|
Plagegeister aller Art und deren Bekämpfung: Bei nutzung von mozila firefox cpu nutzung bei 100 prozentWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.12.2014, 15:36 | #1 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Hallo zusammen habe seit einiger zeit das problem das sobald ich firefox nutze die cpu nutzung auf 100% steigt und dann der stream den ich schaue zu ruckeln anfängt habe mich jetzt bissal durch google geforstet und komme nun selber nicht mehr weiter habe nun die frage was kann ich machen habe mit avira gescannt und dort wurde nichts gefunden dann hatte ich hitze im verdacht und meinen lüfter ausgetauscht gegen neues orginalersatzteil der alte hat schon gefpiffen und gerattert habe dabei auch den laptop gereinigt ist jetzt laufruhig und auch nicht mehr heiß wie es vor dem austausch der fall war würde gerne bissal tiefer in die materie eintauchen nur ohne hilfe schaffe ich das nicht |
12.12.2014, 16:02 | #2 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozent hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
12.12.2014, 16:46 | #3 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozent FRST Logfile:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2014 02 Ran by Martin (administrator) on MARTIN-PC on 12-12-2014 16:36:04 Running from C:\Users\Martin\Contacts\Saved Games\Downloads Loaded Profile: Martin (Available profiles: Martin) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files\ATK Hotkey\AsLdrSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATK Hotkey\MsgTranAgt.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\WDC.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avrestart.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ATKOSD2\ATKOSD2.exe [7737344 2007-10-17] () HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [61440 2006-11-02] (ASUSTeK Computer INC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [Kivyokmiho] => C:\Users\Martin\AppData\Roaming\Invoug\guuxo.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [Facebook Update] => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-18] (Facebook Inc.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [Steam] => C:\Program Files\Steam\Steam.exe [1939136 2014-08-28] (Valve Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [icq] => C:\Users\Martin\AppData\Roaming\ICQM\icq.exe [27453288 2013-03-16] (ICQ) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [18643560 2013-03-01] (Skype Technologies S.A.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\RunOnce: [Adobe Speed Launcher] => 1418398166 HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {8d4c6d88-0c9f-11e3-81d0-0022157f4732} - I:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {8d4c6eb1-0c9f-11e3-81d0-0022157f4732} - I:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {8d4c6eb6-0c9f-11e3-81d0-9a3f56b75943} - I:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {8d4c6ecb-0c9f-11e3-81d0-0022157f4732} - I:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {8d4c6ef2-0c9f-11e3-81d0-daa12eed0b62} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {c1d67011-59d6-11e3-b02c-0022157f4732} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {cd427987-be0c-11e1-a9d1-806e6f6e6963} - F:\Startme.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {cfdefb4b-9c9c-11e2-be21-0022157f4732} - D:\Install.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {e797246c-372c-11e4-a03e-0022157f4732} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {f41fade9-f4c4-11e2-8687-001f3c8db1bf} - F:\autorun.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {f41fae0c-f4c4-11e2-8687-001f3c8db1bf} - G:\Setup.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {f41fae0d-f4c4-11e2-8687-001f3c8db1bf} - H:\Autorun.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {fabfb8dd-df33-11e1-8e70-0022157f4732} - D:\Autorun.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {ff677c85-ddf2-11e2-a80f-0022157f4732} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\MountPoints2: {ff677c98-ddf2-11e2-a80f-0022157f4732} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\n. ATTENTION! ====> ZeroAccess/Alureon? ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=aee3b156000000000000001f3c8db1bf HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com URLSearchHook: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 - (No Name) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> DefaultScope {EFF4AAD8-D55A-4E31-B1AA-8CE22B0F46A8} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=aee3b156000000000000001f3c8db1bf&r=927 SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r= SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {90049ED9-794E-49AB-9C42-9005C1F541F6} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=743C5D59-419F-46E3-BA87-8412229DAA66&apn_sauid=BD0E4797-C0E1-4DB8-8069-82BCD874AA05 SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {EE001F72-E820-4CF1-AB08-134A51CCC6AC} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2851647 SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {EFF4AAD8-D55A-4E31-B1AA-8CE22B0F46A8} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=aee3b156000000000000001f3c8db1bf&r=927 SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Softonic Helper Object -> {E87806B5-E908-45FD-AF5E-957D83E58E68} -> C:\Program