|
Plagegeister aller Art und deren Bekämpfung: Firefox stürzt ständig abWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.05.2014, 18:27 | #1 |
| Firefox stürzt ständig ab Hallo, da ihr mir schon ein paar Mal super geholfen habt, wende ich mich nun erneut mit einem Problem an euch und würde mich freuen, falls ihr mir weiterhelfen könnt. Ich benutze als Internetnavigator Mozilla Firefox, leider stürzt dieser nun seit längerem immer öfter ab - meine Überlegung ist, ob ein Virus oder ein Trojaner daran schuld sein könnte, deswegen stelle ich meine Frage hier im Forum. Es kommt nun schon seit einiger Zeit vor, dass sich Firefox nach einiger Zeit blockiert (mind. 1 - 2 am Tag, Tendenz steigend) und meist nicht mehr reagiert - oder er stürzt einfach sofort ab und es kommt diese Entschuldigungsmeldung von Firefox (Entschuldigung, das hätte nicht passieren dürfen). Falls sich die geöffneten Seiten nicht mehr herstellen lassen, ist der Datenverlust für mich jedes Mal relativ groß, da ich viel im Internet recherchieren muss und daher meist viele Seiten geöffnet habe (aber nicht mehr als früher, Überlastung sollte eigentlich als Grund ausscheiden). Seit einigen Tagen gibt es nun auch eine neue Variante: Firefox wird einfach schwarz (der komplette Bildschirm ist schwarz - andere Anwendungen funktionieren), dann stellen sich nach und nach Elemente der jeweiligen Internetseiten wieder her. Auch in diesem Fall muss ich Firefox komplett schließen und den PC neustarten, da Firefox nicht mehr richtig funktioniert. Außerdem stürzt auch des öfteren der Adobe Flashplayer ab, wenn ich online Videos schaue (dann stürzt Firefox oft auch mit ab) - ob dies nun jedoch mit dem zuvor geschilderten Problem zusammenhängt, weiß ich nicht. Mein System: Windows 7, 64bit Internet: Firefox (habe ich regelmäßig abgedatet, ebenso Adobe Flashplayer) Virenprogramm: Avast Im folgenden würde ich nun die Ergebnisse der Scans laut Board-Anleitung posten: Defogger: defogger_disable by jpshortstuff (23.02.10.1) Log created at 18:51 on 11/05/2014 (Libelle) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST: frst.text Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 Ran by Libelle (administrator) on PC on 11-05-2014 18:53:25 Running from C:\Users\Libelle\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdat-ed. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe (Informatic Ltd.) C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe (Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & De-stroy\SDWinSec.exe (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (FNet Co., Ltd.) C:\Program Files (x86)\XFastUsb\XFastUsb.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Pan-el\VolPanlu.exe (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Geek Software GmbH) E:\Programme\PDF24\pdf24.exe (Adobe Systems Inc.) E:\Programme\Adobe Pro\Acrobat\acrotray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Compo-nents\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Compo-nents\UNS\UNS.exe (Microsoft Corporation) C:\Windows\HelpPane.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office 2010\Office14\WINWORD.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\AmbRunE.dll [17920 2009-02-26] (Creative Technology Ltd.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1580368 2010-11-03] (Logitech, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3019376 2011-02-22] (VIA) HKLM-x32\...\Run: [XFastUsb] => C:\Program Files (x86)\XFastUsb\XFastUsb.exe [4942336 2012-04-18] (FNet Co., Ltd.) HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office 2010\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incor-porated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Soft-ware\Avast\AvastUI.exe [3873704 2014-04-26] (AVAST Software) HKLM-x32\...\Run: [PDFPrint] => E:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Programme\Adobe Pro\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4118839908-2255762619-2302489997-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.) HKU\S-1-5-21-4118839908-2255762619-2302489997-1000\...\MountPoints2: {34f6a3cb-904a-11e1-98fa-002522ce01c6} - F:\LaunchU3.exe -a Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ORFO Agent.lnk ShortcutTarget: ORFO Agent.lnk -> C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe (Informatic Ltd.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://at.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3097DBB87D1DCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache Accept-Langs = de-at HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013 SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013 SearchScopes: HKCU - DefaultScope {E17E02ED-3C1F-4989-A889-B0611CDF9C26} URL = http://search.softonic.com/MOY00006/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=fce15e28000000000000002522ce01c6&r=71 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968 SearchScopes: HKCU - {D4DC2C6E-7CE3-47a9-9224-D11F8999EB99} URL = http://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} SearchScopes: HKCU - {E17E02ED-3C1F-4989-A889-B0611CDF9C26} URL = http://search.softonic.com/MOY00006/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=fce15e28000000000000002522ce01c6&r=71 BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corpora-tion) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorpo-rated) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Mi-crosoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorpo-rated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Dragon NaturallySpeaking Rich Internet Application Support - Extension - {73A89C60-CF59-4EC7-9215-9B7EF05ECEA4} - E:\Dragon Naturally Speaking 12 Deutsch\Program\ieShim.dll (Nuance Communications, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorpo-rated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh\Softonic.dll (Softonic.com) BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorpo-rated) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Fi-les\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorpora-ted) Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicTlbr.dll (Softonic.com) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Fi-les\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{EDEF3BBF-1341-4E63-9148-8934BB617129}: [NameSer-ver]130.244.127.161,130.244.127.169 FireFox: ======== FF ProfilePath: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default FF user.js: detected! => C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js FF Homepage: www.google.at | www.pons.eu FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Fi-les\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Fi-les\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silver-light\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Fi-les\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.669 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Acrobat - E:\Programme\Adobe Pro\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Fi-les\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: nuance.com/DragonRIAPlugin - E:\DRAGON~4\Program\npDgnRia.dll (Nuance Communications Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\softonic.xml FF SearchPlugin: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla fire-fox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla fire-fox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla fire-fox\browser\searchplugins\yahoo-de.xml FF Extension: Разпознаване на устройство Logitech - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\DeviceDetection@logitech.com [2012-04-19] FF Extension: Microsoft .NET Framework Assistant - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012-04-19] FF Extension: Flash and Video Download - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-04-25] FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2012-04-19] FF Extension: Classic Theme Restorer - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-10] FF Extension: Advertising Cookie Opt-out - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\optout@google.com.xpi [2013-02-07] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-20] FF Extension: Adblock Plus - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-02-07] FF Extension: Menu Editor - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi [2012-04-19] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: No Name - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-06-24] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Soft-ware\Avast\WebRep\FF [2012-04-19] FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi FF Extension: No Name - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi [2013-02-11] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn [2014-04-22] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Softonic Chrome Toolbar) - C:\Users\Libelle\AppData\Local\Google\Chrome\User Da-ta\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-06-18] CHR HKCU\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-06-18] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - E:\Programme\Adobe Pro\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21] CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonic.crx [2013-05-01] CHR HKLM-x32\...\Chrome\Extension: [mikhcaiakabeeokmenglcdebplfdjicn] - E:\Dragon Naturally Speaking 12 Deutsch\Program\chromeShim.crx [2013-02-11] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-26] (AVAST Software) S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation) R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & De-stroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S4 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-26] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-26] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-26] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-04-26] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-26] () S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-11 18:53 - 2014-05-11 18:53 - 00022279 _____ () C:\Users\Libelle\Desktop\FRST.txt 2014-05-11 18:53 - 2014-05-11 18:53 - 00000000 ____D () C:\FRST 2014-05-11 18:51 - 2014-05-11 18:51 - 00000476 _____ () C:\Users\Libelle\Desktop\defogger_disable.log 2014-05-11 18:51 - 2014-05-11 18:38 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe 2014-05-11 18:50 - 2014-05-11 18:50 - 02066432 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe 2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable 2014-05-10 01:08 - 2014-05-10 01:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList 2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-05-07 18:24 - 2014-05-07 18:25 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-05-04 23:32 - 2014-05-11 18:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-04 23:32 - 2014-05-04 23:32 - 00692400 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-04 23:32 - 2014-05-04 23:32 - 00070832 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-04 23:32 - 2014-05-04 23:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-03 00:42 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-03 00:42 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-03 00:42 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-03 00:42 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-30 10:52 - 2014-04-30 10:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 08:58 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 08:58 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-29 23:43 - 2014-04-30 08:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex 2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-04-22 11:30 - 2014-04-26 09:51 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-04-22 11:30 - 2014-04-26 09:51 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-04-22 11:30 - 2014-04-26 09:51 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download As-sistant.