|
Plagegeister aller Art und deren Bekämpfung: Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen MediaplayerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.11.2013, 21:15 | #1 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer hallo zusammen, ich habe das problem, dass bei mir im firefox ständig wörter doppelt unterstrichen sind und als link erscheinen. es erschein ein popup, welches dann auf mediaplayertotal.com "holen media palyer" verweist. es gehen auch ständig browserfenster auf, die allerdings dann doch nicht sichtbar sind, nur kurz ein leeres fenster. ich habe combofix schon laufen lassen, allerdings ist das problem immer noch vorhanden. im anhang habe ich die log-datei eingestellt. was nu? muss ich den rechner neu installieren? ich freue mich auf eure nachricht. |
05.11.2013, 21:24 | #2 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen MediaplayerMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Welcher Helfer hat dich angewiesen, ComboFix auszuführen? ComboFix ist kein Spielzeug! So geht es los: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
08.11.2013, 19:20 | #3 | |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen MediaplayerZitat:
Ich habe das mit Combofix im Internet gelesen und einfach durchgeführt. Natürlich nach den Anweisungen der User. Anbei die Dateien. |
08.11.2013, 19:26 | #4 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Servus, du hast dir eine große Menge Adware auf den Rechner geholt... ist zwar lästig, aber nicht gefährlich. Wir kümmern uns die nächsten Tage darum. So geht es los: Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 4 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Bitte poste mit deiner nächsten Antwort
|
08.11.2013, 20:49 | #5 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Hallo Matthias, vielen Dank..Anbei die Dateien |
08.11.2013, 20:57 | #6 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Servus, Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
09.11.2013, 14:19 | #7 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer anbei die Dateien. Mit Malware gibt es derzeit keine Probleme mehr. Der Rechner läuft etwas langsamer habe ich das Gefühl. Wenn ich aktuell Google aufrufe, erscheint eine komische URL bzw. eine komische Endung der URL: https://www.google.de/?gws_rd=cr&ei=WDV-UqSrEIemtAap_IHoBw Was hälst Du von Bitdefender als Firewall-Software |
09.11.2013, 14:41 | #8 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Servus, es fehlt noch die Logdatei von SystemLook, du hast fälschlicherweise JRT nochmal gepostet. |
10.11.2013, 00:49 | #9 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer SystemLook 30.07.11 by jpshortstuff Log created at 14:03 on 09/11/2013 by DANadmin Administrator - Elevation successful ========== filefind ========== Searching for "*Datamngr*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll.vir --a---- 2071552 bytes [16:45 05/10/2013] [05:35 02/10/2013] 3D98969D76B67B3BBE47D952A375FE5E C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe.vir --a---- 3419136 bytes [16:45 05/10/2013] [05:35 02/10/2013] 9EADFB54FB0D5F5C3456ED0B59FF5102 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe.vir --a---- 3581440 bytes [16:45 05/10/2013] [05:35 02/10/2013] 642C03A6F126ABFBD21BF2BA16F526CC C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\Datamngr.dll.vir --a---- 2241024 bytes [16:45 05/10/2013] [05:35 02/10/2013] E458039D0D89DAC5371B3D066564B512 C:\Windows\Prefetch\DATAMNGRUI.EXE-D2B3D245.pf --a---- 127790 bytes [18:47 01/11/2013] [07:03 07/11/2013] 813E9779A17250ACE9BA54CEFAA6C6E2 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF.xpt --a---- 1299 bytes [19:41 08/11/2013] [05:33 02/10/2013] A745588B23A84AD6D9485321BE284EDF C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF10.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] 78DA2A21A7E6D10278616A7EA10D06BA C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF11.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] B03C610736AE5221BDA4EB8DE8702FEB C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF12.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] A95E8A604824501CEBCB682EDFB1104A C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF13.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] C10A76270DF151645F6DD92F7DBE9AF5 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF14.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] 0C87731D61A64A4FC3C610DE580D3358 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF15.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] E77B4845C1B33A7F4E9ABC84C48F9113 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF16.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] B23133F83503E93F07A34BBCC6335F48 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF17.