|
Plagegeister aller Art und deren Bekämpfung: Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
28.11.2013, 16:47 | #1 |
| Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 Huhu, seit ein paar Tagen habe ich ein paar Probleme mit Mozilla. Ständig öffnen sich Fenster (akamaihd.net) die aber dann auch nicht richtig angezeigt werden können. Wernebanner und gewisse Textanzeigen sind ganz verschwunden, Seiten dadurch anders aufgebaut und es steht überall von Ad´sby PlusHD. Ich weiss dass HD nerviger Adware ist und eigentlich habe ich es nicht aktiviert aber dennoch habe ich dadurch mit Mozilla Probleme. Vor allem nervt dass sich ständig neue Fenster öffnen. Jemand ne Idee wie ich das loswerden kann und das meine Seiten wieder richtig angezeigt werden? |
28.11.2013, 17:28 | #2 |
/// TB-Ausbilder | Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
28.11.2013, 17:46 | #3 |
| Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-11-2013 01 Ran by Sonne (administrator) on HARLEY-DAVIDSON on 28-11-2013 17:44:31 Running from C:\Users\Sonne\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHndHkb.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Conduit) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (Conduit) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (Conduit) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (Conduit) C:\Users\Sonne\Desktop\AdwCleaner_brff.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Farbar) C:\Users\Sonne\Desktop\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-09] (Synaptics Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [PfNet] - C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6310912 2010-06-24] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [188264 2009-07-30] (FUJITSU LIMITED) HKLM\...\Run: [FDM7] - C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164712 2009-11-26] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [157544 2009-10-15] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [35176 2009-10-15] (FUJITSU LIMITED) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor) HKLM\...\Run: [ConMgr] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe [535440 2009-12-24] (CSR, plc) HKLM\...\Run: [CSRSkype] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe [431504 2009-12-24] (CSR, plc) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -update plugin [829832 2013-10-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LoadFUJ02E3] - C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe [36712 2009-10-08] (FUJITSU LIMITED) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [47976 2009-10-09] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] () HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1316640 2013-10-31] (Conduit) AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1008928 2013-10-31] (Conduit) Startup: C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV= StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&q={searchTerms}&SSPV= BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default FF NetworkProxy: "type", 0 FF Homepage: hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV= FF SelectedSearchEngine: Conduit Search FF NewTab: hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Visualisateur 3D de 20-20 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\2020Player_IKEA@2020Technologies.com FF Extension: Plus-HD-1.6 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com FF Extension: Plus-HD-2.5 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\75c9b989-a6e6-4455-971f-45304161eb23@02648b91-49b2-4d7f-99ef-7e959a8e6505.com FF Extension: noscript - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= CHR HomePage: http:\/\/search.conduit.com\/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV= CHR RestoreOnStartup: "http:\/\/search.conduit.com\/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV="],"restore_on_startup":4},"tabs":{"use_compact_navigation_bar":false,"use_vertical_tabs":false},"webkit":{"webprefs":{"allow_running_insecure_content" CHR Extension: (DealPly Shopping) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma\3.5.3.0_0 CHR Extension: (Plus-HD-2.5) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0 CHR Extension: (Plus-HD-1.6) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [1735968 2013-10-31] (Conduit) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [330240 2010-06-24] (FUJITSU LIMITED) R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2009-07-30] (FUJITSU LIMITED) R2 VFPRadioSupportService; C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [145840 2009-12-24] (CSR, plc) ==================== Drivers (Whitelisted) ==================== R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2009-12-24] (CSR, plc) R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] R4 GEARAspiWDM; system32\DRIVERS\GEARAspiWDM.sys [x] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-28 17:44 - 2013-11-28 17:44 - 01958850 _____ (Farbar) C:\Users\Sonne\Desktop\FRST64(1).exe 2013-11-28 17:44 - 2013-11-28 17:44 - 00014781 _____ C:\Users\Sonne\Desktop\FRST.txt 2013-11-28 16:35 - 2013-11-28 16:39 - 00000000 ____D C:\Users\Sonne\AppData\Local\Mobogenie 2013-11-28 16:35 - 2013-11-28 16:36 - 00000000 ____D C:\Users\Sonne\AppData\Roaming\newnext.me 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\SearchProtect 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\.android 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Program Files (x86)\SearchProtect 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 _____ C:\Users\Sonne\daemonprocess.txt 2013-11-28 16:34 - 2013-11-28 16:34 - 01125984 _____ (Conduit) C:\Users\Sonne\Desktop\AdwCleaner_brff.exe 2013-11-22 21:56 - 2013-11-28 16:01 - 00001008 _____ C:\Windows\setupact.log 2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log 2013-11-20 10:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 11:45 - 2013-11-16 11:51 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka 2013-11-13 09:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 09:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 09:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 09:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 09:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 09:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 09:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 09:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 09:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 09:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 09:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 09:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 09:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 09:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 09:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 09:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 09:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 09:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 09:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 09:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 09:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 09:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 09:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 09:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 09:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 09:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 09:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 09:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-11-28 17:45 - 2013-11-28 17:44 - 00014781 _____ C:\Users\Sonne\Desktop\FRST.txt 2013-11-28 17:44 - 2013-11-28 17:44 - 01958850 _____ (Farbar) C:\Users\Sonne\Desktop\FRST64(1).exe 2013-11-28 17:41 - 2013-03-28 19:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-28 17:22 - 2011-09-30 22:16 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-28 16:39 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\Mobogenie 2013-11-28 16:36 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Roaming\newnext.me 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\SearchProtect 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\.android 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Program Files (x86)\SearchProtect 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 _____ C:\Users\Sonne\daemonprocess.txt 2013-11-28 16:35 - 2013-10-02 19:36 - 00000000 ____D C:\Users\Sonne\AppData\Local\cache 2013-11-28 16:35 - 2011-09-30 22:23 - 00000000 ____D C:\Users\Sonne 2013-11-28 16:34 - 2013-11-28 16:34 - 01125984 _____ (Conduit) C:\Users\Sonne\Desktop\AdwCleaner_brff.exe 2013-11-28 16:01 - 2013-11-22 21:56 - 00001008 _____ C:\Windows\setupact.log 2013-11-28 14:55 - 2013-06-07 20:17 - 01918745 _____ C:\Windows\WindowsUpdate.log 2013-11-28 14:55 - 2011-09-30 22:16 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-25 14:29 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-25 14:29 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log 2013-11-22 20:54 - 2011-02-14 13:43 - 00000000 ____D C:\Windows\Panther 2013-11-21 08:25 - 2012-04-26 20:52 - 00006144 ____H C:\Users\Sonne\Desktop\photothumb.db 2013-11-20 13:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 10:15 - 2011-02-14 13:57 - 00697322 _____ C:\Windows\system32\perfh007.dat 2013-11-20 10:15 - 2011-02-14 13:57 - 00148328 _____ C:\Windows\system32\perfc007.dat 2013-11-20 10:15 - 2009-07-14 06:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-20 10:09 - 2011-09-30 22:34 - 00001431 _____ C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-20 10:08 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-20 10:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-17 21:01 - 2011-09-30 22:24 - 00000000 ____D C:\Users\Sonne\AppData\Local\Windows Live 2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 11:51 - 2013-11-16 11:45 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka 2013-11-15 15:25 - 2013-09-09 14:44 - 00002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-13 10:40 - 2013-07-09 10:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-11 05:50 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-04 01:13 - 2011-04-16 11:56 - 01591930 _____ C:\Windows\SysWOW64\PerfStringBackup.INI Some content of TEMP: ==================== C:\Users\Sonne\AppData\Local\Temp\nsc9D1D.exe C:\Users\Sonne\AppData\Local\Temp\nsnE018.exe C:\Users\Sonne\AppData\Local\Temp\nsnE325.exe C:\Users\Sonne\AppData\Local\Temp\nssA03A.exe C:\Users\Sonne\AppData\Local\Temp\nsx9A8D.exe C:\Users\Sonne\AppData\Local\Temp\nsxE622.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 10:57 ==================== End Of Log ============================ |