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2014-04-11 01:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-11 01:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-11 01:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-11 01:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-11 01:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-11 01:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-11 01:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-11 01:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-11 01:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-11 01:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-11 01:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-11 01:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-11 01:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-11 01:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-11 01:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-11 01:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-11 01:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-11 01:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-11 01:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-11 01:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-11 01:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-11 01:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-11 01:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-11 01:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-11 01:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-11 01:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-11 01:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-11 01:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-11 01:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-11 01:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-11 01:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-11 01:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-11 01:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-11 01:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-11 01:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-11 01:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-11 01:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-11 01:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-11 01:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-11 01:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-11 01:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-11 01:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-11 01:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-11 01:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll ==================== One Month Modified Files and Folders ======= 2014-05-11 18:53 - 2014-05-11 18:53 - 00022279 _____ () C:\Users\Libelle\Desktop\FRST.txt 2014-05-11 18:53 - 2014-05-11 18:53 - 00000000 ____D () C:\FRST 2014-05-11 18:51 - 2014-05-11 18:51 - 00000476 _____ () C:\Users\Libelle\Desktop\defogger_disable.log 2014-05-11 18:50 - 2014-05-11 18:50 - 02066432 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe 2014-05-11 18:38 - 2014-05-11 18:51 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe 2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable 2014-05-11 18:38 - 2012-04-18 16:36 - 00000000 ____D () C:\Users\Libelle 2014-05-11 18:28 - 2014-05-04 23:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-11 18:27 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-11 18:27 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-11 18:26 - 2011-04-12 09:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-05-11 18:26 - 2011-04-12 09:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-05-11 18:26 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-11 18:23 - 2012-04-18 22:45 - 01453003 _____ () C:\Windows\WindowsUpdate.log 2014-05-11 18:20 - 2013-03-04 22:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-11 18:20 - 2012-07-17 22:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-05-11 18:20 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-11 18:20 - 2009-07-14 06:51 - 00163101 _____ () C:\Windows\setupact.log 2014-05-11 18:11 - 2013-03-04 22:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-11 12:45 - 2012-09-08 14:45 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Skype 2014-05-11 12:13 - 2012-05-03 11:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-11 01:23 - 2012-04-22 14:10 - 00000000 ____D () C:\Users\Libelle\Desktop\***** 2014-05-10 01:08 - 2014-05-10 01:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-09 11:06 - 2013-03-04 22:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 11:06 - 2013-03-04 22:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-09 01:17 - 2012-06-24 16:12 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\vlc 2014-05-08 15:32 - 2012-05-12 21:03 - 00000000 ____D () C:\Users\Libelle\AppData\Local\CrashDumps 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList 2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-05-07 18:25 - 2014-05-07 18:24 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-05-04 23:32 - 2014-05-04 23:32 - 00692400 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-04 23:32 - 2014-05-04 23:32 - 00070832 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-04 23:32 - 2014-05-04 23:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-04 23:32 - 2012-04-19 11:29 - 00000000 ____D () C:\Downloads Program-me 2014-05-04 23:32 - 2012-04-18 18:46 - 00000000 ____D () C:\Users\Libelle\AppData\Local\Adobe 2014-05-04 23:30 - 2012-04-18 18:26 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-30 10:52 - 2014-04-30 10:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 08:59 - 2014-04-29 23:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-29 16:01 - 2014-05-03 00:42 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 15:40 - 2014-05-03 00:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 14:48 - 2014-05-03 00:42 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-29 14:34 - 2014-05-03 00:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-27 11:32 - 2010-11-21 05:47 - 00893798 _____ () C:\Windows\PFRO.log 2014-04-26 23:03 - 2012-04-19 11:46 - 00000000 ____D () C:\Users\Libelle\Desktop\Utilities 2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-04-26 17:51 - 2014-03-22 22:35 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-04-26 17:51 - 2013-03-21 15:18 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-26 17:51 - 2013-03-21 15:18 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-26 17:51 - 2012-04-19 14:20 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-04-26 17:51 - 2012-04-19 14:20 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-04-26 17:51 - 2012-04-19 14:20 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-26 17:51 - 2012-04-19 14:20 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-26 17:51 - 2012-04-19 14:20 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-26 09:51 - 2014-04-22 11:30 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-04-26 09:51 - 2014-04-22 11:30 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-04-26 09:51 - 2014-04-22 11:30 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-04-26 09:48 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-22 17:40 - 2009-07-14 06:45 - 00399824 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-22 13:59 - 2012-04-18 23:36 - 00101920 _____ () C:\Users\Libelle\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex 2014-04-22 11:32 - 2012-04-18 18:26 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Adobe 2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-04-22 11:31 - 2012-04-18 18:26 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download As-sistant.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2014-04-20 01:57 - 2013-12-18 00:20 - 00000000 ____D () C:\Users\Libelle\Desktop\jin shin 2014-04-14 04:24 - 2014-04-30 08:58 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-04-30 08:58 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-12 13:36 - 2012-04-18 23:36 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-04-11 16:50 - 2013-06-13 16:03 - 00000000 ____D () C:\Windows\rescache 2014-04-11 15:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-11 01:05 - 2012-05-28 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 01:03 - 2013-07-25 11:06 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 01:02 - 2012-04-19 13:54 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Files to move or delete: ==================== C:\ProgramData\ezsid.dat Some content of TEMP: ==================== C:\Users\Libelle\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Libelle\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Libelle\AppData\Local\Temp\vlc-2.1.3-win32.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-09 10:46 ==================== End Of Log ============================ application.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-05-2014 Ran by Libelle at 2014-05-11 18:53:50 Running from C:\Users\Libelle\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated) Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.06 - Adobe Systems) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.6 - Adobe Systems Incorporated) Hid-den Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASRock App Charger v1.0.4 (HKLM\...\ASRock App Charger_is1) (Version: - AS-Rock Inc.) ASRock eXtreme Tuner v0.1.77 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version: - ) ASRock InstantBoot v1.26 (HKLM-x32\...\ASRock InstantBoot_is1) (Version: - ) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2018 - Avast Software) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon iP4200 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4200) (Version: - ) Canon MG3100 series Benutzerregistrierung (HKLM-x32\...\Canon MG3100 series Benutzerregistrierung) (Version: - ) Canon MG3100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series) (Version: - ) Canon MG3100 series On-screen Manual (HKLM-x32\...\Canon MG3100 series On-screen Manual) (Version: - ) Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - ) Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version: - Microsoft) Dragon NaturallySpeaking 12 (HKLM-x32\...\{D5D422B9-6976-4E98-8DDF-9632CB515D7E}) (Version: 12.50.000 - Nuance Communications Inc.) FLV Player (HKCU\...\FLV Player) (Version: - ) Free Studio version 2013 (HKLM-x32\...\Free Studio_is1) (Version: 6.1.8.725 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Versi-on: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (HKLM-x32\...\Office14.OMUI.pt-br) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Language Pack 2010 - Portuguese/Português (HKLM-x32\...\Office14.OMUI.pt-pt) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Language Pack 2010 - Spanish/Español (HKLM-x32\...\Office14.OMUI.es-es) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office O MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office O MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office O MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Versi-on: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Basque) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proof (Catalan) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proof (Galician) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corpo-ration) Hidden Microsoft Office Proof (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Shared 64-bit MUI (Portuguese (Brazil)) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (Portuguese (Portugal)) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (Spanish) 2010 (Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office SharePoint Designer MUI (Portuguese (Portugal)) 2010 (x32 Versi-on: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office SharePoint Designer MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office X MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office X MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office X MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Ver-sion: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Micro-soft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Micro-soft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{cde5fd82-4a8f-483e-adf0-ca7343d00433}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Versi-on: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Nero 12 (HKLM-x32\...