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] BC6A382BCB9CED98E40FE44DCA2EE0C1 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF18.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] 6E3176F7D724C817C77523F0D25ED3AA C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF19.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] A0BC0C44325059485C0ADE5F9FDF5AED C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF2.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] 11999A208F90C6C3E018229D729815D0 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF20.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:34 02/10/2013] 1587DC83E45B10910EB396C25E20D181 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF21.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] 2518BC73FC099231639A06F4626B26D6 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF22.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] 5194590D4CDA06DAC9F89439C3DE2591 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF23.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] F9A527A736330D8AEC3A2BC99CAFDE2E C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF24.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] A97920811692F082383169F8D634BFC6 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF4.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] C526B0981FCE3172510503D01D61C5B7 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF5.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] 45D178856F534831DE98942314D7AE71 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF6.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] 8861F4EF30A800EC66EAC5BD45CDB55E C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF7.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] 21D2567EDBDFBAD94575216EBE6054F3 C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF8.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] 1770049059C92BD524F3E135F63D19EB C:\zoek_backup\C_Users_DANadmin_AppData_Roaming_Mozilla_Firefox_Profiles_5dd4qvbf.default_extensions_{24DC3D02-FB26-3342-DC6E-548498E7C843}\components\DatamngrHlpFF9.dll --a---- 1545216 bytes [19:41 08/11/2013] [05:35 02/10/2013] AD5E1B602936B299212A9723DF756316 Searching for "*Babylon*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\searchplugins\Babylon.xml.vir --a---- 6503 bytes [17:10 27/05/2013] [17:10 27/05/2013] 74DC31D6377EF5C780E667A5441EC849 Searching for "*BitGuard*" No files found. Searching for "*Browser Manager*" No files found. Searching for "*BrowserProtect*" No files found. Searching for "*myfree codec*" No files found. Searching for "*Iminent*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\searchplugins\iminent.xml.vir --a---- 1368 bytes [21:57 10/09/2013] [21:57 10/09/2013] 3FF67AC466058B3BE657AE19C55AB49E Searching for "*Movies Toolbar*" No files found. Searching for "*MyPC Backup*" No files found. Searching for "*Plus-HD*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-bg.exe.vir --a---- 742760 bytes [21:57 10/09/2013] [21:57 10/09/2013] A2DC266DBD45C9E008511A8691F17B83 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-bho.dll.vir --a---- 602984 bytes [21:57 10/09/2013] [21:57 10/09/2013] 34F7EB51B33D9F1899A25783AFCF779C C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-bho64.dll.vir --a---- 945000 bytes [21:57 10/09/2013] [21:57 10/09/2013] 4B386E93225DCA2135E9A29BC390BAD6 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-buttonutil.dll.vir --a---- 405352 bytes [21:57 10/09/2013] [21:57 10/09/2013] A76BBACCF541C1B5D3DDFD253BB4542A C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-buttonutil.exe.vir --a---- 343400 bytes [21:56 10/09/2013] [21:56 10/09/2013] 108EA426C87F25E2023157AE205FAF44 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-buttonutil64.dll.vir --a---- 491368 bytes [21:57 10/09/2013] [21:57 10/09/2013] 72BA5E7D31BC659C9B81BC14050DB308 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-buttonutil64.exe.vir --a---- 447848 bytes [21:56 10/09/2013] [21:56 10/09/2013] 5B56B2A08EAA4CD0F1908C9A8E0B9166 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-chromeinstaller.exe.vir --a---- 489320 bytes [21:56 10/09/2013] [21:56 10/09/2013] 8A45835D930F66593FD5AA1F245FAB6E C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-codedownloader.exe.vir --a---- 491880 bytes [21:56 10/09/2013] [21:56 10/09/2013] 43F3E84E485A1F66EBE317508B326B39 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-enabler.exe.vir --a---- 348008 bytes [21:57 10/09/2013] [21:57 10/09/2013] F8FAAA608FE02A91831EE8BBCE05A95A C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-firefoxinstaller.exe.vir --a---- 727400 bytes [21:56 10/09/2013] [21:56 10/09/2013] E5AE3F3C39F5496BEACB2B30A4270646 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-helper.exe.vir --a---- 