28.11.2013, 17:54 | #4 |
/// TB-Ausbilder | Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 Servus, Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 4 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Bitte poste mit deiner nächsten Antwort
|
29.11.2013, 13:14 | #5 |
| Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.013 - Bericht erstellt am 28/11/2013 um 19:05:52 # Updated 24/11/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Sonne - HARLEY-DAVIDSON # Gestartet von : C:\Users\Sonne\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : CltMngSvc ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\Searchprotect Ordner Gelöscht : C:\Users\Sonne\AppData\Local\Searchprotect Ordner Gelöscht : C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma Ordner Gelöscht : C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh Datei Gelöscht : C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk Datei Gelöscht : C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\searchplugins\conduit-search.xml Datei Gelöscht : C:\Windows\System32\Tasks\Dealply Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate Datei Gelöscht : C:\Windows\System32\Tasks\QtraxPlayer ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Plus-HD-1.6 Schlüssel Gelöscht : HKLM\Software\SearchProtect Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v25.0.1 (de) [ Datei : C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\prefs.js ] Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51"); Zeile gelöscht : user_pref("browser.search.defaultenginename", "Conduit Search"); Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV="); Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.js", "\n\n /************************************************************************************\[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_13.name", "CrossriderAppUtils"); Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_14.name", "CrossriderUtils"); Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...] Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_78.name", "CrossriderInfo"); Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.js", "\n\n /************************************************************************************\[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_13.name", "CrossriderAppUtils"); Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_14.name", "CrossriderUtils"); Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n appAP[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...] Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_78.name", "CrossriderInfo"); Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...] Zeile gelöscht : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc"); Zeile gelöscht : user_pref("extentions.webcake.installId", "4fc5a929-8db3-4ed8-ab9d-4deb15a91b9f"); -\\ Google Chrome v31.0.1650.57 [ Datei : C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage Gelöscht : icon_url ************************* AdwCleaner[R0].txt - [9649 octets] - [28/11/2013 19:05:13] AdwCleaner[S0].txt - [8724 octets] - [28/11/2013 19:05:52] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8784 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Home Premium x64 Ran by Sonne on 28.11.2013 at 19:11:16,09 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B? Value Name Type Value Data ======================================================================================== NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\firstsearch ~~~ Files Successfully deleted: [File] "C:\Users\Sonne\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com" ~~~ Folders Successfully deleted: [Folder] "C:\Users\Sonne\AppData\Roaming\zip opener packages" Successfully deleted: [Folder] "C:\Users\Sonne\music\qtrax media library" ~~~ FireFox Successfully deleted: [Folder] C:\Users\Sonne\AppData\Roaming\mozilla\firefox\profiles\dxajxy9v.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com Successfully deleted: [Folder] C:\Users\Sonne\AppData\Roaming\mozilla\firefox\profiles\dxajxy9v.default\extensions\75c9b989-a6e6-4455-971f-45304161eb23@02648b91-49b2-4d7f-99ef-7e959a8e6505.com Emptied folder: C:\Users\Sonne\AppData\Roaming\mozilla\firefox\profiles\dxajxy9v.default\minidumps [11 files] ~~~ Chrome Successfully deleted: [Folder] C:\Users\Sonne\appdata\local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma Successfully deleted: [Folder] C:\Users\Sonne\appdata\local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.11.2013 at 19:17:50,40 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.28.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16428 Sonne :: HARLEY-DAVIDSON [Administrator] 28.11.2013 19:21:13 mbam-log-2013-11-28 (19-21-13).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 231094 Laufzeit: 3 Minute(n), 31 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 1 C:\Users\Sonne\AppData\Local\Temp\CT3317209 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 10 C:\$RECYCLE.BIN\S-1-5-21-2983943463-2176006230-4185877932-1001\$RL3VN7J.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsc9D1D.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsnE018.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsnE325.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nssA03A.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsx9A8D.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsxE622.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsn6539.tmp\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\nsn6539.tmp\BI\BI.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Sonne\AppData\Local\Temp\CT3317209\ddt.csf (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Zoek.exe Version 4.0.0.5 Updated 24-November-2013 Tool run by Sonne on 28.11.2013 at 19:35:27,09. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Sonne\Desktop\zoekzip\zoek.exe [Script inserted] ==== System Restore Info ====================== 28.11.2013 19:37:00 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\prefs.js: user_pref("browser.search.useDBForOrder", true); Added to C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\prefs.js: ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs__1943_.backup ==== Deleting Files \ Folders ====================== C:\Users\Sonne\daemonprocess.txt deleted C:\Users\Sonne\.android deleted C:\Users\Sonne\AppData\Roaming\newnext.me deleted C:\Users\Sonne\AppData\Local\Mobogenie deleted C:\Users\Sonne\AppData\Local\emaze deleted C:\Windows\sysWoW64\config\systemprofile\AppData\Local\PackageAware deleted C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk deleted "C:\Users\Sonne\AppData\Roaming\Uhheom\yzav.ibu" deleted "C:\Users\Sonne\AppData\Roaming\Viemez\ezsel.iqa" deleted "C:\Users\Sonne\AppData\Roaming\Xouwy" deleted "C:\Users\Sonne\AppData\Roaming\Uhheom" deleted "C:\Users\Sonne\AppData\Roaming\Viemez" deleted ==== Firefox Extensions ====================== ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default - Visualisateur 3D de 20-20 - %ProfilePath%\extensions\2020Player_IKEA@2020Technologies.com - NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default 4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Chrome Look ====================== Plus-HD-2.5 - Sonne - Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd ==== Chrome Fix ====================== C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd deleted successfully C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0.localstorage deleted successfully C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0.localstorage-journal deleted successfully C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0 deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {ABEC6EA7-E055-4279-AEF4-75C6572FA32E} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FTSG_deDE451" ==== Reset Google Chrome ====================== C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Sonne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Sonne\AppData\Local\Mozilla\Firefox\Profiles\dxajxy9v.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Sonne\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 28.11.2013 at 19:51:12,15 ====================== Wie geht es denn nun weiter? |
29.11.2013, 14:34 | #6 |
/// TB-Ausbilder | Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 Servus, Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Schritt 1 Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit? Bitte poste mit deiner nächsten Antwort
|
30.11.2013, 10:08 | #7 |
| Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-11-2013 Ran by Sonne (administrator) on HARLEY-DAVIDSON on 30-11-2013 10:06:37 Running from C:\Users\Sonne\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHndHkb.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe () C:\Program Files (x86)\PhotoScape\PhotoScape.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-09] (Synaptics Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [PfNet] - C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6310912 2010-06-24] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [188264 2009-07-30] (FUJITSU LIMITED) HKLM\...\Run: [FDM7] - C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164712 2009-11-26] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [157544 2009-10-15] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [35176 2009-10-15] (FUJITSU LIMITED) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor) HKLM\...\Run: [ConMgr] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe [535440 2009-12-24] (CSR, plc) HKLM\...\Run: [CSRSkype] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe [431504 2009-12-24] (CSR, plc) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKLM-x32\...\Run: [LoadFUJ02E3] - C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe [36712 2009-10-08] (FUJITSU LIMITED) HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [47976 2009-10-09] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] () HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] () Startup: C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Visualisateur 3D de 20-20 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\2020Player_IKEA@2020Technologies.com FF Extension: noscript - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Chrome In-App Payments service) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [330240 2010-06-24] (FUJITSU LIMITED) R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2009-07-30] (FUJITSU LIMITED) R2 VFPRadioSupportService; C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [145840 2009-12-24] (CSR, plc) ==================== Drivers (Whitelisted) ==================== R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2009-12-24] (CSR, plc) R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-30 10:06 - 2013-11-30 10:07 - 00011511 _____ C:\Users\Sonne\Downloads\FRST.txt 2013-11-30 10:06 - 2013-11-30 10:06 - 01959024 _____ (Farbar) C:\Users\Sonne\Downloads\FRST64.exe 2013-11-30 10:04 - 2013-11-30 10:04 - 00165376 _____ C:\Users\Sonne\Downloads\SystemLook_x64.exe 2013-11-28 19:45 - 2013-11-28 19:35 - 00024064 _____ C:\Windows\zoek-delete.exe 2013-11-28 19:36 - 2013-11-28 19:51 - 00006657 _____ C:\zoek-results.log 2013-11-28 19:35 - 2013-11-28 19:44 - 00000000 ____D C:\zoek_backup 2013-11-28 19:35 - 2013-11-28 19:35 - 00000000 ____D C:\Users\Sonne\Desktop\zoekzip 2013-11-28 19:33 - 2013-11-28 19:34 - 04050563 _____ C:\Users\Sonne\Desktop\zoekzip.zip 2013-11-28 19:33 - 2013-11-28 19:33 - 04186953 _____ C:\Users\Sonne\Desktop\zoek.rar 2013-11-28 19:20 - 2013-11-28 19:20 - 00001079 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-28 19:19 - 2013-11-28 19:19 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sonne\Desktop\mbam-setup-1.75.0.1300.exe 2013-11-28 19:07 - 2013-11-28 19:50 - 00004180 _____ C:\Windows\PFRO.log 2013-11-28 19:05 - 2013-11-28 19:05 - 00000000 ____D C:\AdwCleaner 2013-11-28 19:04 - 2013-11-28 19:04 - 01091882 _____ C:\Users\Sonne\Desktop\adwcleaner.exe 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext 2013-11-22 21:56 - 2013-11-29 18:14 - 00001624 _____ C:\Windows\setupact.log 2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log 2013-11-20 10:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 11:45 - 2013-11-16 11:51 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka 2013-11-13 09:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 09:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 09:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 09:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 09:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 09:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 09:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 09:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 09:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 09:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 09:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 09:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 09:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 09:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 09:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 09:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 09:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 09:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 09:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 09:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 09:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 09:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 09:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 09:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 09:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 09:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 09:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 09:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-11-30 10:07 - 2013-11-30 10:06 - 00011511 _____ C:\Users\Sonne\Downloads\FRST.txt 2013-11-30 10:06 - 2013-11-30 10:06 - 01959024 _____ (Farbar) C:\Users\Sonne\Downloads\FRST64.exe 2013-11-30 10:05 - 2013-06-07 20:17 - 02001015 _____ C:\Windows\WindowsUpdate.log 2013-11-30 10:04 - 2013-11-30 10:04 - 00165376 _____ C:\Users\Sonne\Downloads\SystemLook_x64.exe 2013-11-30 10:04 - 2011-09-30 22:16 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-30 10:03 - 2013-03-28 19:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-30 10:03 - 2011-09-30 22:24 - 00000000 ____D C:\Users\Sonne\AppData\Local\Windows Live 2013-11-29 18:14 - 2013-11-22 21:56 - 00001624 _____ C:\Windows\setupact.log 2013-11-29 14:22 - 2011-09-30 22:16 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-28 19:58 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-28 19:58 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-28 19:51 - 2013-11-28 19:36 - 00006657 _____ C:\zoek-results.log 2013-11-28 19:50 - 2013-11-28 19:07 - 00004180 _____ C:\Windows\PFRO.log 2013-11-28 19:50 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-28 19:44 - 2013-11-28 19:35 - 00000000 ____D C:\zoek_backup 2013-11-28 19:43 - 2011-09-30 22:23 - 00000000 ____D C:\Users\Sonne 2013-11-28 19:36 - 2011-02-14 13:57 - 00697322 _____ C:\Windows\system32\perfh007.dat 2013-11-28 19:36 - 2011-02-14 13:57 - 00148328 _____ C:\Windows\system32\perfc007.dat 2013-11-28 19:36 - 2009-07-14 06:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-28 19:35 - 2013-11-28 19:45 - 00024064 _____ C:\Windows\zoek-delete.exe 2013-11-28 19:35 - 2013-11-28 19:35 - 00000000 ____D C:\Users\Sonne\Desktop\zoekzip 2013-11-28 19:34 - 2013-11-28 19:33 - 04050563 _____ C:\Users\Sonne\Desktop\zoekzip.zip 2013-11-28 19:33 - 2013-11-28 19:33 - 04186953 _____ C:\Users\Sonne\Desktop\zoek.rar 2013-11-28 19:20 - 2013-11-28 19:20 - 00001079 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-28 19:20 - 2011-10-01 14:53 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-28 19:19 - 2013-11-28 19:19 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Sonne\Desktop\mbam-setup-1.75.0.1300.exe 2013-11-28 19:10 - 2013-07-17 20:09 - 01034531 _____ (Thisisu) C:\Users\Sonne\Desktop\JRT.exe 2013-11-28 19:05 - 2013-11-28 19:05 - 00000000 ____D C:\AdwCleaner 2013-11-28 19:04 - 2013-11-28 19:04 - 01091882 _____ C:\Users\Sonne\Desktop\adwcleaner.exe 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie 2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext 2013-11-28 16:35 - 2013-10-02 19:36 - 00000000 ____D C:\Users\Sonne\AppData\Local\cache 2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log 2013-11-22 20:54 - 2011-02-14 13:43 - 00000000 ____D C:\Windows\Panther 2013-11-21 08:25 - 2012-04-26 20:52 - 00006144 ____H C:\Users\Sonne\Desktop\photothumb.db 2013-11-20 13:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 10:09 - 2011-09-30 22:34 - 00001431 _____ C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-20 10:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 11:51 - 2013-11-16 11:45 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka 2013-11-15 15:25 - 2013-09-09 14:44 - 00002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-13 10:40 - 2013-07-09 10:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-11 05:50 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2013-11-04 01:13 - 2011-04-16 11:56 - 01591930 _____ C:\Windows\SysWOW64\PerfStringBackup.INI ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-30 10:03 ==================== End Of Log ============================ |
30.11.2013, 10:17 | #8 |
| Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 fertig SystemLook 30.07.11 by jpshortstuff Log created at 10:08 on 30/11/2013 by Sonne Administrator - Elevation successful ========== dir ========== C:\Users\Sonne\AppData\Roaming - Parameters: "(none)" ---Files--- WBPU-TTL.DAT --a---- 5 bytes [09:07 27/06/2013] [09:07 27/06/2013] ---Folders--- Adobe d------ [21:41 30/09/2011] Apple Computer d------ [08:59 01/04/2012] CyberLink d------ [18:09 04/10/2011] Fujitsu d------ [21:34 30/09/2011] Google d------ [21:38 30/09/2011] Identities d------ [21:34 30/09/2011] Macromedia d------ [21:41 30/09/2011] Malwarebytes d------ [13:54 01/10/2011] Media Center Programs d------ [21:23 30/09/2011] Microsoft d---s-- [21:23 30/09/2011] Mozilla d------ [21:46 30/09/2011] Nero d------ [09:25 01/10/2011] OpenOffice.org d------ [10:02 02/04/2012] PhotoScape d------ [09:51 02/04/2012] Skype d------ [15:49 25/02/2013] SoftGrid Client d------ [08:12 28/03/2012] Sony Corporation d------ [13:50 02/10/2011] TeamViewer d------ [15:47 17/11/2012] TP d------ [08:11 28/03/2012] Windows Live Writer d------ [09:19 05/04/2012] ========== filefind ========== Searching for "*Searchprotect*" No files found. Searching for "*Dealply*" C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\102_dealply_m.js.vir --a---- 1768 bytes [13:44 09/09/2013] [13:44 09/09/2013] AC4A6605DB6DAB94639294F200DBDFDD C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Dealply.vir --a---- 3520 bytes [08:07 27/06/2013] [08:07 27/06/2013] 2DC2147D8C911D37863228171025B1E2 C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\DealPlyUpdate.vir --a---- 3366 bytes [08:07 27/06/2013] [08:07 27/06/2013] 0C76158AD070A057CF11EB0C937B3FC2 C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\102_dealply_m.js --a---- 1768 bytes [18:44 28/11/2013] [13:44 09/09/2013] AC4A6605DB6DAB94639294F200DBDFDD Searching for "*Qtrax*" C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk.vir --a---- 2393 bytes [08:07 27/06/2013] [08:07 27/06/2013] FC96415FD98CF4C86D5553EB065B0072 C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\QtraxPlayer.vir --a---- 3818 bytes [08:07 27/06/2013] [08:07 27/06/2013] 9E6E6756546E52499D9D8FB0678983B6 C:\Users\Sonne\AppData\Local\Microsoft\Silverlight\OutOfBrowser\3905286838.portal.qtrax.com\3905286838.portal.qtrax.com.ico --a---- 26777 bytes [08:07 27/06/2013] [08:07 27/06/2013] 965D9ED9252B16ABD3492C7E54379540 Searching for "*conduit*" C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\searchplugins\conduit-search.xml.vir --a---- 975 bytes [15:35 28/11/2013] [15:35 28/11/2013] 42BB9AF7E83B49FB186307A58A4414A7 Searching for "*Zip Opener Packages*" No files found. Searching for "*Plus-HD*" No files found. Searching for "*Crossrider*" C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\crossriderManifest.json.vir --a---- 400 bytes [13:44 09/09/2013] [13:44 09/09/2013] 47603EA8C51CCE36090B315E23DBDF13 C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 5955 bytes [13:44 09/09/2013] [13:44 09/09/2013] A15314F10FA928B5C242EDDC4B91F503 C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [13:44 09/09/2013] [13:44 09/09/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2220 bytes [13:44 09/09/2013] [13:44 09/09/2013] EC3226E86137F361EEEF8F1244A0225A C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\js\lib\crossriderAPI.js.vir --a---- 11366 bytes [13:44 09/09/2013] [13:44 09/09/2013] 7B3ADEF52BEDD686D98A3C0F45278020 C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\crossriderManifest.json --a---- 400 bytes [18:44 28/11/2013] [13:44 09/09/2013] 5060361FBB3EBFE66B81A76F847A819A C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\13_CrossriderAppUtils.js --a---- 5955 bytes [18:44 28/11/2013] [13:44 09/09/2013] A15314F10FA928B5C242EDDC4B91F503 C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\14_CrossriderUtils.js --a---- 12369 bytes [18:44 28/11/2013] [13:44 09/09/2013] 56E07DB48844B5EB4DD57F053D87A38D C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\78_CrossriderInfo.js --a---- 2220 bytes [18:44 28/11/2013] [13:44 09/09/2013] EC3226E86137F361EEEF8F1244A0225A C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\js\lib\crossriderAPI.js --a---- 11366 bytes [18:44 28/11/2013] [13:44 09/09/2013] 7B3ADEF52BEDD686D98A3C0F45278020 Searching for "*newnext.me*" No files found. Searching for "*NextLive*" No files found. ========== folderfind ========== Searching for "*Searchprotect*" C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect d------ [18:05 28/11/2013] C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect d------ [18:05 28/11/2013] C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Searchprotect d------ [18:05 28/11/2013] C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Searchprotect\SearchProtect d------ [18:05 28/11/2013] Searching for "*Dealply*" No folders found. Searching for "*Qtrax*" C:\Users\Sonne\AppData\Local\Microsoft\Silverlight\OutOfBrowser\3905286838.portal.qtrax.com d------ [08:07 27/06/2013] Searching for "*conduit*" No folders found. Searching for "*Zip Opener Packages*" No folders found. Searching for "*Plus-HD*" No folders found. Searching for "*Crossrider*" No folders found. Searching for "*newnext.me*" C:\zoek_backup\C_Users_Sonne_AppData_Roaming_newnext.me d-a---- [18:43 28/11/2013] Searching for "*NextLive*" No folders found. ========== regfind ========== Searching for "Searchprotect" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_Dlls"="C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll" Searching for "Dealply" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "Name"="dealply_m" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[102] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } /** * Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing * information, see hxxp://www.dealply.com/ * * THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE * LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR * OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND, * EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C81A6CC7-9F65-4B36-9A95-33D5EBF5372E}] "Path"="\DealPly" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F18FBE52-13C8-49FF-B7FC-18FCA0169CDD}] "Path"="\DealPlyUpdate" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate] [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "Name"="dealply_m" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[102] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } /** * Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing * information, see hxxp://www.dealply.com/ * * THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE * LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR * OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND, * EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED * WARRANTIES OF MERCHANTABILIT [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js" Searching for "Qtrax" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65A6A838-CF81-4A49-AED4-D6FD263E0342}] "Path"="\QtraxPlayer" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QtraxPlayer] Searching for "conduit" No data found. Searching for "Zip Opener Packages" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "DisplayIcon"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "UninstallString"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe /Uninstall /NM="Zip Opener Packages" /AN="" /MBN="Zip Opener Packages 83"" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "DisplayName"="Zip Opener Packages 83" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "UninstallerPath"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "UninstallerPathParent"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "DisplayIcon"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "UninstallString"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe /Uninstall /NM="Zip Opener Packages" /AN="" /MBN="Zip Opener Packages 83"" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "DisplayName"="Zip Opener Packages 83" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "UninstallerPath"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83] "UninstallerPathParent"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages" Searching for "Plus-HD" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5] [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Manifest] "Name"="Plus-HD-2.5" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{12648780-d578-4ecf-bf84-0e18639d0860}] "AppName"="Plus-HD-1.6-helper.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{12648780-d578-4ecf-bf84-0e18639d0860}] "AppPath"="C:\Program Files (x86)\Plus-HD-1.6" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{134a4566-20ef-4e7b-b221-e1afb3c7cc07}] "AppName"="Plus-HD-2.5-buttonutil64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{134a4566-20ef-4e7b-b221-e1afb3c7cc07}] "AppPath"="C:\Program Files (x86)\Plus-HD-2.5" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{580a372d-7927-49e8-9829-35a62f0ae487}] "AppName"="Plus-HD-2.5-codedownloader.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{580a372d-7927-49e8-9829-35a62f0ae487}] "AppPath"="C:\Program Files (x86)\Plus-HD-2.5" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{990fbfea-1b6f-47e2-ab7a-a2946326c732}] "AppName"="Plus-HD-2.5-helper.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{990fbfea-1b6f-47e2-ab7a-a2946326c732}] "AppPath"="C:\Program Files (x86)\Plus-HD-2.5" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ae2a420b-066c-4a22-a55d-d458972576eb}] "AppName"="Plus-HD-2.5-bg.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ae2a420b-066c-4a22-a55d-d458972576eb}] "AppPath"="C:\Program Files (x86)\Plus-HD-2.5" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b3ad746b-cb54-49dd-a194-6eb097fe6c5e}] "AppName"="Plus-HD-1.6-buttonutil64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b3ad746b-cb54-49dd-a194-6eb097fe6c5e}] "AppPath"="C:\Program Files (x86)\Plus-HD-1.6" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d0f19be0-b4d5-4e81-adea-c00f24c90fa8}] "AppName"="Plus-HD-1.6-buttonutil.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d0f19be0-b4d5-4e81-adea-c00f24c90fa8}] "AppPath"="C:\Program Files (x86)\Plus-HD-1.6" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d42fb26d-4c7d-494d-afa4-bb9b90ead653}] "AppName"="Plus-HD-2.5-buttonutil.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d42fb26d-4c7d-494d-afa4-bb9b90ead653}] "AppPath"="C:\Program Files (x86)\Plus-HD-2.5" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{df8d8370-e00b-4243-839a-728e803720f6}] "AppName"="Plus-HD-1.6-bg.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{df8d8370-e00b-4243-839a-728e803720f6}] "AppPath"="C:\Program Files (x86)\Plus-HD-1.6" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2665d07-8d6d-412d-a4aa-e7c20ab481e4}] "AppName"="Plus-HD-1.6-codedownloader.