\{80836C86-1305-40C9-B7C9-F3A75266070D}) (Version: 12.5.01900 - Nero AG) Nero Audio Pack 1 (x32 Version: 11.0.11500.110.0 - Nero AG) Hidden Nero BackItUp (x32 Version: 12.5.1000 - Nero AG) Hidden Nero BackItUp Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden Nero Blu-ray Player (x32 Version: 12.0.20014 - Nero AG) Hidden Nero Blu-ray Player Help (CHM) (x32 Version: 12.0.9000 - Nero AG) Hidden Nero Burning ROM (x32 Version: 12.5.5001 - Nero AG) Hidden Nero Burning ROM Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Hidden Nero ControlCenter (x32 Version: 11.0.15600 - Nero AG) Hidden Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden Nero Core Components (x32 Version: 11.0.20200 - Nero AG) Hidden Nero Disc Menus Basic (x32 Version: 12.0.11500 - Nero AG) Hidden Nero Effects Basic (x32 Version: 12.0.11500 - Nero AG) Hidden Nero Express (x32 Version: 12.5.5002 - Nero AG) Hidden Nero Express Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden Nero Kwik Media (x32 Version: 1.18.20100 - Nero AG) Hidden Nero Kwik Media Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden Nero Kwik Themes Basic (x32 Version: 12.0.11500 - Nero AG) Hidden Nero PiP Effects Basic (x32 Version: 12.0.11500 - Nero AG) Hidden Nero Recode (x32 Version: 12.5.6000 - Nero AG) Hidden Nero Recode Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden Nero RescueAgent (x32 Version: 12.0.10002 - Nero AG) Hidden Nero RescueAgent Help (CHM) (x32 Version: 12.0.7000 - Nero AG) Hidden Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden Nero Video (x32 Version: 12.5.2001 - Nero AG) Hidden Nero Video Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden neroxml (x32 Version: 1.0.0 - Nero AG) Hidden Office-Bibliothek (HKLM-x32\...\{5C81B189-5456-40C4-9313-7FE6FA6DD64C}) (Version: 5.00.4 - Bibliographisches Institut & F.A. Brockhaus AG) ORFO 9.0 (HKLM-x32\...\InstallShield_{FDEA11CF-BAF9-4EFE-AF7C-58EAB614A407}) (Version: 9.0 - Informatic) ORFO 9.0 (HKLM-x32\...\Orfo) (Version: - ) ORFO 9.0 (x32 Version: 9.0 - Informatic) Hidden PDF24 Creator 6.3.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Platform (x32 Version: 1.36 - VIA Technologies, Inc.) Hidden Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Versi-on: 7.75.80.95 - Apple Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.41.216.2011 - Realtek) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{1C7BD792-204F-49EB-BF0B-A0F9C904128D}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{95604CB2-E3F3-40FD-B90D-2DB0F144F4A2}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{18B9CFE9-6DD6-4C09-8146-F443DBBD62CF}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (x32 Version: - Microsoft) Hidden Ski Challenge 14 (HKCU\...\sc14-GAMETWIST_MAIN) (Version: - ) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Ver-sion: 6.14.104 - Skype Technologies S.A.) Softonic toolbar on IE and Chrome (HKLM-x32\...\Softonic) (Version: 1.8.19.3 - Sof-tonic) <==== ATTENTION Sound Blaster X-Fi MB (HKLM-x32\...\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}) (Version: 1.0 - Creative Technology Limited) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Tele2 Internet (x32 Version: 1.0 - Tele2UTA Telecommunication GmbH) Hidden Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OMUI.es-es_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.pt-br_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.es-es_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.pt-br_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{956FF6E4-8BBB-4B9A-9279-8A34D8C1FF9D}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{3552349D-C975-406D-84B8-BA298D01D5F7}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{A57A9AE3-09A9-44A0-AA78-458C71DA6FDE}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{27F43FC3-052A-41B5-9F39-68514C0AABC2}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{44E3400B-C404-4656-8D25-EBEC0E6A5222}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{837C1EAC-6A89-44A0-8C45-E655AAFD8CE1}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) XFastUsb (HKLM-x32\...\XFastUsb) (Version: - ) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03783D24-AA74-4CDE-B9F4-D3ABE357AA53} - Sys-tem32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-04] (Google Inc.) Task: {096FEDF5-8579-4831-B7BC-462F5EBFD18F} - Sys-tem32\Tasks\{8EFD28B5-5E1F-4DE6-96B8-F7CF102255A3} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10] (Skype Technologies S.A.) Task: {1248B4FD-7AE0-4B42-B790-866611FFEA14} - Sys-tem32\Tasks\DealPlyUpdate => C:\Program Files (x86)\DealPly\DealPlyUpdate.exe <==== ATTENTION Task: {13CB59E9-9BE8-4C54-B915-88CC0A9CB39B} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Fi-les\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {4D3F1791-8000-4EEF-BEEF-0F79914B7FEE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-04] (Adobe Systems Incorporated) Task: {825D6925-CBE2-468F-AA1B-2C6AEDA58972} - Sys-tem32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {85218FCB-9AF2-4874-B6FF-742282D14F92} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-26] (AVAST Software) Task: {A3D367F9-DF1F-4D7A-9C93-2A55841D67C0} - Sys-tem32\Tasks\RealUpgradeLogonTaskS-1-5-21-4118839908-2255762619-2302489997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-06-21] (RealNetworks, Inc.) Task: {AA1CF60E-851D-4740-B83A-F128B4B22DB2} - Sys-tem32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4118839908-2255762619-2302489997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-06-21] (RealNetworks, Inc.) Task: {B4F34596-E14C-4B4B-8A0E-D14F6D3D477D} - System32\Tasks\Java Up-date Scheduler => C:\Program Files (x86)\Common Files\Java\Java Up-date\jusched.exe Task: {D17E44B3-BF5E-4467-9E04-32B24F519B31} - Sys-tem32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E39552D0-681F-4E9D-8E67-6DFAA77FBF39} - Sys-tem32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-04] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Fi-les\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2012-04-18 18:22 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-04-18 18:23 - 2011-02-22 08:03 - 00078448 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2012-04-18 18:23 - 2011-02-22 08:03 - 00386160 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2012-04-18 18:23 - 2011-02-22 08:03 - 00621168 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll 2014-05-11 12:14 - 2014-05-11 12:14 - 02253312 _____ () C:\Program Files\AVAST Software\Avast\defs\14051100\algo.dll 2014-05-11 18:21 - 2014-05-11 18:21 - 02253312 _____ () C:\Program Files\AVAST Software\Avast\defs\14051103\algo.dll 2012-04-18 18:27 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL 2012-04-18 18:27 - 2009-04-20 11:55 - 00148480 _____ () C:\Windows\SysWOW64\APOMngr.DLL 2014-03-22 22:35 - 2014-03-22 22:35 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2012-09-23 20:43 - 2012-09-23 20:43 - 00010240 _____ () E:\Programme\Adobe Pro\Acrobat\locale\de_de\acrotray.deu 2014-04-29 23:43 - 2014-04-29 23:43 - 03019888 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2014-04-29 23:43 - 2014-04-29 23:43 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2014-04-29 23:43 - 2014-04-29 23:43 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2014-05-10 01:08 - 2014-05-10 01:08 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2014-05-04 23:32 - 2014-05-04 23:32 - 16351920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2013-12-21 08:05 - 2013-12-21 08:05 - 00133120 _____ () E:\Programme\Adobe Pro\Acrobat\Locale\de_de\PDFMaker\PDFMOfficeAddin.DEU ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8 ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: NAUpdate => 2 MSCONFIG\Services: VIAKaraokeService => 2 MSCONFIG\Services: WSearch => 2 MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Fi-les\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: CanonMyPrinter => C:\Program Fi-les\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon MSCONFIG\startupreg: VoipCheapCom => "E:\VoipCheapCom\VoipCheapCom.exe" -nosplash -minimized ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/11/2014 06:20:50 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/11/2014 06:18:08 PM) (Source: Application Hang) (User: ) (EventID: 1002) Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1108 Startzeit: 01cf6d01cbbea2b9 Endzeit: 133 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: c50c3e73-d927-11e3-9928-002522ce01c6 Error: (05/11/2014 00:13:31 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/11/2014 01:53:24 AM) (Source: SideBySide) (User: ) (EventID: 80) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (05/10/2014 10:49:42 AM) (Source: SideBySide) (User: ) (EventID: 80) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (05/10/2014 10:20:01 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/09/2014 10:47:22 AM) (Source: SideBySide) (User: ) (EventID: 80) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (05/09/2014 10:17:53 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/08/2014 03:32:16 PM) (Source: Application Error) (User: ) (EventID: 1000) Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17041, Zeitstempel: 0x53180888 Name des fehlerhaften Moduls: IEFRAME.dll, Version: 11.0.9600.17041, Zeitstem-pel: 0x53181af7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000148331 ID des fehlerhaften Prozesses: 0x183c Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0 Pfad der fehlerhaften Anwendung: iexplore.exe1 Pfad des fehlerhaften Moduls: iexplore.exe2 Berichtskennung: iexplore.exe3 Error: (05/08/2014 03:32:01 PM) (Source: Application Error) (User: ) (EventID: 1000) Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17041, Zeitstempel: 0x53180888 Name des fehlerhaften Moduls: IEFRAME.dll, Version: 11.0.9600.17041, Zeitstem-pel: 0x53181af7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000148331 ID des fehlerhaften Prozesses: 0x1bc8 Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0 Pfad der fehlerhaften Anwendung: iexplore.exe1 Pfad des fehlerhaften Moduls: iexplore.exe2 Berichtskennung: iexplore.exe3 System errors: ============= Error: (05/11/2014 03:56:03 PM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/09/2014 11:48:38 PM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/08/2014 03:39:17 PM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/08/2014 11:13:35 AM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/07/2014 10:16:01 AM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/04/2014 03:07:00 PM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (05/02/2014 11:29:37 AM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (04/28/2014 08:39:16 PM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (04/24/2014 07:47:16 PM) (Source: Disk) (User: ) (EventID: 11) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR4 gefunden. Error: (04/23/2014 10:06:01 PM) (Source: volsnap) (User: ) (EventID: 36) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Microsoft Office Sessions: ========================= Error: (05/11/2014 06:20:50 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/11/2014 06:18:08 PM) (Source: Application Hang) (User: ) (EventID: 1002) Description: firefox.exe29.0.1.5239110801cf6d01cbbea2b9133C:\Program Files (x86)\Mozilla Firefox\firefox.exec50c3e73-d927-11e3-9928-002522ce01c6 Error: (05/11/2014 00:13:31 PM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/11/2014 01:53:24 AM) (Source: SideBySide) (User: ) (EventID: 80) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestE:\Dragon Naturally Speaking 12 Deutsch\Program\dragon_support_packager.exe Error: (05/10/2014 10:49:42 AM) (Source: SideBySide) (User: ) (EventID: 80) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestE:\Dragon Naturally Speaking 12 Deutsch\Program\dragon_support_packager.exe Error: (05/10/2014 10:20:01 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/09/2014 10:47:22 AM) (Source: SideBySide) (User: ) (EventID: 80) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestE:\Dragon Naturally Speaking 12 Deutsch\Program\dragon_support_packager.exe Error: (05/09/2014 10:17:53 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003 Error: (05/08/2014 03:32:16 PM) (Source: Application Error) (User: ) (EventID: 1000) Description: iexplo-re.exe11.0.9600.1704153180888IEFRAME.dll11.0.9600.1704153181af7c00000050000000000148331183c01cf6ac1ed3b8984C:\Program Files\Internet Explo-rer\iexplore.exeC:\Windows\system32\IEFRAME.dll2b1c05a6-d6b5-11e3-acf9-002522ce01c6 Error: (05/08/2014 03:32:01 PM) (Source: Application Error) (User: ) (EventID: 1000) Description: iexplo-re.exe11.0.9600.1704153180888IEFRAME.dll11.0.9600.1704153181af7c000000500000000001483311bc801cf6ac1e47bd868C:\Program Files\Internet Explo-rer\iexplore.exeC:\Windows\system32\IEFRAME.dll228846a8-d6b5-11e3-acf9-002522ce01c6 ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 3816.75 MB Available physical RAM: 1727.88 MB Total Pagefile: 7631.67 MB Available Pagefile: 5562.29 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:59.53 GB) (Free:7.29 GB) NTFS Drive e: (Volume) (Fixed) (Total:931.51 GB) (Free:643.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 60 GB) (Disk ID: 5B478C15) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=60 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 36DE7CD4) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Gmer: Code:
ATTFilter GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-05-11 19:19:35 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 M4-CT064M4SSD2 rev.0309 59,63GB Running: Gmer-19357.exe; Driver: C:\Users\Libelle\AppData\Local\Temp\pxldapow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wininit.exe[480] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Windows\system32\services.exe[528] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Windows\system32\winlogon.exe[588] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Windows\System32\svchost.exe[932] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Windows\system32\svchost.exe[984] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe[436] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Windows\Explorer.EXE[1276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Windows\system32\taskhost.exe[1352] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1548] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Windows\System32\rundll32.exe[1824] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076e6ef8d 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe[2036] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe[2036] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000755d1465 2 bytes [5D, 75] .text C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe[2036] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000755d14bb 2 bytes [5D, 75] .text ... * 2 .text C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe[2108] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\ProgramData\FLEXnet\Connect\11\agent.exe[2396] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Program Files (x86)\XFastUsb\XFastUsb.exe[2496] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe[2516] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe[2864] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text E:\Programme\PDF24\pdf24.exe[2072] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text E:\Programme\Adobe Pro\Acrobat\acrotray.exe[2600] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[3160] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[2776] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] .text C:\Users\Libelle\Desktop\Gmer-19357.exe[1908] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000753ba2fd 1 byte [62] ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [2556:3080] 000007fef0b99688 ---- EOF - GMER 2.1 ---- Ich hoffe, ich habe alles richtig gemacht mit den Logfiles. Einen Virenscan mit avast habe ich ebenfalls durchgeführt, da wurde jedoch nichts gefunden. Ich wäre euch sehr dankbar, wenn ihr mir helfen könnt! Es ist ein ziemlich lästiges Problem, da man nie weiß, wann wieder der nächste Absturz kommt. Vielen Dank schonmal im Voraus für eure Hilfe! jvc |
12.05.2014, 06:51 | #2 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab hi,
__________________Scan mit Combofix
__________________ |
12.05.2014, 10:24 | #3 |
| Firefox stürzt ständig ab Hallo schrauber,
__________________vielen Dank für deine Antwort!! Ich poste hier das Ergebnis vom Combofix: Code:
ATTFilter Combofix Logfile: Es gab während des Scans ein kleines Problem: Circa bei Stufe 7 kam in einem kleinen Fenster folgende Meldung: PEV.exe funktioniert nicht mehr Das Programm wird aufgrund eines Problems nicht richtig ausgeführt. Das Programm wird geschlossen und Sie werden benachrichtigt, wenn eine Lösung verfügbar ist. Dann kam der Button "Programm schließen" Da der Scan im Hintergrund jedoch einfach weiterlief, habe ich gar nichts gemacht (da ich ja die Maus nicht bewegen soll). Das Fenster schloss sich dann gegen Ende des Scans und las Logfile wurde problemlos erstellt. Ich kann die ganzen bisherigen Logfiles leider überhaupt nicht deuten (kenne mich diesbezüglich gar nicht aus), kannst du mir sagen, ob mein PC infiziert ist? Vielen Dank für deine Hilfe und viele Grüße, jvc |
13.05.2014, 09:35 | #4 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab Ja, jede menge Adware. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.05.2014, 21:16 | #5 |
| Firefox stürzt ständig ab Hallo schrauber, vielen Dank für deine Nachricht und für deine Hilfe. Im folgenden poste ich die Logfiles: Malwarebytes Anti-Malware (hier gab es über 60 Funde): Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2014/05/13 11:31:23 +0200</date> <log>mbam-log-2014-05-13 (11-25-43).xml</log> <isadmin>yes</isadmin> </header> <engine> <version>2.00.1.1004</version> <rules-database>v2014.05.13.06</rules-database> <swissarmy-database>v2014.03.27.01</swissarmy-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>Libelle</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>287471</objects> <time>336</time> <processes>0</processes> <modules>0</modules> <keys>25</keys> <values>3</values> <datas>5</datas> <folders>9</folders> <files>116</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <shuriken>enabled</shuriken> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <key><path>HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>668458f85f1c93a3c0242238fe043fc1</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>668458f85f1c93a3c0242238fe043fc1</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7674aca4205bd066b1ddcb59f50d946c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>40aa7dd33447e155c0e5751307fb8d73</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>1dcda4ac3b4063d37e27097fae5444bc</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>45a5b79994e737ff762fdfa9a260718f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>a941a9a7de9d1f172283addb1de5e61a</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\elchiiiejkobdbblfejjkbphbddgmljf</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>28c2e36dcdaeca6c7632dfa9689a9b65</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>b733ca869edd11254b5ea9df38cad030</hash></key> <key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>48a2dc740675989e7e960ba243c05aa6</hash></key> <key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE</path><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><hash>ad3d93bd572495a1d16a614c6e95af51</hash></key> <key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>19d1d27ea6d5dc5ad6d089ff4db502fe</hash></key> <key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>8268163a05767abc214588fd679ba15f</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key> <value><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR</path><valuename>{5018CFD2-804D-4C99-9F81-25EAEA2769DE}</valuename><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><valuedata>Softonic Toolbar</valuedata><hash>7674aca4205bd066b1ddcb59f50d946c</hash></value> <value><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}</path><valuename></valuename><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><valuedata></valuedata><hash>1dcd6ce4710a2d0989050321e31f28d8</hash></value> <value><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE</path><valuename>tb</valuename><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><valuedata>0J1H1HtGtCtH1Q1R1T1VtF0C</valuedata><hash>ad3d93bd572495a1d16a614c6e95af51</hash></value> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL</path><valuename>Default</valuename><vendor>PUP.Optional.SnapDo.A</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</baddata><gooddata>www.google.com</gooddata><hash>b93128283546e6504a6596a5d92b0af6</hash></data> <data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Start Page</valuename><vendor>PUP.Optional.StartPage</vendor><action>replaced</action><valuedata>hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968</valuedata><baddata>hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968</baddata><gooddata>hxxp://www.google.com</gooddata><hash>c2285ff1f784e551e24edc6964a09868</hash></data> <data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>Default_Search_URL</valuename><vendor>PUP.Optional.Snapdo</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</baddata><gooddata>hxxp://www.google.com</gooddata><hash>a446f858f08b092dda3daa9b2dd751af</hash></data> <data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>SearchAssistant</valuename><vendor>PUP.Optional.Snapdo</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</baddata><gooddata>hxxp://www.google.com</gooddata><hash>d11995bbf784043217014302818303fd</hash></data> <data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL</path><valuename>Default</valuename><vendor>PUP.Optional.SnapDo.A</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013</baddata><gooddata>www.google.com</gooddata><hash>45a5d17f97e449edb6faf04ba2621ee2</hash></data> <folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder> <folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder> <folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\D59E0BB400B9476EB0564E8D56C48B04</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder> <folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\F31A901D6C9C490A932D30C45DE6DE96</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder> <folder><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></folder> <folder><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></folder> <folder><path>C:\Program Files (x86)\Softonic\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></folder> <folder><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></folder> <folder><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></folder> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicTlbr.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7674aca4205bd066b1ddcb59f50d946c</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh\Softonic.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\D59E0BB400B9476EB0564E8D56C48B04\DeltaTB.exe</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>b436a2ae3b4094a2628e61a3eb1612ee</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\F31A901D6C9C490A932D30C45DE6DE96\DeltaTB.exe</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>cb1fa3add8a36acc8b650bf9827f3ac6</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\softonic.xml</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>3bafa9a783f8ac8a376c9eea3cc638c8</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\babylon.xml</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>30ba2e22087359dd8e3c7d0e41c125db</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\Web Search.xml</path><vendor>PUP.Optional.WebSearch.A</vendor><action>success</action><hash>32b8490767144de930b3e2aac24034cc</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\3710.ico</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\EBB77268-338F-4C6A-8590-AD88FED26F4A</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\Installer.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\OCBrowserHelper_1.0.6.128.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\appCntrl.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.html</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CrmAdpt.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\ct.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CTB.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\dpk.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.htm</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\json2.min.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\logo.png</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\manifest.json</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\pref.json</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\escortShld.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\softonic.crx</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicApp.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicEng.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonicsrv.exe</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file> <file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\uninstall.exe</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.aflt", "babsst");</baddata><gooddata></gooddata><hash>a84286cadd9e82b4c20c452c5da726da</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.babExt", "");</baddata><gooddata></gooddata><hash>1fcb321e24573600ca04e38e63a1ac54</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=100512_4_");</baddata><gooddata></gooddata><hash>43a7f9579edd59ddbc12e68b5ba945bb</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.hardId", "fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>eefcd27e5d1ec274ece21a57f60e9070</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.id", "fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>86640c44601bd363b11d383956ae1ee2</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.instlDay", "15472");</baddata><gooddata></gooddata><hash>f2f887c9dc9f8ea8be10640d5da740c0</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.instlRef", "sst");</baddata><gooddata></gooddata><hash>17d394bca0db61d509c5f37e9a6a4cb4</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.newTab", true);</baddata><gooddata></gooddata><hash>7a7074dcb9c200363c924e2341c3d32d</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=110819&tt=100512_4_&babsrc=NT_ss&mntrId=fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>2ebca1af74078babb01e89e89272b44c</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");</baddata><gooddata></gooddata><hash>2fbb4010b7c43ef8b816620fbe467888</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");</baddata><gooddata></gooddata><hash>29c190c0463579bdbf0fc1b059ab3bc5</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.smplGrp", "none");</baddata><gooddata></gooddata><hash>de0c5df3a8d376c022ac98d9e222926e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.srcExt", "ss");</baddata><gooddata></gooddata><hash>29c1034da9d220160ac480f159abb54b</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");</baddata><gooddata></gooddata><hash>f1f9f45c2f4ca88eba14640da65e768a</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");</baddata><gooddata></gooddata><hash>00ea0f41b6c568ce1ab497daa460c23e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:58:29");</baddata><gooddata></gooddata><hash>4d9d5ff11d5e6dc9dbf31e53d034f50b</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");</baddata><gooddata></gooddata><hash>2bbff65af5865bdb5b730b66699bf50b</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.admin", false);</baddata><gooddata></gooddata><hash>58925cf48dee7eb802cd135e9470fd03</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.aflt", "SD");</baddata><gooddata></gooddata><hash>db0f450b1a618babcf006b0649bb728e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");</baddata><gooddata></gooddata><hash>b03ad9771e5d4de9359ac2af4abab749</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.autoRvrt", "false");</baddata><gooddata></gooddata><hash>db0f91bf16658aaca926353cff050ef2</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.dfltLng", "de");</baddata><gooddata></gooddata><hash>43a7321e15666ccadff0d69bc440bb45</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.dfltSrch", true);</baddata><gooddata></gooddata><hash>4e9cb0a0b3c83501339c6e0334d0a25e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.dnsErr", true);</baddata><gooddata></gooddata><hash>9c4e410f9eddfa3cb11e9dd43dc713ed</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.excTlbr", false);</baddata><gooddata></gooddata><hash>49a189c79ae1dc5a20af561b9371fb05</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.ffxUnstlRst", false);</baddata><gooddata></gooddata><hash>11d94010d2a97abc8649b3be14f0af51</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.hmpg", true);</baddata><gooddata></gooddata><hash>19d1d080f18a0432dcf3d29f6a9a02fe</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&cc=&mi=fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>5991b29eb8c3ae8802cd9ad74eb6758b</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.hpOld0", "hxxp://www.google.at|hxxp://de.pons.eu/");</baddata><gooddata></gooddata><hash>8d5d07496a115adc13bc521fbe460cf4</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.id", "fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>7476c28e92e9ef47854acaa7679d1ee2</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.instlDay", "15874");</baddata><gooddata></gooddata><hash>2bbf3c14c4b761d511be0170fc08bb45</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.instlRef", "MOY00006");</baddata><gooddata></gooddata><hash>7e6c58f82f4cd363d3fc51201de7d828</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.kw_url", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=2&cc=&mi=fce15e28000000000000002522ce01c6&q=");</baddata><gooddata></gooddata><hash>17d3222e85f6c76f7f5072ff1ee6a35d</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.newTab", true);</baddata><gooddata></gooddata><hash>cf1b29278af15dd9cd02d899a262dc24</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00006/tb_v1/?SearchSource=15&cc=&mi=fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>8a60193753286cca16b9b4bd04007789</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.prdct", "Softonic");</baddata><gooddata></gooddata><hash>ca20f858e398cb6b6669e48d788cd32d</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.prtnrId", "softonic");</baddata><gooddata></gooddata><hash>1bcf81cf700b5fd7ffd0a9c8f11338c8</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.rvrt", "false");</baddata><gooddata></gooddata><hash>3fabe16f89f245f1339c125fd82ceb15</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.smplGrp", "none");</baddata><gooddata></gooddata><hash>7476de72c7b4c96da728b2bf8183e719</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");</baddata><gooddata></gooddata><hash>cd1dc38df9823402973884edab59ec14</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.tlbrId", "BASEirobinhoodActive");</baddata><gooddata></gooddata><hash>8d5d1040413a2f07a32c5b16bb4936ca</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=1&cc=&mi=fce15e28000000000000002522ce01c6&q=");</baddata><gooddata></gooddata><hash>30ba1a36fb80d85ed3fccea3749054ac</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.vrsn", "1.8.19.3");</baddata><gooddata></gooddata><hash>5694d27e512ad660418e125f798bc739</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.vrsnTs", "1.8.19.39:56:28");</baddata><gooddata></gooddata><hash>a3475ff1c8b382b4fcd3096880842ad6</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref("extensions.Softonic.vrsni", "1.8.19.3");</baddata><gooddata></gooddata><hash>509ab0a095e6af8728a7a9c85ba96997</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.FaceMoods.A</vendor><action>replaced</action><baddata>user_pref("extensions.facemoods.aflt", "_#ironto");</baddata><gooddata></gooddata><hash>5892d27ee99246f0953fea87758f58a8</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.FaceMoods.A</vendor><action>replaced</action><baddata>user_pref("extensions.facemoods.firstRun", false);</baddata><gooddata></gooddata><hash>8367f85879022c0ad004a5ccd82cc937</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.FaceMoods.A</vendor><action>replaced</action><baddata>user_pref("extensions.facemoods.lastActv", "14");</baddata><gooddata></gooddata><hash>8664d17f720942f472622b4617ed9a66</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.admin", false);</baddata><gooddata></gooddata><hash>86647ad6ef8c82b47a5beb862bd958a8</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.aflt", "babsst");</baddata><gooddata></gooddata><hash>608a8bc507749b9b6c69a7ca33d1c838</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");</baddata><gooddata></gooddata><hash>1dcdd47c6a11bd790fc65c15f311a858</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.autoRvrt", "false");</baddata><gooddata></gooddata><hash>c52589c7aad175c16c69e78a16eebd43</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.dfltLng", "de");</baddata><gooddata></gooddata><hash>bb2f1f315c1fea4c845120519272e719</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.excTlbr", false);</baddata><gooddata></gooddata><hash>777389c7d1aa2d09736276fbde26aa56</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.ffxUnstlRst", true);</baddata><gooddata></gooddata><hash>539727295922e4523e97e9885fa56c94</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.id", "fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>b8329db37ffc003642935e13ca3ad828</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.instlDay", "15925");</baddata><gooddata></gooddata><hash>d31769e77902b6805184ee8345bfc23e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.instlRef", "sst");</baddata><gooddata></gooddata><hash>5a9084cc403b5dd94d8895dc5fa50cf4</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.newTab", false);</baddata><gooddata></gooddata><hash>59911e32314a0234dff6521f7a8a5ca4</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.prdct", "delta");</baddata><gooddata></gooddata><hash>bf2b6ae6b6c540f6ffd6571af50f639d</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.prtnrId", "delta");</baddata><gooddata></gooddata><hash>33b79eb263186dc918bd7ff248bc46ba</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.rvrt", "false");</baddata><gooddata></gooddata><hash>db0fcd831d5e65d1b91cda97857f27d9</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.smplGrp", "none");</baddata><gooddata></gooddata><hash>2dbdff51522981b5419499d8857f28d8</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.tlbrId", "base");</baddata><gooddata></gooddata><hash>1ecc56fa8deeb185ce0796dbc83cad53</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.tlbrSrchUrl", "");</baddata><gooddata></gooddata><hash>8961a5abe299a2942ca93938e51f4bb5</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.vrsn", "1.8.22.0");</baddata><gooddata></gooddata><hash>569479d75b203afc5184ee8313f142be</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.vrsnTs", "1.8.22.015:56:44");</baddata><gooddata></gooddata><hash>0dddde7284f70e2807ce472a1fe5ea16</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta.vrsni", "1.8.22.0");</baddata><gooddata></gooddata><hash>dc0e59f70b7059ddbc197cf5a75ddd23</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta_i.babExt", "");</baddata><gooddata></gooddata><hash>effb76da2a51ca6ce6eff1800004d22e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta_i.babTrack", "affID=121564&tt=070813_wt3&tsp=4968");</baddata><gooddata></gooddata><hash>04e670e01269da5c5d7880f1fd0732ce</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref("extensions.delta_i.srcExt", "ss");</baddata><gooddata></gooddata><hash>dd0db7993c3f7fb794411d54c63ef20e</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=100512_4_");</baddata><gooddata></gooddata><hash>8f5b78d87b003afc2c1cf47d0004eb15</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.babExt", "");</baddata><gooddata></gooddata><hash>6486aca4007bb38314346908ab59ce32</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.srcExt", "ss");</baddata><gooddata></gooddata><hash>06e4e46c6912ab8b92b683ee6e96d62a</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.id", "fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>35b52e22daa1a78f390f710051b340c0</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.hardId", "fce15e28000000000000002522ce01c6");</baddata><gooddata></gooddata><hash>37b39bb5eb908fa7fa4ed79a30d4c33d</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.instlDay", "15472");</baddata><gooddata></gooddata><hash>c02a5ff1fb80102607416b06b64e0000</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");</baddata><gooddata></gooddata><hash>86640c44f9825ed84cfc274a22e201ff</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");</baddata><gooddata></gooddata><hash>8b5ff55b80fb092dee5a7df4ff059868</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:58:29");</baddata><gooddata></gooddata><hash>23c729274239989e80c82849a16335cb</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");</baddata><gooddata></gooddata><hash>cf1bbd93562561d54cfc4e23d52f946c</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");</baddata><gooddata></gooddata><hash>2ebcc987671446f0ec5c8fe219ebac54</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.aflt", "babsst");</baddata><gooddata></gooddata><hash>07e30f414536082e3612b8b9986cc33d</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.smplGrp", "none");</baddata><gooddata></gooddata><hash>3eac331d2f4c290db4946011e81cab55</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");</baddata><gooddata></gooddata><hash>de0c62eeabd0ff3749ff650c7f8538c8</hash></file> <file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.instlRef", "sst");</baddata><gooddata></gooddata><hash>f7f34010156694a2d870ef8227dd8d73</hash></file> </items> </mbam-log> AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.208 - Bericht erstellt am 13/05/2014 um 11:44:53 # Aktualisiert 11/05/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Libelle - PC # Gestartet von : C:\Users\Libelle\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\DeviceVM Ordner Gelöscht : C:\Program Files (x86)\Softonic Ordner Gelöscht : C:\Users\Libelle\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Libelle\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Libelle\AppData\Roaming\DeviceVM Ordner Gelöscht : C:\Users\Libelle\AppData\Roaming\dvdvideosoftiehelpers Datei Gelöscht : C:\Users\Libelle\Desktop\Youtube.lnk Datei Gelöscht : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\bProtector_extensions.rdf Datei Gelöscht : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\invalidprefs.js Datei Gelöscht : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_clonedvd_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_clonedvd_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-youtube-download_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-youtube-download_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Softonic ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js ] Zeile gelöscht : user_pref("bearsharemediabar.Var1", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var10", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var2", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var3", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var4", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var5", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var6", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var7", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var8", "0"); Zeile gelöscht : user_pref("bearsharemediabar.Var9", "0"); Zeile gelöscht : user_pref("bearsharemediabar.firstlaunch", "0"); Zeile gelöscht : user_pref("bearsharemediabar.guid", "%7B2C1A1497-5376-0D55-73B6-2E42CF04E463%7D"); Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.babExt", ""); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=100512_4_"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.hardId", "fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.id", "fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.instlDay", "15472"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=110819&tt=100512_4_&babsrc=NT_ss&mntrId=fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:58:29"); Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Zeile gelöscht : user_pref("extensions.Softonic.admin", false); Zeile gelöscht : user_pref("extensions.Softonic.aflt", "SD"); Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true); Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true); Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false); Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false); Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true); Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&cc=&mi=fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.Softonic.hpOld0", "hxxp://www.google.at|hxxp://de.pons.eu/"); Zeile gelöscht : user_pref("extensions.Softonic.id", "fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "15874"); Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00006"); Zeile gelöscht : user_pref("extensions.Softonic.kw_url", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=2&cc=&mi=fce15e28000000000000002522ce01c6&q="); Zeile gelöscht : user_pref("extensions.Softonic.newTab", true); Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00006/tb_v1/?SearchSource=15&cc=&mi=fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic"); Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic"); Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false"); Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "BASEirobinhoodActive"); Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=1&cc=&mi=fce15e28000000000000002522ce01c6&q="); Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.19.3"); Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.19.39:56:28"); Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.19.3"); Zeile gelöscht : user_pref("extensions.delta.admin", false); Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de"); Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true); Zeile gelöscht : user_pref("extensions.delta.id", "fce15e28000000000000002522ce01c6"); Zeile gelöscht : user_pref("extensions.delta.instlDay", "15925"); Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); Zeile gelöscht : user_pref("extensions.delta.newTab", false); Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.22.0"); Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.22.015:56:44"); Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.22.0"); Zeile gelöscht : user_pref("extensions.delta_i.babExt", ""); Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121564&tt=070813_wt3&tsp=4968"); Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss"); Zeile gelöscht : user_pref("extensions.facemoods.aflt", "_#ironto"); Zeile gelöscht : user_pref("extensions.facemoods.firstRun", false); Zeile gelöscht : user_pref("extensions.facemoods.lastActv", "14"); Zeile gelöscht : user_pref("extensions.ffxtlbr@delta.com.install-event-fired", true); Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false); Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true); Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "at"); Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "snapdoocyb"); Zeile gelöscht : user_pref("extensions.helperbar.installationid", "e2104eac-9743-4275-82eb-98b205103149"); Zeile gelöscht : user_pref("extensions.helperbar.installdate", "31/05/2013"); Zeile gelöscht : user_pref("extensions.helperbar.publisher", "snapdoocyb"); -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [14807 octets] - [13/05/2014 11:37:10] AdwCleaner[S0].txt - [14322 octets] - [13/05/2014 11:44:53] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14383 octets] ########## Junkware Removal Tool: JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Libelle on 13.05.2014 at 11:49:02,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4118839908-2255762619-2302489997-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E17E02ED-3C1F-4989-A889-B0611CDF9C26} ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\Libelle\AppData\Roaming\mozilla\firefox\profiles\nzf25kdk.default\minidumps [159 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.05.2014 at 11:59:02,50 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und hier noch FRST (ist hier alles ok mit dem Scan, dass das nur so ein kurzer Bericht nur mit Datum ist?): Code:
ATTFilter LastRegBack: 2014-05-09 10:46 ==================== End Of Log ============================ Wie sieht es denn jetzt aus? Wie gesagt, ich kann das hier alles nicht wirklich deuten... Könntest du mir vielleicht sagen, welches Programm ich in Zukunft nutzen könnte, um soviel Adware wie jetzt zu vermeiden? Gibt es da irgendein Programm, mit dem ich regelmäßig scannen bzw. dann Gefundenes auch (gefahrlos...) entfernen könnte? Vielen Dank für deine Hilfe und viele Grüße, jvc Hallo nochmal, ich hätte noch eine kleine Ergänzung: ich wollte vorhin ein Video auf der Seite einer ausländischen Tageszeitung ansehen, als der Flashplayer schon wieder abgestürzt ist (wie gesagt, ich weiß leider nicht, ob die beiden Probleme zusammenhängen). Das mit den Abstürzen des Flashplayers (immer bei Internetvidos) geht nun schon seit vielen Monaten so... Diesmal kamen folgende Fehlermeldungen: 1. Warnung: nicht antwortendes Plugin Shockwave Flash ist möglicherweise beschäftigt oder reagiert nicht mehr. Sie können das Plugin jetzt stoppen oder fortsetzen, um zu sehen, ob das Plugin weiter arbeitet. -> ich gehe dann immer auf "stoppen", sonst geht nämlich gar nichts mehr. Dann kam die 2. Meldung: Warnung: Nicht antwortendes Skript Ein Script auf dieser Seite ist eventuell beschäftigt oder es antwortet nicht mehr. Sie können das Skript jetzt stoppen oder fortsetzen, um zu sehen, ob das Skript fertig wird. Skript: https://apis.google.com/js/plusone.js:13 -> auch hier gehe ich dann auf "stoppen", da sonst nichts mehr geht Und dann noch die 3. Meldung - das kleine graue Flashplayer-Fenster mit einem nach unten gerichteten Smiley und folgender Text (kenn ich inzw. schon auswendig... ;-) ): Das Plugin "Adobe Flash" ist abgestürzt. Firefox stürzt ständig ab, um es erneut zu versuchen. Oft kommt auch nur die 3. Meldung alleine. Ich habe schon viele Flashplayer-Versionen ausprobiert, x-mal neu installiert (vorher komplett deinstalliert) und auch Firefox neu installiert, bisher war alles umsonst. Ich habe auch viel in Foren gelesen, jedoch nie eine Lösung gefunden, was bei anderen geholfen hat, nützte bei mir nie etwas. Wie gesagt, ich weiß ja nicht, ob die Probleme zusammengehören, ich wollte dir die Fehlermeldungen nur aufschreiben, vielleicht ist das für dich ja ein Hinweis auf etwas. Vielen Dank und noch einen schönen Tag, jvc Hallo schrauber, jetzt muss ich leider nochmal ein Update machen... Falls das für dich wichtig ist, Firefox ist vorhin wieder abgestürzt - mit der üblichen Meldung (Entschuldigung, das hätte nicht passieren dürfen), danach schließen sich alle geöffneten Firefox-Fenster. Ich dachte, vielleicht ist das wichtig für dich als Info... Dankeschön und noch einen schönen Abend, jvc |
14.05.2014, 19:16 | #6 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen Scan auf Reste: ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Firefox stürzt ständig ab |
15.05.2014, 13:56 | #7 |
| Firefox stürzt ständig ab Hallo schrauber, vielen Dank für deine Nachricht! Ich hätte jetzt noch eine Frage, bevor ich alle Schritte durchführe: wenn ich Firefox deinstalliere, werden dann alle meine gespeicherten Links gelöscht? Es sind nämlich ziemlich viele und die müsste ich dann vorher irgendwie sichern... Dankeschön! jvc |
16.05.2014, 11:16 | #8 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab Die kannste vorher exportieren, aber sonst bitte nichts aus Firefox speichern.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.05.2014, 14:22 | #9 |
| Firefox stürzt ständig ab Hallo schrauber, habe nun versucht, das zu machen, was du mir beschrieben hast - leider gab es schon beim ersten Schritt ein mittelmäßiges Drama. Ich habe Firefox mit dem Revo Uninstaller entfernt, gegen Ende des Vorgangs kamen jedoch einige Fragen (es kamen 2 Listen mit Dateien, die Frage war, ob ich die alle entfernen möchte (ich glaube auch Registry-Einträge, weiß es jedoch nicht mehr genau) - da du geschrieben hast, keine Daten behalten, hab ich sämtliche Dateien markiert und gelöscht). Das hat dann soweit auch funktioniert. Dann wollte ich jedoch mit dem Internet Explorer (den ich sonst nie benutze) Firefox downloaden, der Explorer funktionierte jedoch überhaupt nicht richtig! Es ließen sich keine Seiten laden (Internet-Verbindung war jedoch ok, ich konnte meine Mails abrufen), nach einer halben Stunde hat er dann irgendwann Google geladen, ich konnte jedoch keine einzige Seite daraus öffnen. Ich habe dann irgendwann gemerkt, dass ich zwar jeweils die Startseiten laden konnte (zb Google, Tageszeitungen, Mozilla), aber wenn ich innerhalb dieser Seiten eine weitere Seite öffnen wollte, tat sich einfach gar nichts, es öffnete sich ein leeres Fenster, aber nichts ladete (daher große Panik bei mir, weil ich das Internet beruflich dringend brauche). Ich habe dann über meinen alten Laptop das Firefox-Setup heruntergeladen und das dann installiert. Jetzt funktioniert wieder alles, allerdings glaube ich, dass vorher schon beim Deinstallieren etwas schief gegangen ist, denn nach der Firefox-Installation waren weder meine Links gelöscht noch sonstige Einstellungen (Add-ons), es sah alles aus wie vorher... Die weiteren Scans habe ich jetzt daher nicht gemacht, da ich nicht glaube, dass das richtig funktioniert hat. Ich weiß nicht, ob ich mich das mit Revo noch einmal traue, ich glaube, ich bräuchte genauere Anweisungen, was ich während dieses Prozesses ganz genau anklicken soll, da ich mich damit nicht auskenne. Ich kann mir auch nicht erklären, warum nachher der Internet Explorer nicht funktioniert hat, ich hätte nicht einmal im Internet recherchieren und nach Lösungen suchen können... Der Internet Explorer funktioniert übrigens immer noch nicht, meistens kommt folgende Meldung: Die Navigation zu der Webseite wurde abgebrochen (oder einfach gar nichts und er versucht auch gar nicht, eine Seite zu laden) Vielen Dank!! Geändert von jvc (17.05.2014 um 14:29 Uhr) |
18.05.2014, 12:24 | #10 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab Hast Du den Firefox auch nach dem neuen INstallieren zurückgesetzt wie oben angegeben??