315752 bytes [21:56 10/09/2013] [21:56 10/09/2013] 3038761C74E17A2BCC740810CEA5FC4A C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6-updater.exe.vir --a---- 367976 bytes [21:57 10/09/2013] [21:57 10/09/2013] CBC3B94BEF876E1F4FAC868CD0065378 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6\Plus-HD-1.6.ico.vir --a---- 9662 bytes [08:50 02/09/2013] [08:50 02/09/2013] 739B67DAC0C716F3DA123622BACAB424 C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Plus-HD-1.6-chromeinstaller.vir --a---- 4938 bytes [21:56 10/09/2013] [21:56 10/09/2013] 44A2F120482B540ECB8028AAEEBB3A4F C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Plus-HD-1.6-codedownloader.vir --a---- 4230 bytes [21:56 10/09/2013] [21:56 10/09/2013] AFB406F22FCE8BA3B2BC22E87807AA11 C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Plus-HD-1.6-enabler.vir --a---- 4130 bytes [21:57 10/09/2013] [21:57 10/09/2013] 4FB26A03D651AAC2CD9544DFE8295C1D C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Plus-HD-1.6-firefoxinstaller.vir --a---- 4862 bytes [21:56 10/09/2013] [21:56 10/09/2013] 7846813B64CC173243AECBFCC8CDDE52 C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Plus-HD-1.6-updater.vir --a---- 4326 bytes [21:57 10/09/2013] [21:57 10/09/2013] 82DD6891781C70DE0E540E3CA707B6B6 C:\AdwCleaner\Quarantine\C\Windows\Tasks\Plus-HD-1.6-chromeinstaller.job.vir --a---- 1908 bytes [21:56 10/09/2013] [16:56 08/11/2013] 14FAEC2623A8A92B3687A1E85DE71A81 C:\AdwCleaner\Quarantine\C\Windows\Tasks\Plus-HD-1.6-codedownloader.job.vir --a---- 1200 bytes [21:56 10/09/2013] [16:56 08/11/2013] 5B9EE38CB0922964D6513B8F12E6E575 C:\AdwCleaner\Quarantine\C\Windows\Tasks\Plus-HD-1.6-enabler.job.vir --a---- 1100 bytes [21:57 10/09/2013] [16:57 08/11/2013] 8BA4C6ADC52AB4C4F32780A4CC0A132B C:\AdwCleaner\Quarantine\C\Windows\Tasks\Plus-HD-1.6-firefoxinstaller.job.vir --a---- 1832 bytes [21:56 10/09/2013] [17:01 08/11/2013] 6A211382F624B025B720FB44C5A943B3 C:\AdwCleaner\Quarantine\C\Windows\Tasks\Plus-HD-1.6-updater.job.vir --a---- 1296 bytes [21:57 10/09/2013] [16:57 08/11/2013] B2771FC0491E793983FE11026A1CC8C4 C:\Windows\Prefetch\PLUS-HD-1.6-CHROMEINSTALLER.E-FCFAA71C.pf --a---- 52662 bytes [22:56 01/11/2013] [16:56 08/11/2013] 1B099C7DD3E36BFE546627B97394E01D C:\Windows\Prefetch\PLUS-HD-1.6-CODEDOWNLOADER.EX-80E855FA.pf --a---- 45594 bytes [22:56 01/11/2013] [16:56 08/11/2013] 758A7B8AD3484F855ED8AC77FA9704A4 C:\Windows\Prefetch\PLUS-HD-1.6-ENABLER.EXE-5F25D7DD.pf --a---- 25378 bytes [22:57 01/11/2013] [16:57 08/11/2013] 2C65C74EBE48A25BBECCC2B5D1366C24 C:\Windows\Prefetch\PLUS-HD-1.6-FIREFOXINSTALLER.-235E0EC5.pf --a---- 31478 bytes [22:56 01/11/2013] [16:56 08/11/2013] ABB4E1641C9EA7767546028B8F9175E4 C:\Windows\Prefetch\PLUS-HD-1.6-UPDATER.EXE-61E07451.pf --a---- 49694 bytes [22:57 01/11/2013] [16:57 08/11/2013] 31DFF1368E1FBC4926DBAAD90DB6D049 Searching for "*BabSolution*" No files found. Searching for "*DealPly*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\102_dealply_m.js.vir --a---- 1768 bytes [19:16 05/11/2013] [19:16 05/11/2013] AC4A6605DB6DAB94639294F200DBDFDD C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\102_dealply_m.js.vir --a---- 2247 bytes [17:29 06/11/2013] [20:25 05/11/2013] FEF39E0386D6094AF47A936CAAC7C00D C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Dealply.vir --a---- 3524 bytes [17:13 27/05/2013] [17:13 27/05/2013] 442957DBB8575B5034551F3D6028F307 C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\102_dealply_m.js.vir --a---- 1768 bytes [21:56 10/09/2013] [21:56 10/09/2013] AC4A6605DB6DAB94639294F200DBDFDD C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\102_dealply_m.js.vir --a---- 1768 bytes [09:03 19/10/2013] [14:40 18/10/2013] AC4A6605DB6DAB94639294F200DBDFDD Searching for "*crossrider*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\crossriderManifest.json.vir --a---- 736 bytes [19:16 05/11/2013] [19:16 05/11/2013] D57B5C9DF4A2CEF18F305804FB096399 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 5955 bytes [19:16 05/11/2013] [19:16 05/11/2013] A15314F10FA928B5C242EDDC4B91F503 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [19:16 05/11/2013] [19:16 05/11/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2220 bytes [19:16 05/11/2013] [19:16 05/11/2013] EC3226E86137F361EEEF8F1244A0225A C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\js\lib\crossriderAPI.js.vir --a---- 11366 bytes [19:16 05/11/2013] [19:16 05/11/2013] 7B3ADEF52BEDD686D98A3C0F45278020 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 7056 bytes [17:29 06/11/2013] [20:25 05/11/2013] 5C624086605726A12BFEC9C83F5E0CF2 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [17:29 06/11/2013] [20:25 05/11/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2234 bytes [17:29 06/11/2013] [20:25 05/11/2013] AFC19F46F2798D47DCE5568D444A571A