Files\Softonic\Softonic\1.8.21.14\bh\Softonic.dll (Softonic.com) Toolbar: HKLM - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll (Softonic.com) Toolbar: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> No Name - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation) Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation) Winsock: Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog5 06 C:\Windows\system32\winrnr.dll [19968] (Microsoft Corporation) Winsock: Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 25 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 26 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 27 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 28 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 29 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 30 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1948944073-1962714127-1447560850-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF user.js: detected! => C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\BrowserProtect.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\softonic.xml FF Extension: Avira Browser Safety - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\abs@avira.com [2014-10-21] FF Extension: DownloadHelper - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-05-23] FF Extension: Green Fox - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{d122ad80-ff45-11dd-87af-0800200c9a66} [2013-10-21] FF Extension: 1-Click YouTube Video Downloader - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-05-24] FF Extension: In The Dark - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{86FA6F53-95FE-7A69-D8C3-E1454281F8B6}.xpi [2013-10-21] FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-08-06] FF Extension: BlockSite - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}.xpi [2012-09-27] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-10-16] FF HKLM\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF Extension: Java Link Helper - C:\Users\Martin\AppData\Roaming\14001.012 [2012-08-09] FF HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF Extension: No Name - {9A207F60-3F1C-4ED0-972D-0A4CDFBFF803} [Not Found] FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found] Chrome: ======= CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Softonic Chrome Toolbar) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-11-29] CHR Extension: (No Name) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc [2012-09-04] CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-04-06] CHR HKLM\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files\Softonic\Softonic\1.8.21.14\Softonic.crx [2013-06-11] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path CHR HKLM\...\Chrome\Extension: [leocdeigfnkaojcapikdjcdbedcjmffc] - C:\Users\Martin\AppData\Local\CRE\leocdeigfnkaojcapikdjcdbedcjmffc.crx [2012-08-26] CHR HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Chrome\Extension: [leocdeigfnkaojcapikdjcdbedcjmffc] - C:\Users\Martin\AppData\Local\CRE\leocdeigfnkaojcapikdjcdbedcjmffc.crx [2012-08-26] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) ATTENTION: => Could not perform signature verification. Cryptographic Service is not running. R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-02] () R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] () R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () S2 Update Higher Aurum; "C:\Program Files\Higher Aurum\updateHigherAurum.exe" [X] S2 Util Higher Aurum; "C:\Program Files\Higher Aurum\bin\utilHigherAurum.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-07-25] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-29] (Disc Soft Ltd) S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [49528 2012-07-26] (G Data Software AG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-07-25] () R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-04-12] (Avira GmbH) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 USBAAPL; System32\Drivers\usbaapl.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] S1 {9cfd4b14-8f9d-43c1-9616-4ac755908334}Gt; system32\drivers\{9cfd4b14-8f9d-43c1-9616-4ac755908334}Gt.sys [X] S1 {9cfd4b14-8f9d-43c1-9616-4ac755908334}t; system32\drivers\{9cfd4b14-8f9d-43c1-9616-4ac755908334}t.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-12 16:35 - 2014-12-12 16:36 - 00000000 ____D () C:\FRST 2014-12-12 15:15 - 2014-12-12 15:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-12 15:14 - 2014-12-12 16:27 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-12-12 15:14 - 2014-12-12 15:14 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-12 15:13 - 2014-12-12 15:51 - 00000000 ____D () C:\Users\Martin\Desktop\mbar 2014-12-12 15:13 - 2014-12-12 15:13 - 00079576 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-12 14:32 - 2014-12-12 14:34 - 00000000 ____D () C:\Windows\LastGood.Tmp 2014-12-12 14:15 - 2014-12-12 14:15 - 00001009 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-12-12 14:04 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-12-12 14:03 - 2014-10-10 02:01 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-12-12 14:03 - 2014-10-10 00:22 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-12-12 13:59 - 2014-09-19 01:50 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-12-12 