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.05.2014, 14:18 | #11 |
| Firefox stürzt ständig ab Hallo, also, ich hab nur den ersten Schritt gemacht (mit dem Revo Uninstaller), da dann bei Firefox noch alle Daten wie vorher vorhanden waren, habe ich nicht mehr weitergemacht, da ich dachte, es hat nicht funktioniert und ich frage besser vorher bei dir nach.. Was meinst du, was ich jetzt am Besten machen soll? Vielen Dank und einen schönen Sonntag! |
19.05.2014, 09:34 | #12 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab FF zurücksetzen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.05.2014, 17:42 | #13 |
| Firefox stürzt ständig ab Hallo schrauber, danke für die Antwort, aber was bedeutet Firefox zurücksetzen..? Soll ich danach mit den restlichen Schritten weitermachen (das hier https://support.mozilla.org/de/kb/fi...einfach-loesen, ESET und Security Check)? Danke! Geändert von jvc (19.05.2014 um 17:49 Uhr) |
20.05.2014, 11:48 | #14 |
/// the machine /// TB-Ausbilder | Firefox stürzt ständig ab Der von dir zitierte Link zeigt doch das Zurücksetzen von Firefox . Ja mach das alles.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.05.2014, 18:11 | #15 |
| Firefox stürzt ständig ab Hallo schrauber, vielen Dank für deine Antwort, jetzt hab ich's verstanden!! ;-) Hier kommt erstmal der ESET Scan, es gab 10 Funde, der Rest kommt dann gleich Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a6bcec977effcd4a913ae78ed3c960e7 # engine=18336 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=false # utc_time=2014-05-20 04:55:21 # local_time=2014-05-20 06:55:21 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 76 376728 2077420 0 0 # compatibility_mode=5893 16776573 100 94 17392 152234771 0 0 # scanned=211549 # found=10 # cleaned=0 # scan_time=11152 sh=095DF1429E4F8DBE71EE72AEE04090E6A8F35931 ft=1 fh=749ee4b2bcea0726 vn="Variante von Win32/DownloadSponsor.A evtl. uner-wünschte Anwendung" ac=I fn="E:\Downloads Programme\PDF24 Creator.exe" sh=49892F2B31FDE87333BA9AD84222DA7493E6AC98 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.F evtl. uner-wünschte Anwendung" ac=I fn="E:\PC\Backup Set 2012-04-23 110626\Backup Files 2012-06-01 121107\Backup files 1.zip" sh=C6BC5D1905E0D1708C558B868AD764E1B6FF3DFB ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\PC\Backup Set 2012-04-23 110626\Backup Files 2012-09-01 131437\Backup files 3.zip" sh=F966F62E111A5C3E7A15687419EE8D2A71B6A7C4 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\PC\Backup Set 2012-10-01 113843\Backup Files 2012-10-01 113843\Backup files 5.zip" sh=0B81499A6E75C8860868AEA41018272A33FCEB48 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2013-06-01 102200\Backup Files 2013-06-01 102200\Backup files 1.zip" sh=E7063D47F1D2936DF344F039F1C9FA4857C3E8C1 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2013-09-01 122740\Backup Files 2013-09-01 122740\Backup files 1.zip" sh=276C8018079581296B484C1E25E483F437C6D7C9 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2013-11-01 123144\Backup Files 2013-11-01 123144\Backup files 1.zip" sh=7CAABE77E57FF26D357C22279B91FD926BA4B0CC ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2014-01-01 125203\Backup Files 2014-01-01 125203\Backup files 1.zip" sh=8FBA19CF36F8D7440DB7EB21DB3A147DA0E6DEF8 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2014-03-01 102548\Backup Files 2014-03-01 102548\Backup files 1.zip" sh=C9FD395FFDA8587F0656929505273AF55AA25A1F ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2014-05-01 120325\Backup Files 2014-05-01 120325\Backup files 2.zip" Hier das Ergebnis von SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Adobe Flash Player 13.0.0.214 Adobe Reader XI Mozilla Firefox (29.0.1) Mozilla Thunderbird (24.5.0) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Spybot Teatimer.exe is disabled! Malwarebytes Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Und hier noch FRST.log FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014 Ran by Libelle (administrator) on PC on 20-05-2014 19:21:11 Running from C:\Users\Libelle\Desktop Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Informatic Ltd.) C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Geek Software GmbH) E:\Programme\PDF24\pdf24.exe (Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Adobe Systems Inc.) E:\Programme\Adobe Pro\Acrobat\acrotray.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (FNet Co., Ltd.) C:\Program Files (x86)\XFastUsb\XFastUsb.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\AmbRunE.dll [17920 2009-02-26] (Creative Technology Ltd.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1580368 2010-11-03] (Logitech, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3019376 2011-02-22] (VIA) HKLM-x32\...\Run: [XFastUsb] => C:\Program Files (x86)\XFastUsb\XFastUsb.exe [4942336 2012-04-18] (FNet Co., Ltd.) HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office 2010\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-26] (AVAST Software) HKLM-x32\...\Run: [PDFPrint] => E:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Programme\Adobe Pro\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-4118839908-2255762619-2302489997-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ORFO Agent.lnk ShortcutTarget: ORFO Agent.lnk -> C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe (Informatic Ltd.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3097DBB87D1DCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {D4DC2C6E-7CE3-47a9-9224-D11F8999EB99} URL = http://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Dragon NaturallySpeaking Rich Internet Application Support - Extension - {73A89C60-CF59-4EC7-9215-9B7EF05ECEA4} - E:\Dragon Naturally Speaking 12 Deutsch\Program\ieShim.dll (Nuance Communications, Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{EDEF3BBF-1341-4E63-9148-8934BB617129}: [NameServer]130.244.127.161,130.244.127.169 FireFox: ======== FF ProfilePath: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\dhylyhti.default-1400592478296 FF Homepage: www.google.at | hxxp://de.pons.com/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.669 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Acrobat - E:\Programme\Adobe Pro\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: nuance.com/DragonRIAPlugin - E:\DRAGON~4\Program\npDgnRia.dll (Nuance Communications Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Classic Theme Restorer - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\dhylyhti.default-1400592478296\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-20] FF Extension: Adblock Plus - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\dhylyhti.default-1400592478296\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-20] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: No Name - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-06-24] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-04-19] FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi FF Extension: Dragon NaturallySpeaking Rich Internet Application Support - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi [2013-02-11] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn [2014-04-22] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - E:\Programme\Adobe Pro\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21] CHR HKLM-x32\...\Chrome\Extension: [mikhcaiakabeeokmenglcdebplfdjicn] - E:\Dragon Naturally Speaking 12 Deutsch\Program\chromeShim.crx [2013-02-11] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-26] (AVAST Software) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation) R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) S4 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-26] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-26] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-26] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-26] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-26] () R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-20] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-20 19:21 - 2014-05-20 19:21 - 00018168 _____ () C:\Users\Libelle\Desktop\FRST.txt 2014-05-20 19:21 - 2014-05-20 19:21 - 00000000 ____D () C:\Users\Libelle\Desktop\FRST-OlderVersion 2014-05-20 19:13 - 2014-05-20 19:13 - 00854367 _____ () C:\Users\Libelle\Desktop\SecurityCheck.exe 2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Downloads\esetsmartinstaller_deu(1).exe 2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Desktop\esetsmartinstaller_deu.exe 2014-05-20 15:28 - 2014-05-20 15:28 - 00000000 ____D () C:\Users\Libelle\Desktop\Alte Firefox-Daten 2014-05-17 15:06 - 2014-05-17 15:06 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-05-17 15:06 - 2014-05-17 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-17 13:34 - 2014-05-17 13:34 - 00000729 _____ () C:\Users\Libelle\Desktop\Revo Uninstaller.lnk 2014-05-17 13:33 - 2014-05-17 13:33 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Libelle\Desktop\revosetup95.exe 2014-05-17 13:20 - 2014-05-17 13:20 - 00120822 _____ () C:\Users\Libelle\Desktop\bookmarks-2014-05-17.json 2014-05-17 13:16 - 2014-05-17 13:16 - 00000676 _____ () C:\Users\Libelle\Desktop\Youtube.lnk 2014-05-15 05:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 05:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 05:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 05:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 05:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 05:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 04:55 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-15 04:55 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-15 04:55 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 04:55 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 04:55 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 04:55 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 04:55 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 04:55 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 04:55 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 04:55 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 04:55 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 04:55 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 04:55 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 04:55 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 04:55 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 04:55 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 04:55 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 04:55 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 04:55 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 04:55 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 04:55 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 04:55 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 04:55 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 04:55 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 04:55 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 04:55 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 04:55 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 04:55 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-13 11:49 - 2014-05-13 11:49 - 00000000 ____D () C:\Windows\ERUNT 2014-05-13 11:48 - 2014-05-13 11:48 - 01016261 _____ (Thisisu) C:\Users\Libelle\Desktop\JRT.exe 2014-05-13 11:37 - 2014-05-13 11:44 - 00000000 ____D () C:\AdwCleaner 2014-05-13 11:37 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-13 11:36 - 2014-05-13 11:36 - 01325827 _____ () C:\Users\Libelle\Desktop\adwcleaner.exe 2014-05-13 11:24 - 2014-05-20 19:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-13 