C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\skin\crossrider_statusbar.png.vir --a---- 1361 bytes [17:29 06/11/2013] [20:25 05/11/2013] 8B1EB9CB80417EC0022D278A44AB1DC7 C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\crossriderManifest.json.vir --a---- 737 bytes [21:56 10/09/2013] [21:56 10/09/2013] 5ACE8F7658D482C935F1498DF3258532 C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 5955 bytes [21:56 10/09/2013] [21:56 10/09/2013] A15314F10FA928B5C242EDDC4B91F503 C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [21:56 10/09/2013] [21:56 10/09/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2220 bytes [21:56 10/09/2013] [21:56 10/09/2013] EC3226E86137F361EEEF8F1244A0225A C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.69_0\js\lib\crossriderAPI.js.vir --a---- 11366 bytes [21:56 10/09/2013] [21:56 10/09/2013] 7B3ADEF52BEDD686D98A3C0F45278020 C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 6912 bytes [06:28 31/10/2013] [06:28 31/10/2013] 19733A843BECAB002D5C00D94FFE2796 C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [09:03 19/10/2013] [14:40 18/10/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2234 bytes [09:03 19/10/2013] [14:40 18/10/2013] AFC19F46F2798D47DCE5568D444A571A C:\Qoobox\Quarantine\C\Users\DANadmin\AppData\Roaming\Mozilla\Firefox\Profiles\5dd4qvbf.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com\skin\crossrider_statusbar.png.vir --a---- 1361 bytes [09:03 19/10/2013] [14:40 18/10/2013] 8B1EB9CB80417EC0022D278A44AB1DC7 Searching for "*torch*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo\1.2.0.4501_0\images\torch_32x32.png.vir --a---- 1965 bytes [16:51 05/10/2013] [16:51 05/10/2013] ED3D8A64FF68A01413FBB43C722A60A6 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo\1.2.0.4501_0\plugin\TorchPlugin.dll.vir --a---- 170848 bytes [16:51 05/10/2013] [16:51 05/10/2013] 4D94AFDA9AB1ED26717938840D241673 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo\1.2.0.4617_0\images\torch_32x32.png.vir --a---- 1965 bytes [14:31 15/10/2013] [14:31 15/10/2013] ED3D8A64FF68A01413FBB43C722A60A6 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\cipmepknanmbbaneimacddfemfbfgpgo\1.2.0.4617_0\plugin\TorchPlugin.dll.vir --a---- 170848 bytes [14:31 15/10/2013] [14:31 15/10/2013] 627D11DA34173B445C29508B00005A2A C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\images\torch_32x32.png.vir --a---- 1965 bytes [16:51 05/10/2013] [16:51 05/10/2013] ED3D8A64FF68A01413FBB43C722A60A6 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\images\.svn\prop-base\torch_32x32.png.svn-base.vir --a---- 53 bytes [16:51 05/10/2013] [16:51 05/10/2013] 113136892F2137AA0116093A524ADE0B C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\images\.svn\text-base\torch_32x32.png.svn-base.vir --a---- 1965 bytes [16:51 05/10/2013] [16:51 05/10/2013] ED3D8A64FF68A01413FBB43C722A60A6 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\plugin\TorchPlugin.dll.vir --a---- 193024 bytes [16:51 05/10/2013] [16:51 05/10/2013] 23E376C3FDAF6773E920A9AAE6E9D8C5 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\plugin\.svn\prop-base\TorchPlugin.dll.svn-base.vir --a---- 53 bytes [16:51 05/10/2013] [16:51 05/10/2013] 113136892F2137AA0116093A524ADE0B C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\plugin\.svn\text-base\TorchPlugin.dll.svn-base.vir --a---- 193024 bytes [16:51 05/10/2013] [16:51 05/10/2013] 23E376C3FDAF6773E920A9AAE6E9D8C5 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\images\torch_32x32.png.vir --a---- 1965 bytes [14:31 15/10/2013] [14:31 15/10/2013] ED3D8A64FF68A01413FBB43C722A60A6 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\images\.svn\prop-base\torch_32x32.png.svn-base.vir --a---- 53 bytes [14:31 15/10/2013] [14:31 15/10/2013] 113136892F2137AA0116093A524ADE0B C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\images\.svn\text-base\torch_32x32.png.svn-base.vir --a---- 1965 bytes [14:31 15/10/2013] [14:31 15/10/2013] ED3D8A64FF68A01413FBB43C722A60A6 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\plugin\TorchPlugin.dll.vir --a---- 193024 bytes [14:31 15/10/2013] [14:31 15/10/2013] 23E376C3FDAF6773E920A9AAE6E9D8C5 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\plugin\.svn\prop-base\TorchPlugin.dll.svn-base.vir --a---- 53 bytes [14:31 15/10/2013] [14:31 15/10/2013] 113136892F2137AA0116093A524ADE0B C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\plugin\.svn\text-base\TorchPlugin.dll.svn-base.vir --a---- 193024 bytes [14:31 15/10/2013] [14:31 15/10/2013] 23E376C3FDAF6773E920A9AAE6E9D8C5 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\lecpjhggilhbceadobnggaagnpfpafhg\25.0.0.4508_0\TorchHelper.dll.vir --a---- 267104 bytes [16:51 05/10/2013] [16:51 05/10/2013] 8AE4CE9B0668F61BF4C6B8037F5ABBCE C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\lecpjhggilhbceadobnggaagnpfpafhg\25.0.0.4626_0\TorchHelper.dll.vir --a---- 267104 bytes [14:31 15/10/2013] [14:31 15/10/2013] 1DA0F42D50A77FD581F8F030D4EBE43C C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed\1.0.0.4501_0\torch_music_icon19x19.png.vir --a---- 563 bytes [16:51 05/10/2013] [16:51 05/10/2013] 2012D35594CE75FB35170D82FB3415A2 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed\1.0.0.4501_0\images\torch_music_icon19x19.png.vir --a---- 681 bytes [16:51 05/10/2013] [16:51 05/10/2013] FD9B24B9544127C00601CB50FC774ACE C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed\1.0.0.4501_0\images\torch_search_button.png.vir --a---- 1256 bytes [16:51 05/10/2013] [16:51 05/10/2013] 4FBA46B72AA38334F7D36166A8406AE7 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed\1.0.0.4617_0\torch_music_icon19x19.png.vir --a---- 563 bytes [14:31 15/10/2013] [14:31 15/10/2013] 2012D35594CE75FB35170D82FB3415A2 C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed\1.0.0.4617_0\images\torch_music_icon19x19.png.vir --a---- 681 bytes [14:31 15/10/2013] [14:31 15/10/2013] FD9B24B9544127C00601CB50FC774ACE C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\ohimbkoaphfnmekmfppijeblmkncneed\1.0.0.4617_0\images\torch_search_button.png.vir --a---- 1256 bytes [14:31 15/10/2013] [14:31 15/10/2013] 4FBA46B72AA38334F7D36166A8406AE7 ========== folderfind ========== Searching for "*Datamngr*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr d------ [18:47 08/11/2013] Searching for "*Babylon*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\Babylon d------ [18:47 08/11/2013] Searching for "*BitGuard*" No folders found. Searching for "*Browser Manager*" No folders found. Searching for "*BrowserProtect*" No folders found. Searching for "*myfree codec*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\myfree codec d------ [18:47 08/11/2013] C:\AdwCleaner\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec d------ [18:47 08/11/2013] Searching for "*Iminent*" C:\Users\DANadmin\AppData\LocalLow\SIEN SA\iminent d------ [21:57 10/09/2013] Searching for "*Movies Toolbar*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar d------ [18:47 08/11/2013] Searching for "*MyPC Backup*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup d------ [18:47 08/11/2013] Searching for "*Plus-HD*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\Plus-HD-1.6 d------ [18:47 08/11/2013] Searching for "*BabSolution*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\BabSolution d------ [18:47 08/11/2013] Searching for "*DealPly*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Roaming\DealPly d------ [18:47 08/11/2013] Searching for "*crossrider*" No folders found. Searching for "*torch*" C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch d------ [18:47 08/11/2013] C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4486_0\plugin\TorchShareHelper.plugin d------ [18:47 08/11/2013] C:\AdwCleaner\Quarantine\C\Users\DANadmin\AppData\Local\torch\User Data\Default\Extensions\gimjmfipknpppbpmkdenjjpfhobiiojk\1.1.0.4587_0\plugin\TorchShareHelper.plugin d------ [18:47 08/11/2013] C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_torch.exe_c422fe13601c7267cb7d3cdaad7b99e9e098ee4_03817020 d----c- [16:52 05/10/2013] C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\AppCrash_torch.exe_c422fe13601c7267cb7d3cdaad7b99e9e098ee4_03817020 d----c- [16:52 05/10/2013] C:\Users\DANadmin\Documents\My Music\Torch d------ [22:17 16/05/2013] ========== regfind ========== Searching for "Datamngr" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Datamngr] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0B9B89AD-495A-4A03-981D-645479AE7AF6}] "AppPath"="C:\PROGRA~2\MOVIES~1\Datamngr\SRTOOL~2\IE" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{314B40A6-3664-4FC4-859F-F9384DC41001}] "AppPath"="C:\PROGRA~2\MOVIES~1\Datamngr\SRTOOL~1\IE" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6717CEF8-874E-4EA8-8E1D-CA9B07749B60}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F3DE482-6DE4-4AA7-9460-34519DDEB3F5}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3BEE9F71-38ED-4F50-BBEE-7F71504EE19B}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5D4C5708-ED46-4B4C-A101-A28228DD3EC7}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6717CEF8-874E-4EA8-8E1D-CA9B07749B60}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F3DE482-6DE4-4AA7-9460-34519DDEB3F5}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3BEE9F71-38ED-4F50-BBEE-7F71504EE19B}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5D4C5708-ED46-4B4C-A101-A28228DD3EC7}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6717CEF8-874E-4EA8-8E1D-CA9B07749B60}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F3DE482-6DE4-4AA7-9460-34519DDEB3F5}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3BEE9F71-38ED-4F50-BBEE-7F71504EE19B}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5D4C5708-ED46-4B4C-A101-A28228DD3EC7}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" Searching for "Babylon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}] "DllName"="BabylonToolbar.