13:58 - 2014-10-24 02:04 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-12-12 13:58 - 2014-10-24 02:03 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-12-12 13:57 - 2014-09-09 07:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-12 13:56 - 2014-08-12 03:25 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-12-12 13:54 - 2014-10-18 02:08 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-12-12 13:54 - 2014-10-03 02:18 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-12-12 13:53 - 2014-09-05 00:27 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-12-12 13:52 - 2014-12-12 13:52 - 00000853 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-12 13:50 - 2014-12-12 13:50 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-12-12 13:50 - 2014-12-12 13:49 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-12-12 13:43 - 2014-10-13 00:34 - 02054656 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-12-12 13:42 - 2014-10-27 20:10 - 12366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-12 13:42 - 2014-10-27 20:05 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-12 13:42 - 2014-10-27 20:02 - 09739776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-12 13:42 - 2014-10-27 19:59 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-12 13:42 - 2014-10-27 19:59 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-12 13:42 - 2014-10-27 19:58 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-12 13:42 - 2014-10-27 19:57 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-12-12 13:42 - 2014-10-27 19:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-12 13:42 - 2014-10-27 19:56 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-12 13:42 - 2014-10-27 19:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-12-12 13:42 - 2014-10-27 19:56 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-12 13:42 - 2014-10-27 19:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-12 13:42 - 2014-10-27 19:56 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-12 13:42 - 2014-10-27 19:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-12 13:42 - 2014-10-27 19:55 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-12 13:42 - 2014-10-27 19:55 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-12 13:42 - 2014-10-27 19:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-12 13:42 - 2014-10-27 19:55 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-12-12 13:42 - 2014-10-27 19:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-12-12 13:42 - 2014-10-27 19:55 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-12-12 13:42 - 2014-10-27 19:54 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-12 13:25 - 2014-12-12 13:25 - 00000939 _____ () C:\Users\Public\Desktop\DivX Converter.lnk 2014-12-12 13:25 - 2014-12-12 13:25 - 00000874 _____ () C:\Users\Public\Desktop\DivX Player.lnk 2014-11-20 17:03 - 2014-12-12 13:25 - 00001442 _____ () C:\Users\Martin\Desktop\DivX Movies.lnk ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-12 16:32 - 2006-11-02 11:33 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-12 16:30 - 2012-04-11 17:38 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype 2014-12-12 16:30 - 2011-10-16 05:43 - 01604666 _____ () C:\Windows\WindowsUpdate.log 2014-12-12 16:29 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Steam 2014-12-12 16:27 - 2011-10-16 15:07 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-12-12 16:26 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-12 16:26 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-12 16:26 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-12 16:24 - 2008-01-21 03:47 - 00526672 _____ () C:\Windows\PFRO.log 2014-12-12 16:24 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-12 16:24 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\L2Schemas 2014-12-12 16:23 - 2013-10-09 12:40 - 00000000 ___RD () C:\Users\Martin\Dropbox 2014-12-12 16:21 - 2012-07-18 11:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-12 16:05 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-12-12 15:45 - 2013-10-09 12:40 - 00000969 _____ () C:\Users\Martin\Desktop\Dropbox.lnk 2014-12-12 15:45 - 2013-10-09 12:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-12-12 15:45 - 2013-10-09 12:31 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Dropbox 2014-12-12 15:21 - 2012-07-18 11:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-12-12 15:21 - 2011-10-15 22:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-12-12 15:05 - 2011-11-16 21:08 - 00000000 ____D () C:\Users\Martin\AppData\Local\Adobe 2014-12-12 14:34 - 2011-10-15 20:54 - 00000000 ____D () C:\Users\Martin 2014-12-12 14:32 - 2012-03-05 05:22 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA.job 2014-12-12 14:32 - 2012-03-05 05:22 - 00001120 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core.job 2014-12-12 14:30 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2014-12-12 14:16 - 2014-10-21 13:58 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 14:15 - 2013-04-12 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 14:15 - 2013-04-12 02:54 - 00000000 ____D () C:\Program Files\Avira 2014-12-12 14:10 - 2006-11-02 13:47 - 00240296 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-12 14:08 - 2012-05-16 10:30 