11:24 - 2014-05-13 11:24 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-13 11:24 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-13 11:24 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-13 11:24 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-12 11:13 - 2014-05-12 11:13 - 00024191 _____ () C:\ComboFix.txt 2014-05-12 11:04 - 2014-05-12 11:13 - 00000000 ____D () C:\Qoobox 2014-05-12 11:04 - 2014-05-12 11:11 - 00000000 ____D () C:\Windows\erdnt 2014-05-12 11:04 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-12 11:04 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-12 11:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-12 11:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-12 11:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-12 11:04 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-12 11:04 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-12 11:04 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-12 11:02 - 2014-05-12 11:03 - 05200347 ____R (Swearware) C:\Users\Libelle\Desktop\ComboFix.exe 2014-05-11 19:14 - 2014-05-11 19:14 - 00380416 _____ () C:\Users\Libelle\Desktop\Gmer-19357.exe 2014-05-11 19:02 - 2014-05-11 19:02 - 00380416 _____ () C:\Users\Libelle\Downloads\Gmer-19357.exe 2014-05-11 18:53 - 2014-05-20 19:21 - 00000000 ____D () C:\FRST 2014-05-11 18:51 - 2014-05-11 18:38 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe 2014-05-11 18:50 - 2014-05-20 19:21 - 02067456 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe 2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList 2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-05-07 18:24 - 2014-05-07 18:25 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-05-04 23:32 - 2014-05-20 18:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-04 23:32 - 2014-05-14 19:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-04 23:32 - 2014-05-14 19:28 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-04 23:32 - 2014-05-14 19:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-30 10:52 - 2014-05-15 14:18 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 23:43 - 2014-04-30 08:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex 2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-04-22 11:30 - 2014-04-26 09:51 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-04-22 11:30 - 2014-04-26 09:51 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-04-22 11:30 - 2014-04-26 09:51 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 ==================== One Month Modified Files and Folders ======= 2014-05-20 19:21 - 2014-05-20 19:21 - 00018168 _____ () C:\Users\Libelle\Desktop\FRST.txt 2014-05-20 19:21 - 2014-05-20 19:21 - 00000000 ____D () C:\Users\Libelle\Desktop\FRST-OlderVersion 2014-05-20 19:21 - 2014-05-11 18:53 - 00000000 ____D () C:\FRST 2014-05-20 19:21 - 2014-05-11 18:50 - 02067456 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe 2014-05-20 19:13 - 2014-05-20 19:13 - 00854367 _____ () C:\Users\Libelle\Desktop\SecurityCheck.exe 2014-05-20 19:11 - 2013-03-04 22:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-20 19:01 - 2014-05-13 11:24 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-20 18:28 - 2014-05-04 23:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-20 15:45 - 2012-04-18 22:45 - 01420435 _____ () C:\Windows\WindowsUpdate.log 2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Downloads\esetsmartinstaller_deu(1).exe 2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Desktop\esetsmartinstaller_deu.exe 2014-05-20 15:36 - 2011-04-12 09:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat 2014-05-20 15:36 - 2011-04-12 09:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat 2014-05-20 15:36 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-20 15:28 - 2014-05-20 15:28 - 00000000 ____D () C:\Users\Libelle\Desktop\Alte Firefox-Daten 2014-05-20 13:06 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-20 13:06 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-20 12:59 - 2013-03-04 22:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-20 12:59 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-20 12:59 - 2009-07-14 06:51 - 00164725 _____ () C:\Windows\setupact.log 2014-05-20 01:38 - 2012-04-22 14:10 - 00000000 ____D () C:\Users\Libelle\Desktop\Lydia 2014-05-19 20:36 - 2012-09-08 14:45 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Skype 2014-05-18 11:28 - 2012-05-03 11:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-17 15:30 - 2012-04-19 11:46 - 00000000 ____D () C:\Users\Libelle\Desktop\Utilities 2014-05-17 15:06 - 2014-05-17 15:06 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-05-17 15:06 - 2014-05-17 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-17 13:34 - 2014-05-17 13:34 - 00000729 _____ () C:\Users\Libelle\Desktop\Revo Uninstaller.lnk 2014-05-17 13:33 - 2014-05-17 13:33 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Libelle\Desktop\revosetup95.exe 2014-05-17 13:20 - 2014-05-17 13:20 - 00120822 _____ () C:\Users\Libelle\Desktop\bookmarks-2014-05-17.json 2014-05-17 13:16 - 2014-05-17 13:16 - 00000676 _____ () C:\Users\Libelle\Desktop\Youtube.lnk 2014-05-17 13:14 - 2012-06-24 16:12 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\vlc 2014-05-16 10:56 - 2013-06-13 16:03 - 00000000 ____D () C:\Windows\rescache 2014-05-15 14:22 - 2014-03-22 22:35 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-05-15 14:22 - 2012-04-19 14:20 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-05-15 14:22 - 2012-04-19 14:20 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-05-15 14:19 - 2012-04-18 16:36 - 00000000 ___RD () C:\Users\Libelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-15 14:19 - 2012-04-18 16:36 - 00000000 ___RD () C:\Users\Libelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-15 14:18 - 2014-04-30 10:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 05:43 - 2012-05-28 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 05:41 - 2013-07-25 11:06 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 05:40 - 2012-04-19 13:54 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 19:28 - 2014-05-04 23:32 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 19:28 - 2014-05-04 23:32 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-14 19:28 - 2014-05-04 23:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-13 11:49 - 2014-05-13 11:49 - 00000000 ____D () C:\Windows\ERUNT 2014-05-13 11:48 - 2014-05-13 11:48 - 01016261 _____ (Thisisu) C:\Users\Libelle\Desktop\JRT.exe 2014-05-13 11:45 - 2010-11-21 05:47 - 00907418 _____ () C:\Windows\PFRO.log 2014-05-13 11:44 - 2014-05-13 11:37 - 00000000 ____D () C:\AdwCleaner 2014-05-13 11:36 - 2014-05-13 11:36 - 01325827 _____ () C:\Users\Libelle\Desktop\adwcleaner.exe 2014-05-13 11:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-05-13 11:24 - 2014-05-13 11:24 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-12 11:13 - 2014-05-12 11:13 - 00024191 _____ () C:\ComboFix.txt 2014-05-12 11:13 - 2014-05-12 11:04 - 00000000 ____D () C:\Qoobox 2014-05-12 11:11 - 2014-05-12 11:04 - 00000000 ____D () C:\Windows\erdnt 2014-05-12 11:11 - 2012-05-12 21:03 - 00000000 ____D () C:\Users\Libelle\AppData\Local\CrashDumps 2014-05-12 11:11 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-12 11:03 - 2014-05-12 11:02 - 05200347 ____R (Swearware) C:\Users\Libelle\Desktop\ComboFix.exe 2014-05-11 19:14 - 2014-05-11 19:14 - 00380416 _____ () C:\Users\Libelle\Desktop\Gmer-19357.exe 2014-05-11 19:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-11 19:02 - 2014-05-11 19:02 - 00380416 _____ () C:\Users\Libelle\Downloads\Gmer-19357.exe 2014-05-11 18:38 - 2014-05-11 18:51 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe 2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable 2014-05-11 18:38 - 2012-04-18 16:36 - 00000000 ____D () C:\Users\Libelle 2014-05-11 18:20 - 2012-07-17 22:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-05-09 11:06 - 2013-03-04 22:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 11:06 - 2013-03-04 22:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-09 08:14 - 2014-05-15 04:55 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-15 04:55 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList 2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList 2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-05-07 18:25 - 2014-05-07 18:24 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-05-06 06:40 - 2014-05-15 05:42 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 05:42 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 05:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 05:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-04 23:32 - 2012-04-19 11:29 - 00000000 ____D () C:\Downloads Programme 2014-05-04 23:32 - 2012-04-18 18:46 - 00000000 ____D () C:\Users\Libelle\AppData\Local\Adobe 2014-05-04 23:30 - 2012-04-18 18:26 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-04-30 08:59 - 2014-04-29 23:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-04-26 17:51 - 2013-03-21 15:18 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-04-26 17:51 - 2013-03-21 15:18 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-04-26 17:51 - 2012-04-19 14:20 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400156538465 2014-04-26 17:51 - 2012-04-19 14:20 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400156538465 2014-04-26 17:51 - 2012-04-19 14:20 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-04-26 17:51 - 2012-04-19 14:20 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-04-26 17:51 - 2012-04-19 14:20 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-04-26 09:51 - 2014-04-22 11:30 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk 2014-04-26 09:51 - 2014-04-22 11:30 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk 2014-04-26 09:51 - 2014-04-22 11:30 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk 2014-04-26 09:48 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-22 17:40 - 2009-07-14 06:45 - 00399824 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-22 13:59 - 2012-04-18 23:36 - 00101920 _____ () C:\Users\Libelle\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex 2014-04-22 11:32 - 2012-04-18 18:26 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Adobe 2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-04-22 11:31 - 2012-04-18 18:26 - 00000000 ____D () C:\ProgramData\Adobe 2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk 2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24 2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2014-04-20 01:57 - 2013-12-18 00:20 - 00000000 ____D () C:\Users\Libelle\Desktop\jin shin Files to move or delete: ==================== C:\ProgramData\ezsid.dat Some content of TEMP: ==================== C:\Users\Libelle\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe [2014-05-15 04:55] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-19 19:16 ==================== End Of Log ============================ Was sagen dir denn die Ergebnisse? Wie gesagt, ich kann das ja alles nicht deuten... Ich probiere jetzt mal 2-3 Tage, dann würde ich dir wieder Bescheid geben, wie Firefox läuft (außer wir müssen vorher noch etwas reparieren aufgrund der Logs) Dankeschön!! Geändert von jvc (20.05.2014 um 18:23 Uhr) |
Themen zu Firefox stürzt ständig ab |
absturz, adobe flashplayer, antivirus, association, bildschirm, blockiert, browser, dvdvideosoft ltd., excel, firefox, flash player, google, helper, home, homepage, hängt, iexplore.exe, mp3, object, problem, programm, registry, safer networking, security, software, super, svchost.exe, system, trojaner, virus |