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}] "DllName"="BabylonToolbarTlbr.dll" Searching for "BitGuard" No data found. Searching for "Browser Manager" No data found. Searching for "BrowserProtect" No data found. Searching for "myfree codec" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{FD501041-8EBE-11CE-8183-00AA00577DA2}] "FriendlyName"="MyFree Codec Filter" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{FD501041-8EBE-11CE-8183-00AA00577DA2}] "FriendlyName"="MyFree Codec Filter" Searching for "Iminent" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "prdct"="iminent" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "prtnrid"="iminent" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "tlbrsrchurl"="http%3A%2F%2Fstart%2Eiminent%2Ecom%2F%3Fref%3Dtoolbarm%23q%3D" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"="iminent.com" [HKEY_CURRENT_USER\Software\SIEN SA\iminent] [HKEY_CURRENT_USER\Software\SIEN SA\iminent] "lastB"="hxxp://start.iminent.com/?appId=C4D60F63-6E8C-4793-BD7A-AE2BDB2CFC6C" [HKEY_CURRENT_USER\Software\SIEN SA\iminent\iestrg] "prdct"="iminent" [HKEY_CURRENT_USER\Software\SIEN SA\iminent\iestrg] "prtnrid"="iminent" [HKEY_CURRENT_USER\Software\SIEN SA\iminent\iestrg] "tlbrsrchurl"="http%3A%2F%2Fstart%2Eiminent%2Ecom%2F%3Fref%3Dtoolbarm%23q%3D" [HKEY_CURRENT_USER\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\SIEN SA\iminent] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Iminent\"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Iminent\inst\Bootstrapper\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\Program Files (x86)\Iminent\inst\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] "00000000000000000000000000000000"="C:\Program Files (x86)\Iminent\inst\Bootstrapper\Bootstrapper.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] "00000000000000000000000000000000"="02:\SOFTWARE\Iminent\AppInstanceUid" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C] "00000000000000000000000000000000"="C:\Program Files (x86)\Iminent\StartWeb.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD] "00000000000000000000000000000000"="C:\Program Files (x86)\Iminent\USearch.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287] "00000000000000000000000000000000"="C:\Program Files (x86)\Iminent\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7] "00000000000000000000000000000000"="C:\Program Files (x86)\Iminent\SearchTheWeb.xml" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SIEN SA\iminent] [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent] [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "prdct"="iminent" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "prtnrid"="iminent" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "tlbrsrchurl"="http%3A%2F%2Fstart%2Eiminent%2Ecom%2F%3Fref%3Dtoolbarm%23q%3D" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Internet Explorer\SearchScopes] "DoNotAskAgain"="iminent.com" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent] [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent] "lastB"="hxxp://start.iminent.com/?appId=C4D60F63-6E8C-4793-BD7A-AE2BDB2CFC6C" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "prdct"="iminent" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "prtnrid"="iminent" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent\iestrg] "tlbrsrchurl"="http%3A%2F%2Fstart%2Eiminent%2Ecom%2F%3Fref%3Dtoolbarm%23q%3D" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\SIEN SA\iminent] [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\SIEN SA\iminent] Searching for "Movies Toolbar" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6717CEF8-874E-4EA8-8E1D-CA9B07749B60}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F3DE482-6DE4-4AA7-9460-34519DDEB3F5}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3BEE9F71-38ED-4F50-BBEE-7F71504EE19B}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5D4C5708-ED46-4B4C-A101-A28228DD3EC7}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6717CEF8-874E-4EA8-8E1D-CA9B07749B60}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F3DE482-6DE4-4AA7-9460-34519DDEB3F5}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3BEE9F71-38ED-4F50-BBEE-7F71504EE19B}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5D4C5708-ED46-4B4C-A101-A28228DD3EC7}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{6717CEF8-874E-4EA8-8E1D-CA9B07749B60}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0F3DE482-6DE4-4AA7-9460-34519DDEB3F5}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{3BEE9F71-38ED-4F50-BBEE-7F71504EE19B}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{5D4C5708-ED46-4B4C-A101-A28228DD3EC7}"="v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~2\IE\dtUser.exe|Name=Movies