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2665d07-8d6d-412d-a4aa-e7c20ab481e4}] "AppPath"="C:\Program Files (x86)\Plus-HD-1.6" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5] [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Manifest] "Name"="Plus-HD-2.5" Searching for "Crossrider" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Code] "AppJavaScript"=" /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: hxxp://docs.crossrider.com *************************************************************************************/ appAPI.ready(function($) { //alert(appAPI.isMatchPages("*youtube*")); //alert(appAPI.isMatchPages("*watch*")); //alert(appAPI.isMatchPages("*hd=1*")) if (appAPI.isMatchPages("*youtube*") && appAPI.isMatchPages("*watch*") && !appAPI.isMatchPages("*hd=1*")) { //alert(window.location); window.location = window.location + "&hd=1" //alert(window.location); } }); " [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Code] "BgJavaScript"=" /************************************************************************************ This is your background code. For more information please visit our wiki site: hxxp://docs.crossrider.com/#!/guide/background_scope *************************************************************************************/ appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.) }); " [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Installer] "CodeDownloadDomain"="hxxp://app-static.crossrider.com" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Installer] "Domain"="hxxp://app-static.crossrider.com" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1] "JavaScript"="appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},css:"/plugins/stylesheets/sidebar.css",themes:"/plugins/images/sidebar"}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},statsBase:{production:"hxxp://nstats.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},geolocation:"hxxp://www.geoplugin.net/json.gp?jsoncallback=fn",meta:"/notifier/"+appAPI._cr_config.appID()+"/meta.json",messages:"/notifier/"+appAPI._cr_config.appID()+"/{id}.json",logger:"/notifications.gif",loggerAPI:"/api_notifications.gif"},notifications:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},cs [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1] "Url"="hxxp://app-static.crossrider.com/plugins/mins/base.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\101] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/cortica_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[102] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } /** * Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing * information, see hxxp://www.dealply.com/ * * THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE * LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR * OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND, * EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\103] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_5_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[104] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } var permanentData = {gui:[],actions:[]}; var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1 e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9 f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4cf351d0b2","1f89d526fc52417e16d99b9f069f1 8f [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/jollywallet_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\105] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/corticas_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\107] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupish_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\108] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/icm_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\116] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/ads_only_5_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\117] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupons_intext_ads_5_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[119] = function() { (function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m=r,q);$(e).trigger(c)}else{if(q!==m){location.href=location.href.replace(/#.*/,"")+q}}p=setTimeout(n [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/similar_web_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[120] = function() { function injectScript(geo) { appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=luck&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID()); } var geo = appAPI.db.get("geo"); if (!geo) { appAPI.request.get("hxxp://ipgeoapi.com/", function(res) { if (res) { var res = appAPI.JSON.parse(res); if (res && res.country_name) { geo = res.country_name; appAPI.db.set("geo", geo, appAPI.time.daysFromNow(7)); injectScript(geo); } } }); } else { injectScript(geo); } };" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/luck_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[123] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.intext){ return; } } // boris don't want it on youtube for shop helper if (appAPI.appID == 33256 && location.href.indexOf("youtube.com") !== -1) { return; } if (!(/^https\:\/\//.test(document.location.href))) { appAPI.dom.addRemoteJS("hxxp://intext.nav-links.com/js/intext.js?afid=crossrider&subid=" + appAPI.internal.monetization.getSubId() + "&maxlinks=3&linkcolor=009900"); } };" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_adv_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\124] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_no_search_no_coupons_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\125] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi2_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\126] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_ws_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\127] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_p_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\128] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_pricora_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\129] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/widdit_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13] "Name"="CrossriderAppUtils" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13] "Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderAppUtils.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\132] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_coupons_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\133] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_intext_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\134] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_serp_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\135] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi3_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[138] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } function injectScript(geo) { appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=getdeal&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID()); } var geo = appAPI.db.get("geo"); if (!geo) { appAPI.request.get("hxxp://ipgeoapi.com/", function(res) { if (res) { var res = appAPI.JSON.parse(res); if (res && res.country_name) { geo = res.country_nam [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/getdeal_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14] "Name"="CrossriderUtils" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14] "Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderUtils.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\17] "Url"="hxxp://app-static.crossrider.com/plugins/mins/jQuery.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\2] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_1.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21] "JavaScript"="var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h("body").bindExtensionEvent("debug_request_data",function(j,i){i f(i.appId==f.appId){e();}});h("body").bindExtensionEvent("debug_request_reload_background",function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBa ckground){appAPI.internal.reloadBackground();}});h("body").bindExtensionEvent("debug_request_reload_plugins",function(j,i){if(i.appId==f.appId){appAPI .resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h("body").bindExtensionEvent("debug_mode_activate",function(j,i){if(i.appId ==f.appId){b(i);}});h("body").bindExtensionEvent("debug_mode_deactivate",function(j,i){if(i.appId==f.appId){d();}});h("body").bindExtensionEvent("debu g_request_database",function(j,i){if(i.appId==f.appId){c(i);}});h("b [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21] "Url"="hxxp://app-static.crossrider.com/plugins/mins/debug.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22] "JavaScript"="(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.init ializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === "undefined") { jQuery = $jquery_171; }('+appAPI.resources.parseIncludeJS(c.toString())+")($jquery_171)")();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appA PI.time.daysFromNow(90),nextCheck:360,DBNamespace:"Resources_",isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.b rowser.msie&&z.browser.version*1==7},w=new z.Deferred(),h=J("meta")||{},D=J("remote_resources")||{remoteId:0},e=J("queue")||{},g=initialVersion=J("lastVersion")||0;return z.Class.extend({i [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22] "Url"="hxxp://app-static.crossrider.com/plugins/mins/resources.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28] "JavaScript"="var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}});e("body").bindExtensionEvent("__CR_REQUEST_READY",a);},isReady:func tion(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e("body").fireExtensionEvent("__CR_RESPONSE_READY",{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28] "Url"="hxxp://app-static.crossrider.com/plugins/mins/initializer.