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-12-12 14:07 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-12-12 13:52 - 2014-09-11 21:38 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-12-12 13:52 - 2011-10-15 21:10 - 00000865 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-12 13:50 - 2013-11-04 22:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-12-12 13:50 - 2013-07-17 17:50 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-12 13:49 - 2011-10-15 22:26 - 00000000 ____D () C:\Program Files\Java 2014-12-12 13:31 - 2011-11-16 14:19 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-12-12 13:25 - 2014-11-05 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2014-12-12 13:25 - 2011-11-10 21:56 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-12-12 13:25 - 2011-11-10 21:28 - 00000000 ____D () C:\Program Files\DivX 2014-12-12 13:25 - 2011-11-10 21:27 - 00000000 ____D () C:\ProgramData\DivX 2014-11-26 21:29 - 2011-10-15 21:15 - 00092672 _____ () C:\Users\Martin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-11-26 21:25 - 2012-09-02 14:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\vlc 2014-11-12 15:00 - 2014-03-09 19:17 - 00000000 ____D () C:\Users\Martin\Desktop\Neuer Ordner (4) ZeroAccess: C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22}\n ZeroAccess: C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\@ Files to move or delete: ==================== C:\ProgramData\zak_lo0i7g.pad Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\Temp\APNStub.exe C:\Users\Martin\AppData\Local\Temp\AskSLib.dll C:\Users\Martin\AppData\Local\Temp\AutoRun.exe C:\Users\Martin\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Martin\AppData\Local\Temp\avgnt.exe C:\Users\Martin\AppData\Local\Temp\BingBarSetup-Partner.exe C:\Users\Martin\AppData\Local\Temp\bootstrapper.exe C:\Users\Martin\AppData\Local\Temp\DivXSetup.exe C:\Users\Martin\AppData\Local\Temp\drm_dialogs.dll C:\Users\Martin\AppData\Local\Temp\drm_dyndata_7290008.dll C:\Users\Martin\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpb5grat.dll C:\Users\Martin\AppData\Local\Temp\DTLite4471-0333.exe C:\Users\Martin\AppData\Local\Temp\DTLite4481-0347.exe C:\Users\Martin\AppData\Local\Temp\eauninstall.exe C:\Users\Martin\AppData\Local\Temp\HighAurum_bs.exe C:\Users\Martin\AppData\Local\Temp\InstallFlashPlayer.exe C:\Users\Martin\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe C:\Users\Martin\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe C:\Users\Martin\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe C:\Users\Martin\AppData\Local\Temp\kz55xmis.dll C:\Users\Martin\AppData\Local\Temp\Need For Speed Underground_uninst.exe C:\Users\Martin\AppData\Local\Temp\pyl7389.tmp.exe C:\Users\Martin\AppData\Local\Temp\pyl8352.tmp.exe C:\Users\Martin\AppData\Local\Temp\pylADDB.tmp.exe C:\Users\Martin\AppData\Local\Temp\pylEDE6.tmp.exe C:\Users\Martin\AppData\Local\Temp\pylFB00.tmp.exe C:\Users\Martin\AppData\Local\Temp\RSPUpgradeInstaller.exe C:\Users\Martin\AppData\Local\Temp\SHSetup.exe C:\Users\Martin\AppData\Local\Temp\softonic_ggl_1.6.7.4.exe C:\Users\Martin\AppData\Local\Temp\tbedrs.dll C:\Users\Martin\AppData\Local\Temp\tbuTor.dll C:\Users\Martin\AppData\Local\Temp\ubi7305.tmp.exe C:\Users\Martin\AppData\Local\Temp\utt32A6.tmp.exe C:\Users\Martin\AppData\Local\Temp\vlc-1.1.11-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.0.4-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.0.5-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.0.7-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.0.8-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.1.1-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.1.2-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\Martin\AppData\Local\Temp\vlc-2.1.5-win32.exe C:\Users\Martin\AppData\Local\Temp\_is7757.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-12-12 16:35 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-12-2014 02 Ran by Martin at 2014-12-12 16:38:16 Running from C:\Users\Martin\Contacts\Saved Games\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated) Adobe Reader X (10.1.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated) ANNO 1404 (HKLM\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.00.0000 - Ubisoft) Anno 1404 (Version: 1.00.0000 - Ubisoft) Hidden ASUS LifeFrame3 (HKLM\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.6 - ASUS) ASUS SmartLogon (HKLM\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0004 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM\...\{C0FC1C14-4824-4A73-87A6-9E888C9C3102}) (Version: 1.02.0020 - ASUS) ASUS Virtual Camera (HKLM\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.08 - asus) ATI Catalyst Install Manager (HKLM\...\{C1D783C5-D3ED-D03E-59CE-1FCC0C059B0F}) (Version: 3.0.657.0 - ATI Technologies, Inc.) ATK Generic Function Service (HKLM\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK) ATK Hotkey (HKLM\...\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}) (Version: 1.00.0027 - ATK) ATK Media (HKLM\...\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}) (Version: - ) ATKOSD2 (HKLM\...\{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}) (Version: 6.64.1.6 - ATK) Avira (HKLM\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG) Avira (Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.7.342 - Avira) ccc-Branding (HKLM\...