)\DownloadManager 2013-06-27 20:12 - 2009-07-14 19:58 - 00697680 ____A C:\Windows\System32\perfh007.dat 2013-06-27 20:12 - 2009-07-14 19:58 - 00148976 ____A C:\Windows\System32\perfc007.dat 2013-06-27 20:12 - 2009-07-14 07:13 - 01616160 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-27 20:11 - 2012-03-18 22:39 - 00000000 ____D C:\Users\Chriss\AppData\Roaming\vlc 2013-06-25 22:27 - 2013-06-25 22:27 - 00000048 ____A C:\MyUpdateLogs.log 2013-06-25 21:53 - 2013-06-25 21:51 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister Backup 2013-06-25 02:25 - 2013-06-25 02:25 - 00000000 ____D C:\Users\Chriss\Desktop\ebay 2013-06-25 01:11 - 2013-06-25 01:11 - 00000000 ____D C:\Users\Chriss\Documents\Turbo Lister 2013-06-25 01:02 - 2013-06-25 00:59 - 00000402 ____A C:\InstallHelper.log 2013-06-25 00:58 - 2013-06-25 00:58 - 00001814 ____A C:\Users\Public\Desktop\eBay Turbo Lister 2.lnk 2013-06-25 00:58 - 2013-06-25 00:58 - 00000000 ____D C:\ProgramData\eBay 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iTunes 2013-06-22 15:07 - 2013-06-22 15:07 - 00000000 ____D C:\Program Files\iPod 2013-06-21 16:06 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-17 22:09 - 2013-06-17 22:09 - 02702378 ____A C:\Users\Chriss\Desktop\Mixer.rar 2013-06-15 14:06 - 2012-04-04 13:31 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-15 14:06 - 2012-03-19 20:44 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-13 13:03 - 2009-07-14 07:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-12 20:02 - 2013-01-23 19:29 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-12 20:02 - 2012-04-10 21:26 - 00000000 ____D C:\ProgramData\Skype 2013-06-10 15:58 - 2013-06-10 15:58 - 01044480 ___RA (eHelp Corporation.) C:\Windows\SysWOW64\roboex32.dll 2013-06-10 15:58 - 2013-06-10 15:58 - 00049152 ___RA (Blue Sky Software Corporation.) C:\Windows\SysWOW64\inetwh32.dll 2013-06-08 23:34 - 2012-04-19 15:38 - 00000000 ____D C:\Users\Chriss\AppData\Local\Deployment 2013-06-02 17:11 - 2012-03-27 21:22 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-23 03:30 ==================== End Of Log ============================ Danke |
02.07.2013, 13:40 | #9 |
/// the machine /// TB-Ausbilder | Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Java, Adobe und Firefox updaten. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.07.2013, 16:09 | #10 |
| Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Vielen Dank für deine Hilfe Soweit alles Super, werde jetzt mal Firerfox updaten |
02.07.2013, 16:50 | #11 |
/// the machine /// TB-Ausbilder | Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Bei benutzung des Browesers "FirerFox" öffnet sich sich die Suchseite "Qvo6.com |
.com, benutzung, browservirus, download, firerfox, lösen, nenne, nervige, probiert, problem, qvo6.com, suchseite, video, öffnet |