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\3] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_2.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\35] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEAjax.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId="BG";appAPI.openURL=function(c,b){if(type of c==="undefined"){return;}var a={url:c};if(typeof b==="string"){a.where=b;}appAPI.internal.message.send({eventName:"openURL",eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!=="string"){console.error("appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: "+(typeof a));return;}appAPI.internal.message.send({eventName:"runHelper",eventContent:a});};window.alert=function(a){appAPIinternal.alert(a);};window.open=func tion(b,a,d,c){appAPI.internal.message.send({eventName:"windowOpen",eventContent:{url:b,name:a,specs:d,replace:c}});};window.console.log=appAPI.interna l.console.log;console.log=window.console.log;window.console.info= [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBackground.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.consol e.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.inte rnal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.intern al.callbacks.setEventHandler("openURL",function(c){if(appAPI.isActiveTab()){var b=c.url;var a=c.where;appAPI.openURL(b,a);}});appAPI.internal.callbacks.setEventHandler("runHelper",function(b){if(appAPI.isActiveTab()){var a=b;appAPIinternal.run(a);}});(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onBeforeNavigate");if(typeof c!=="string"){re [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBrowserEvents.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d==="undefined"){return;}var a=e.eventName;if(typeof a==="undefined"){return;}if(typeof appAPI.internal.callbacks[a]==="undefined"){return;}if(typeof appAPI.internal.callbacks[a].handler!=="undefined"){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners==="undefined"){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]==="undefined"){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalDa [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IECallbacks.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\39] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEDatabase.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\4] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/jquery-1_7_1_min.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\40] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEExtension.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform="IE";if(typeof appAPI.appInfo==="undefined"){appAPI.appInfo={};}var b=appAPI.internal.prefs.getChar("fullVersionForUrl","Installer");if(typeof b==="string"){appAPI.appInfo.platformVersion=b;}else{appAPI.appInfo.platformVersion=appAPI.internal.prefs.getChar("fullVersion","Installer");}appAPI.a ppInfo.userId=appAPI.internal.prefs.getChar("bic","Crossrider");appAPI.appInfo.id=appAPI.internal.prefs.getInt("activeAppId","");appAPI.appInfo.versio n=appAPI.internal.prefs.getInt("version","Manifest");appAPI.appInfo.description=appAPI.internal.prefs.getChar("description","Manifest");appAPI.appInfo .name=appAPI.internal.prefs.getChar("name","Manifest");appAPI.appInfo.publisherName=appAPI.inte [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInfo.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\42] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInternal.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\43] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMessaging.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\44] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMisc.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.tabId="onRequest";window.console.log=appAPI.internal.console.log;console .log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console. warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onRequest");if(typeof c!=="string"){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!=="object"){return 0;}var d=0;for(var b in c){d++;appAPI.internal.callbacks.addListener("onRequest",function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!=="string"){re [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEOnRequest.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\46] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IETimers.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47] "JavaScript"="(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appIdfunction(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:"hxxp://resources.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},update:"/apps/{appId}/resources/meta/{lastVersion}"},env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:" Resources_",isDebugappAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get("debug_resources_path"))},w=o("meta")||{},g=o("remote_resources")||{r emoteId:0},t=o("queue")||{},B=o("lastVersion")||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}}); }},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!=="undefined"){D=jQuery.trim(D);}return b(D,"string" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47] "Url"="hxxp://app-static.crossrider.com/plugins/mins/resources_background.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\64] "Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiMessage.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\72] "Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiValidation.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78] "Name"="CrossriderInfo" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78] "Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderInfo.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87] "JavaScript"="var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform=="FF"){$jquery.fn.__prepend=$jquery.fn.prepend;$jquery.fn.prepend=function(a){if($jquery(a).is("script")){window. document.body.appendChild(a);}else{$jquery(this).__prepend(a);}};}var isChrome=appAPI.platform==="CH";function wit_getXMLHttpRequest(){return function(){this.open=function(b,a,c){this.type=b;this.url=a;this.isAsync=c;};this.send=function(){var a=this,b;if(this.isAsync){b=this.type=="GET"?appAPI.request.get:appAPI.request.post;b(this.url,function(c){a.readyState=4;a.status=200;a.responseText= c;if(a.onreadystatechange){a.onreadystatechange();}});}else{b=this.type=="GET"?appAPI.request.sync.get:appAPI.request.sync.post;a.readyState=4;a.statu s=200;a.responseText=b(this.url);}};this.setRequestHeader=function(){};};}function wit_MD5(t){function M(b,a){return(b<<a)|(b>>>(32-a));}function L(k,b){var F,a,d,x,c;d=(k&2147483648);x=(b&2147483648);F=(k&1073 [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/ginyas_wrapper.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91] "JavaScript"="(function(h){var o=(function(){var Q=0;var Y="";function P(ab){return Z(N(R(ab)));}function O(ab){return B(N(R(ab)));}function I(ab,ac){return E(N(R(ab)),ac);}function W(ab,ac){return Z(G(R(ab),R(ac)));}function L(ab,ac){return B(G(R(ab),R(ac)));}function H(ab,ad,ac){return E(G(R(ab),R(ad)),ac);}function aa(){return P("abc").toLowerCase()=="900150983cd24fb0d6963f7d28e17f72";}function N(ab){return U(F(M(ab),ab.length*8));}function G(ad,ag){var af=M(ad);if(af.length>16){af=F(af,ad.length*8);}var ab=Array(16),ae=Array(16);for(var ac=0;ac<16;ac++){ab[ac]=af[ac]^909522486;ae[ac]=af[ac]^1549556828;}var ah=F(ab.concat(M(ag)),512+ag.length*8);return U(F(ae.concat(ah),512+128));}function Z(ad){if(typeof Q==="undefined"){Q=0;}var af=Q?"0123456789ABCDEF":"0123456789abcdef";var ac="";var ab;for(var ae=0;ae<ad.length;ae++){ab=ad.charCodeAt(ae);ac+=af.charAt((ab>>>4)&15)+af.charAt(ab&15);}return ac;}function B(ad){if(typeof Y==="undefine [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/monetizationLoader.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92] "JavaScript"="if(typeof appAPI.internal.monetization==="undefined"){appAPI.internal.monetization={};}if(typeof appAPI.internal.monetization.plugins==="undefined"){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[92]=function(){if(typeof appAPI.internal.monetization.verticals!=="undefined"){if(!appAPI.internal.monetization.verticals.shopping){return;}}if(!(/^https\:\/\//.test(document.location.href))){appAPI.dom.addRemoteJS("hxxp://www.superfish.com/ws/sf_main.jsp?dlsource=crossrider&userId=abc&CTID="+appAPI.internal.monetization.getSubId());}};" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\93] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94] "JavaScript"="appAPI.isBackground=false;appAPI.tabId="POPUP";appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: "+(typeof a));return;}if(a.length!==4){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA)");return;}appAPI.internal.message.send({eventName:"onSetBadgeColorFromPopup",eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a) {var b={};if(typeof c!=="string"){console.error("appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: "+(typeof c));return;}b.text=c;if(typeof a==="undefined"||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: "+(typeof a));return;}else{if(a.lengt [HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEPopup.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Code] "AppJavaScript"=" /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: hxxp://docs.crossrider.com *************************************************************************************/ appAPI.ready(function($) { //alert(appAPI.isMatchPages("*youtube*")); //alert(appAPI.isMatchPages("*watch*")); //alert(appAPI.isMatchPages("*hd=1*")) if (appAPI.isMatchPages("*youtube*") && appAPI.isMatchPages("*watch*") && !appAPI.isMatchPages("*hd=1*")) { //alert(window.location); window.location = window.location + "&hd=1" //alert(window.location); } }); " [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Code] "BgJavaScript"=" /************************************************************************************ This is your background code. For more information please visit our wiki site: hxxp://docs.crossrider.com/#!