Toolbar (Dist. by Bandoo Media, Inc.) DTX Broker|" Searching for "MyPC Backup" No data found. Searching for "Plus-HD" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{111F7D9D-D23A-4A81-BF69-19B3D3CADA52}] "Path"="\Plus-HD-1.6-enabler" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72EF1523-7E84-48B0-95E4-15E2DC27CE1D}] "Path"="\Plus-HD-1.6-updater" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB88F6C3-92ED-437E-8C8C-0284BF705EE5}] "Path"="\Plus-HD-1.6-firefoxinstaller" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F8B3CD-C8FF-4E0C-9CC5-1DD9F38ACDB7}] "Path"="\Plus-HD-1.6-chromeinstaller" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2029951-1B50-4D8F-930C-8DEFB360F4B7}] "Path"="\Plus-HD-1.6-codedownloader" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-1.6-chromeinstaller] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-1.6-codedownloader] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-1.6-enabler] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-1.6-firefoxinstaller] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plus-HD-1.6-updater] Searching for "BabSolution" No data found. Searching for "DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C88E60A-A9B6-43F2-9679-85CC7DC0D76C}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] Searching for "crossrider" No data found. Searching for "torch" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\UserChoice] "Progid"="TorchFlvPlayer.flv" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_CURRENT_USER\Software\Classes\.flv] "TorchFlvPlayer.flv_backup"="" [HKEY_CURRENT_USER\Software\Classes\.flv] @="TorchFlvPlayer.flv" [HKEY_CURRENT_USER\Software\Classes\TorchFlvPlayer.flv] [HKEY_CURRENT_USER\Software\Classes\TorchFlvPlayer.flv\DefaultIcon] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe,0" [HKEY_CURRENT_USER\Software\Classes\TorchFlvPlayer.flv\shell\open] @="Open with TorchFlvPlayer" [HKEY_CURRENT_USER\Software\Classes\TorchFlvPlayer.flv\shell\open\command] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe %L" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bmp\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dib\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.flv] "TorchFlvPlayer.flv_backup"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.flv] @="TorchFlvPlayer.flv" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gif\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ico\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.jfif\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.jpe\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.jpg\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mfp\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdf\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.png\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.URL\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.webm\OpenWithList\Torch.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TorchFlvPlayer.flv] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TorchFlvPlayer.flv\DefaultIcon] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe,0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TorchFlvPlayer.flv\shell\open] @="Open with TorchFlvPlayer" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TorchFlvPlayer.flv\shell\open\command] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe %L" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv\UserChoice] "Progid"="TorchFlvPlayer.flv" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\ftp\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\https\UserChoice] "Progid"="TorchHTML.TE2P5TNQCOBVGDDKAE542J3UPY" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\.flv] "TorchFlvPlayer.flv_backup"="" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\.flv] @="TorchFlvPlayer.flv" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\TorchFlvPlayer.flv] [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\TorchFlvPlayer.flv\DefaultIcon] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe,0" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\TorchFlvPlayer.flv\shell\open] @="Open with TorchFlvPlayer" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\Classes\TorchFlvPlayer.flv\shell\open\command] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe %L" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\.flv] "TorchFlvPlayer.flv_backup"="" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\.flv] @="TorchFlvPlayer.flv" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\TorchFlvPlayer.flv] [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\TorchFlvPlayer.flv\DefaultIcon] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe,0" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\TorchFlvPlayer.flv\shell\open] @="Open