Code:
Alles auswählen Aufklappen ATTFilter
SystemLook 30.07.11 by jpshortstuff
Log created at 19:11 on 08/12/2013 by Jasskas
Administrator - Elevation successful
========== filefind ==========
Searching for "*MyEmoticons*"
C:\Nero Autobackup\20131025_232350_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe ------- 592304 bytes [22:10 25/10/2013] [22:10 25/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131025_232350_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe ------- 592304 bytes [22:10 25/10/2013] [22:10 25/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131101_212147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131101_212147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131108_232147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131108_232147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131115_212149_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131115_212149_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131122_232147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131122_232147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131129_212150_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131129_212150_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131206_232147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131206_232147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131207_232149_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131207_232149_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_104821_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_104821_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_112147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_112147_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_132148_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_132148_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_174326_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Nero Autobackup\20131208_174326_Local Autobackup\C\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [08:32 27/10/2013] [08:32 27/10/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Users\Jasskas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyEmoticons\MyEmoticons.lnk --a---- 1881 bytes [20:29 16/04/2013] [20:29 16/04/2013] D904D4A5C5B266D813FFF70D199F21E0
C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons-1.6.1.dll --a---- 214896 bytes [06:58 28/02/2013] [06:58 28/02/2013] E6A33D8B7E4286416AB0D6588F8A7FF9
C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons.ico --a---- 97869 bytes [10:47 05/02/2013] [10:47 05/02/2013] A030834B42C7B05D67BC1F82B646052E
C:\Users\Jasskas\AppData\Roaming\MyEmoticons\MyEmoticons.url --a---- 136 bytes [20:28 16/04/2013] [20:29 16/04/2013] 9F4EC05B4F9EFCC5FD8AE20B8D6B1826
C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons@myemoticons.com.xpi --a---- 28704 bytes [06:58 28/02/2013] [06:58 28/02/2013] DFBBFC06188A48CA48D1BA9C6DE3F0BF
C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons@myemoticons.com-1.6.1\content\myemoticons.jar --a---- 12077 bytes [20:29 16/04/2013] [20:29 16/04/2013] 6BC9880C19A046C26C806930705248FF
C:\Users\Jasskas\Downloads\myemoticons(1).exe --a---- 592304 bytes [20:28 16/04/2013] [20:28 16/04/2013] 1603B443E65F235D100D661CFE6C3E90
C:\Users\Jasskas\Downloads\myemoticons.exe --a---- 592304 bytes [20:27 16/04/2013] [20:27 16/04/2013] 1603B443E65F235D100D661CFE6C3E90
========== folderfind ==========
Searching for "*MyEmoticons*"
C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\MyEmoticons d------ [17:09 11/03/2013]
C:\Users\All Users\IncrediMail\Data\Default Identity\EmoticonCenter\MyEmoticons d------ [17:09 11/03/2013]
C:\Users\Jasskas\AppData\Local\IM\Identities\{18178290-1BD3-41C2-86FB-EF595E480DE1}\EmoticonCenter\MyEmoticons d------ [21:34 04/12/2011]
C:\Users\Jasskas\AppData\Roaming\MyEmoticons d------ [20:28 16/04/2013]
C:\Users\Jasskas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyEmoticons d------ [20:29 16/04/2013]
C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons@myemoticons.com-1.6.1 d------ [20:29 16/04/2013]
========== regfind ==========
Searching for "MyEmoticons"
[HKEY_CURRENT_USER\Software\IncrediMail\Identities\{18178290-1BD3-41C2-86FB-EF595E480DE1}\EmoticonCenter\MyEmoticons]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"DisplayName"="MyEmoticons"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"UninstallString"="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\uninst.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"URLInfoAbout"="hxxp://www.myemoticons.com"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"DisplayIcon"="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons.ico"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7970495D-2F98-45F4-B093-87E76C7B8B60}]
@="IMyEmoticons"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0]
@="MyEmoticons 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0\0\win32]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons-1.6.1.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0\HELPDIR]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DCC39ACE-709B-44EA-B062-5F6BE2774644}]
@="MyEmoticons Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DCC39ACE-709B-44EA-B062-5F6BE2774644}\InprocServer32]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons-1.6.1.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{7970495D-2F98-45F4-B093-87E76C7B8B60}]
@="IMyEmoticons"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0]
@="MyEmoticons 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0\0\win32]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons-1.6.1.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0\HELPDIR]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\MyEmoticons\QuickBar\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\MyEmoticons\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AEE38AFC8FA67634F86968B5A6CA2F8F]
"4F8EDFE0D1960BC44B1CB06DB39070FF"="C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\MyEmoticons\QuickBar\Order.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oopofgccipckckifenoicncegojimpmf]
"path"="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\oopofgccipckckifenoicncegojimpmf.crx"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\IncrediMail\Default Identity\EmoticonCenter\MyEmoticons]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{DCC39ACE-709B-44EA-B062-5F6BE2774644}]
@="MyEmoticons"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"myemoticons@myemoticons.com"="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons@myemoticons.com-1.6.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{DCC39ACE-709B-44EA-B062-5F6BE2774644}]
@="MyEmoticons Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{DCC39ACE-709B-44EA-B062-5F6BE2774644}\InprocServer32]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons-1.6.1.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{7970495D-2F98-45F4-B093-87E76C7B8B60}]
@="IMyEmoticons"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0]
@="MyEmoticons 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0\0\win32]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons-1.6.1.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{E6CAE78A-607F-4A09-BD7E-0826A32B975B}\1.0\HELPDIR]
@="C:\Users\Jasskas\AppData\Roaming\MyEmoticons"
[HKEY_USERS\S-1-5-21-990396829-1976191800-715236640-1000\Software\IncrediMail\Identities\{18178290-1BD3-41C2-86FB-EF595E480DE1}\EmoticonCenter\MyEmoticons]
[HKEY_USERS\S-1-5-21-990396829-1976191800-715236640-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
[HKEY_USERS\S-1-5-21-990396829-1976191800-715236640-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"DisplayName"="MyEmoticons"
[HKEY_USERS\S-1-5-21-990396829-1976191800-715236640-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"UninstallString"="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\uninst.exe"
[HKEY_USERS\S-1-5-21-990396829-1976191800-715236640-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"URLInfoAbout"="hxxp://www.myemoticons.com"
[HKEY_USERS\S-1-5-21-990396829-1976191800-715236640-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyEmoticons]
"DisplayIcon"="C:\Users\Jasskas\AppData\Roaming\MyEmoticons\myemoticons.ico"
-= EOF =-