/guide/background_scope *************************************************************************************/ appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.) }); " [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Installer] "CodeDownloadDomain"="hxxp://app-static.crossrider.com" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Installer] "Domain"="hxxp://app-static.crossrider.com" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1] "JavaScript"="appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},css:"/plugins/stylesheets/sidebar.css",themes:"/plugins/images/sidebar"}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},statsBase:{production:"hxxp://nstats.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},geolocation:"hxxp://www.geoplugin.net/json.gp?jsoncallback=fn",meta:"/notifier/"+appAPI._cr_config.appID()+"/meta.json",messages:"/notifier/"+appAPI._cr_config.appID()+"/{id}.json",logger:"/notifications.gif",loggerAPI:"/api_notifications.gif"},notifications:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1] "Url"="hxxp://app-static.crossrider.com/plugins/mins/base.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\101] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/cortica_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[102] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } /** * Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing * information, see hxxp://www.dealply.com/ * * THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE * LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR * OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND, * EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED * WARRANTIES OF MERCHANTABILIT [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\103] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_5_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[104] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } var permanentData = {gui:[],actions:[]}; var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1 e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9 f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4cf3 [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/jollywallet_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\105] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/corticas_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\107] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupish_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\108] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/icm_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\116] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/ads_only_5_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\117] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupons_intext_ads_5_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[119] = function() { (function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m=r,q);$(e).trigger(c)}else{if(q!==m){location.href=location. [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/similar_web_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[120] = function() { function injectScript(geo) { appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=luck&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID()); } var geo = appAPI.db.get("geo"); if (!geo) { appAPI.request.get("hxxp://ipgeoapi.com/", function(res) { if (res) { var res = appAPI.JSON.parse(res); if (res && res.country_name) { geo = res.country_name; appAPI.db.set("geo", geo, appAPI.time.daysFromNow(7)); injectScript(geo); } } }); } el [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/luck_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[123] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.intext){ return; } } // boris don't want it on youtube for shop helper if (appAPI.appID == 33256 && location.href.indexOf("youtube.com") !== -1) { return; } if (!(/^https\:\/\//.test(document.location.href))) { appAPI.dom.addRemoteJS("hxxp://intext.nav-links.com/js/intext.js?afid=crossrider&subid=" + appAPI.internal.monetization.getSubId() + "&maxlinks=3&linkcolor=009900"); } };" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_adv_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\124] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_no_search_no_coupons_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\125] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi2_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\126] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_ws_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\127] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_p_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\128] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_pricora_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\129] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/widdit_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13] "Name"="CrossriderAppUtils" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13] "Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderAppUtils.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\132] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_coupons_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\133] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_intext_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\134] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_serp_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\135] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi3_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138] "JavaScript"="if (typeof appAPI.internal.monetization === "undefined") { appAPI.internal.monetization = {}; } if (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI.internal.monetization.plugins = {}; } appAPI.internal.monetization.plugins[138] = function() { if (typeof appAPI.internal.monetization.verticals !== "undefined") { if (!appAPI.internal.monetization.verticals.shopping){ return; } } function injectScript(geo) { appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=getdeal&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID()); } var geo = appAPI.db.get("geo"); if (!geo) { appAPI.request.get("hxxp://ipgeoapi.com/", function(res) { if (res) { var res = appAPI.JSON.parse(res); if (res && res.c [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/getdeal_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14] "Name"="CrossriderUtils" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14] "Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderUtils.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\17] "Url"="hxxp://app-static.crossrider.com/plugins/mins/jQuery.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\2] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_1.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21] "JavaScript"="var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h("body").bindExtensionEvent("debug_request_data",function(j,i){i f(i.appId==f.appId){e();}});h("body").bindExtensionEvent("debug_request_reload_background",function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBa ckground){appAPI.internal.reloadBackground();}});h("body").bindExtensionEvent("debug_request_reload_plugins",function(j,i){if(i.appId==f.appId){appAPI .resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h("body").bindExtensionEvent("debug_mode_activate",function(j,i){if(i.appId ==f.appId){b(i);}});h("body").bindExtensionEvent("debug_mode_deactivate",function(j,i){if(i.appId==f.appId){d();}});h("body").bindExtensionEvent("debu g_request_database",function [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21] "Url"="hxxp://app-static.crossrider.com/plugins/mins/debug.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22] "JavaScript"="(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.init ializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === "undefined") { jQuery = $jquery_171; }('+appAPI.resources.parseIncludeJS(c.toString())+")($jquery_171)")();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appA PI.time.daysFromNow(90),nextCheck:360,DBNamespace:"Resources_",isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.b rowser.msie&&z.browser.version*1==7},w=new z.Deferred(),h=J("meta")||{},D=J("remote_resources")||{remoteId:0},e=J("queue")||{},g=initialVersion=J("l [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22] "Url"="hxxp://app-static.crossrider.com/plugins/mins/resources.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28] "JavaScript"="var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}});e("body").bindExtensionEvent("__CR_REQUEST_READY",a);},isReady:func tion(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e("body").fireExtensionEvent("__CR_RESPONSE_READY",{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28] "Url"="hxxp://app-static.crossrider.com/plugins/mins/initializer.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\3] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_2.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\35] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEAjax.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId="BG";appAPI.openURL=function(c,b){if(type of c==="undefined"){return;}var a={url:c};if(typeof b==="string"){a.where=b;}appAPI.internal.message.send({eventName:"openURL",eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!