with TorchFlvPlayer" [HKEY_USERS\S-1-5-21-4026774876-2766942307-3061109094-1004_Classes\TorchFlvPlayer.flv\shell\open\command] @="C:\Users\DANadmin\AppData\Local\Torch\Plugins\Video\TorchFlvPlayer\TorchFlvPlayer.exe %L" Searching for " " [HKEY_LOCAL_MACHINE\SOFTWARE\Canon\WIA\Devices\MX850 series] "ProductId"="MX850 " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell] "ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32] "ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> -= EOF =- konnte die Datei irgendwie nicht laden, daher habe ich den Inhalt direkt kopiert! |
10.11.2013, 12:02 | #10 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Servus, wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss daran räumen wir auf und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start Task: {111F7D9D-D23A-4A81-BF69-19B3D3CADA52} - \Plus-HD-1.6-enabler No Task File Task: {3DB023AE-47BB-48EA-90D0-E1EDC2B987D2} - System32\Tasks\0 => Iexplore.exe Task: {6C88E60A-A9B6-43F2-9679-85CC7DC0D76C} - \DealPly No Task File Task: {72BE9DCC-D57F-4275-B68B-EAEB5F914885} - \EPUpdater No Task File Task: {72EF1523-7E84-48B0-95E4-15E2DC27CE1D} - \Plus-HD-1.6-updater No Task File Task: {BB88F6C3-92ED-437E-8C8C-0284BF705EE5} - \Plus-HD-1.6-firefoxinstaller No Task File Task: {DDD69A80-2A9B-44BA-B3D9-3DCB576B852B} - System32\Tasks\4913 => C:\Users\DANadmin\AppData\Local\Temp\launchie.vbsC:\Users\DANadmin\AppData\Local\Temp\launchie.vbs //B Task: {E0F8B3CD-C8FF-4E0C-9CC5-1DD9F38ACDB7} - \Plus-HD-1.6-chromeinstaller No Task File Task: {E2029951-1B50-4D8F-930C-8DEFB360F4B7} - \Plus-HD-1.6-codedownloader No Task File C:\Users\DANadmin\Documents\My Music\Torch Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Datamngr" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0B9B89AD-495A-4A03-981D-645479AE7AF6}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{314B40A6-3664-4FC4-859F-F9384DC41001}" /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v {6717CEF8-874E-4EA8-8E1D-CA9B07749B60} /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v {0F3DE482-6DE4-4AA7-9460-34519DDEB3F5} /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v {3BEE9F71-38ED-4F50-BBEE-7F71504EE19B} /f Reg: reg delete "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules" /v {5D4C5708-ED46-4B4C-A101-A28228DD3EC7} /f Reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4026774876-2766942307-3061109094-1004\Software\SIEN SA\iminent" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes" /v DoNotAskAgain /f Reg: reg delete "HKEY_CURRENT_USER\Software\SIEN SA\iminent" /f Reg: reg delete "HKEY_CURRENT_USER\Software\Classes\TorchFlvPlayer.flv" /f end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
10.11.2013, 22:33 | #11 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer hallo, anbei die Dateien.. |
11.11.2013, 14:33 | #12 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Servus, du sollst einen Fix mit FRST machen und keinen Scan... liest du auch das, was ich schreibe? FRST-Fix durchführen und Logdatei dazu posten. |
11.11.2013, 20:21 | #13 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer hallo, jetzt weiß ich nicht, warum die letzte nachricht nicht durchgegangen ist. Anbei nochmals die Nachricht. |
11.11.2013, 20:23 | #14 |
| Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer sorry, hatte die falsche Datei gepostet! Viele Grüße |
12.11.2013, 19:00 | #15 |
/// TB-Ausbilder | Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer Servus, Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Schritt 2 Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software / Programme deinstallieren--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Hacken für den McAfee SecurityScan bzw. Google Chrome. Schritt 3
Prüfe bitte auch (regelmässig) ob folgende Links fehlende Updates bei deinen Plugins zeigen: Schritt 4 Die Reihenfolge ist hier entscheidend.
Schritt 5 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von Registry Cleanern. Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link: Miekemoes Blogspot ( MVP ) Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Themen zu Firefox erscheinen doppelt unterstichene Wörter und es erschein ein Verweis auf "MediaPlayerTotal" Holen Mediaplayer |
anhang, browserfenster, combofix, doppel, doppelt, doppelt unterstrichen, erscheine, erscheinen, firefox, freue, hallo zusammen, holen, installiere, installieren, laufe, laufen, leeres, link, log-datei, mediaplayer, mediaplayertotal, mediaplayertotal.com, nachricht, neu, nicht sichtbar, popup, problem, rechner, sichtbar, unterstrichen, zusammen |