=="string"){console.error("appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: "+(typeof a));return;}appAPI.internal.message.send({eventName:"runHelper",eventContent:a});};window.alert=function(a){appAPIinternal.alert(a);};window.open=func tion(b,a,d,c){appAPI.internal.message.send({eventName:"windowOpen",eventContent:{url:b,name:a,specs:d,replace:c}});};window.console.log=appAPI.interna l.console.log;console.log [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBackground.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.consol e.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.inte rnal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.intern al.callbacks.setEventHandler("openURL",function(c){if(appAPI.isActiveTab()){var b=c.url;var a=c.where;appAPI.openURL(b,a);}});appAPI.internal.callbacks.setEventHandler("runHelper",function(b){if(appAPI.isActiveTab()){var a=b;appAPIinternal.run(a);}});(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onBef [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBrowserEvents.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d==="undefined"){return;}var a=e.eventName;if(typeof a==="undefined"){return;}if(typeof appAPI.internal.callbacks[a]==="undefined"){return;}if(typeof appAPI.internal.callbacks[a].handler!=="undefined"){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners==="undefined"){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]==="undefined"){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.int [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IECallbacks.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\39] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEDatabase.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\4] "Url"="hxxp://app-static.crossrider.com/plugins/javascripts/jquery-1_7_1_min.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\40] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEExtension.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform="IE";if(typeof appAPI.appInfo==="undefined"){appAPI.appInfo={};}var b=appAPI.internal.prefs.getChar("fullVersionForUrl","Installer");if(typeof b==="string"){appAPI.appInfo.platformVersion=b;}else{appAPI.appInfo.platformVersion=appAPI.internal.prefs.getChar("fullVersion","Installer");}appAPI.a ppInfo.userId=appAPI.internal.prefs.getChar("bic","Crossrider");appAPI.appInfo.id=appAPI.internal.prefs.getInt("activeAppId","");appAPI.appInfo.versio n=appAPI.internal.prefs.getInt("version","Manifest");appAPI.appInfo.description=appAPI.internal.prefs.getChar("description","Manifest");appAPI.appInfo .name=appAPI.internal.prefs.getChar("name","Manifest"); [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInfo.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\42] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInternal.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\43] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMessaging.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\44] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMisc.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45] "JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.tabId="onRequest";window.console.log=appAPI.internal.console.log;console .log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console. warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onRequest");if(typeof c!=="string"){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!=="object"){return 0;}var d=0;for(var b in c){d++;appAPI.internal.callbacks.addListener("onRequest",function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditiona [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEOnRequest.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\46] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IETimers.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47] "JavaScript"="(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appIdfunction(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:"hxxp://resources.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},update:"/apps/{appId}/resources/meta/{lastVersion}"},env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:" Resources_",isDebugappAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get("debug_resources_path"))},w=o("meta")||{},g=o("remote_resources")||{r emoteId:0},t=o("queue")||{},B=o("lastVersion")||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}}); }},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!=="undefined [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47] "Url"="hxxp://app-static.crossrider.com/plugins/mins/resources_background.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\64] "Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiMessage.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\72] "Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiValidation.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78] "Name"="CrossriderInfo" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78] "Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderInfo.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87] "JavaScript"="var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform=="FF"){$jquery.fn.__prepend=$jquery.fn.prepend;$jquery.fn.prepend=function(a){if($jquery(a).is("script")){window. document.body.appendChild(a);}else{$jquery(this).__prepend(a);}};}var isChrome=appAPI.platform==="CH";function wit_getXMLHttpRequest(){return function(){this.open=function(b,a,c){this.type=b;this.url=a;this.isAsync=c;};this.send=function(){var a=this,b;if(this.isAsync){b=this.type=="GET"?appAPI.request.get:appAPI.request.post;b(this.url,function(c){a.readyState=4;a.status=200;a.responseText= c;if(a.onreadystatechange){a.onreadystatechange();}});}else{b=this.type=="GET"?appAPI.request.sync.get:appAPI.request.sync.post;a.readyState=4;a.statu s=200;a.responseText=b(this.url);}};this.setRequestHeader=function(){};};}function wit_MD5(t){function M(b,a){return(b<<a)|(b>>>(32-a));}function L(k,b){var F,a,d,x,c;d=( [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/ginyas_wrapper.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91] "JavaScript"="(function(h){var o=(function(){var Q=0;var Y="";function P(ab){return Z(N(R(ab)));}function O(ab){return B(N(R(ab)));}function I(ab,ac){return E(N(R(ab)),ac);}function W(ab,ac){return Z(G(R(ab),R(ac)));}function L(ab,ac){return B(G(R(ab),R(ac)));}function H(ab,ad,ac){return E(G(R(ab),R(ad)),ac);}function aa(){return P("abc").toLowerCase()=="900150983cd24fb0d6963f7d28e17f72";}function N(ab){return U(F(M(ab),ab.length*8));}function G(ad,ag){var af=M(ad);if(af.length>16){af=F(af,ad.length*8);}var ab=Array(16),ae=Array(16);for(var ac=0;ac<16;ac++){ab[ac]=af[ac]^909522486;ae[ac]=af[ac]^1549556828;}var ah=F(ab.concat(M(ag)),512+ag.length*8);return U(F(ae.concat(ah),512+128));}function Z(ad){if(typeof Q==="undefined"){Q=0;}var af=Q?"0123456789ABCDEF":"0123456789abcdef";var ac="";var ab;for(var ae=0;ae<ad.length;ae++){ab=ad.charCodeAt(ae);ac+=af.charAt((ab>>>4)&15)+af.charAt(ab&15);}return ac [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/monetizationLoader.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92] "JavaScript"="if(typeof appAPI.internal.monetization==="undefined"){appAPI.internal.monetization={};}if(typeof appAPI.internal.monetization.plugins==="undefined"){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[92]=function(){if(typeof appAPI.internal.monetization.verticals!=="undefined"){if(!appAPI.internal.monetization.verticals.shopping){return;}}if(!(/^https\:\/\//.test(document.location.href))){appAPI.dom.addRemoteJS("hxxp://www.superfish.com/ws/sf_main.jsp?dlsource=crossrider&userId=abc&CTID="+appAPI.internal.monetization.getSubId());}};" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\93] "Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94] "JavaScript"="appAPI.isBackground=false;appAPI.tabId="POPUP";appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: "+(typeof a));return;}if(a.length!==4){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA)");return;}appAPI.internal.message.send({eventName:"onSetBadgeColorFromPopup",eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a) {var b={};if(typeof c!=="string"){console.error("appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: "+(typeof c));return;}b.text=c;if(typeof a==="undefined"||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but go [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94] "Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEPopup.js" Searching for "newnext.me" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Run] "NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l" Searching for "NextLive" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l" [HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Run] "NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l" -= EOF =- |
30.11.2013, 13:05 | #9 |
/// TB-Ausbilder | Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 Servus, wenn du FRST richtig ausgeführt hast, dann erstellt es 2 Logdateien, FRST.txt und Addition.txt. Poste mir bitte noch die Addition.txt, dann kann es weitergehen. |
04.12.2013, 20:09 | #10 |
/// TB-Ausbilder | Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 Fehlende Rückmeldung Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen! |
Themen zu Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 |
adware, adware?, akamaihd.net, aktiviert, angezeigt, anzeigen, applaus, korrekt, loswerden, nerviger, plushd, probleme, pup.optional.conduit.a, pup.optional.opencandy, pup.optional.searchprotect.a, trojan:js/medfos.b, verschwunden, überall, öffnen |