\{6E32B134-CA8D-49DD-B94C-0DB155CE70B5}) (Version: 1.00.0000 - ATI) ccc-core-static (Version: 2007.1220.2143.38732 - Ihr Firmenname) Hidden CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.0.2838 - CDBurnerXP) Command & Conquer 3 (HKLM\...\{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}) (Version: 1.00.0000 - Ihr Firmenname) Counter-Strike: Source (HKLM\...\Steam App 240) (Version: - Valve) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC) Dropbox (HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.) Emergency 4 Deluxe (HKLM\...\{EDA12670-56B5-4459-BA21-D010F0E3EBA1}) (Version: 1.03.001 - ) Facebook Video Calling 3.1.0.521 (HKLM\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) ICQ 8.0 (build 6007, für aktuellen Benutzer) (HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\ICQ) (Version: 8.0.6007.0 - Mail.Ru) IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC) Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle) Java(TM) 6 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Flight (HKLM\...\GFWL_{4D5308D2-DC8E-4658-A37C-351000048100}) (Version: 1.0.0004.129 - Microsoft Studios) Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Motorola SM56 Speakerphone Modem (HKLM\...\SMSERIAL) (Version: 6.12.25.06 - Motorola Inc) Mozilla Firefox 34.0.5 (x86 de) (HKLM\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden Net4Switch (HKLM\...\{9D6D7811-43B3-463C-BC79-5D1755269989}) (Version: 1.00.0015 - ) PokerStars.eu (HKLM\...\PokerStars.eu) (Version: - PokerStars.eu) Power4Gear eXtreme (HKLM\...\{8CFEBE9C-F29F-4C49-80E0-7106970F8734}) (Version: 1.00.0014 - ATK) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5548 - Realtek Semiconductor Corp.) Return to Castle Wolfenstein - Platinum Edition (HKLM\...\Return to Castle Wolfenstein - Platinum Edition) (Version: - ) Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Hidden Skins (Version: 2007.1220.2143.38732 - ATI) Hidden Skype™ 6.3 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.) Softonic toolbar on IE and Chrome (HKLM\...\Softonic) (Version: 1.8.21.14 - Softonic) <==== ATTENTION Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeamViewer 7 (HKLM\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer) Ubuntu (HKLM\...\Wubi) (Version: 11.10-rev241 - Ubuntu) USB 2.0 1.3M UVC WebCam (HKLM\...\USB 2.0 1.3M UVC WebCam) (Version: - ) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden Veetle TV (HKLM\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) Windows Home Server-CD zum Wiederherstellen von Heimcomputern (Dual-Boot-Version) (HKLM\...\{E98E2A33-05D1-476B-B81B-40F4BD957056}) (Version: 1 - Microsoft Corporation) Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) WinFF 1.4.2 (HKLM\...\WinFF_is1) (Version: - WinFF.org) WinRAR 4.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Wolfenstein - Enemy Territory (HKLM\...\Wolfenstein - Enemy Territory) (Version: - ) World of Subways Vol.2 (HKLM\...\{0A902DF4-B767-49DB-98D3-D413E6F1E703}) (Version: 1.00 - TML-Studios) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 -> C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\n. No File CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\Martin\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{CB242D42-1C23-41F7-BC94-3AEB0EC80CAC}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\AcroIEHelpe186.dll No File CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1A1962AF-44F8-453D-80D0-EEE8A722E488} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-12] (Adobe Systems Incorporated) Task: {7F21CFE0-43D1-44AC-8C3B-19A19C1E1BF3} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files\ASUS\SmartLogon\sensorsrv.exe [2007-12-26] (ASUS) Task: {8910A7D7-1D84-44D3-B08E-157DC9E74AA0} - System32\Tasks\{D33F39F9-04FB-4792-8D8C-F8628FE9A1CC} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}\setup.exe" -c -runfromtemp -l0x0007 -removeonly Task: {8D502C71-F56F-492B-B1CC-9F47F7385A99} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-18] (Facebook Inc.) Task: {927EE91E-0D9F-404F-8BFE-92913720E78B} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {956A7F53-E932-44AD-A379-DC61C3879C35} - System32\Tasks\{DCBFFBDF-2D4E-42C1-BA55-1E016CCA5584} => Firefox.exe Skype für den Desktop herunterladen Task: {C87FA0AE-6F21-4F24-AE95-30CD476EE35F} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\system32\FlashPlayerUpdateService.exe Task: {D89C2817-2828-48A9-ADD6-7B37CB03DA6D} - System32\Tasks\{A5B012AF-96E5-428F-B4EE-CFC0621612D5} => pcalua.exe -a C:\ProgramData\036DFF9802D4A6A3DB0579432F3B707C\036DFF9802D4A6A3DB0579432F3B707C.exe -c -u Task: {E25F89C9-A87A-4935-B9CE-FFD61BB82FD7} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\system32\FlashPlayerUpdateService.exe Task: {ED6671A4-529C-419C-B9EB-3DE300C3FC6A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-18] (Facebook Inc.) Task: {F52CC31E-9EE1-4E64-9FC1-67BA0D99933E} - System32\Tasks\{A73FE778-1843-4B2D-BFA4-AA4E15BF1018} => pcalua.exe -a C:\PROGRA~1\RETURN~1\Uninstall\Unwise.exe -c /u C:\PROGRA~1\RETURN~1\Uninstall\Install.log (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core.job => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA.job => C:\Users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-10-15 22:46 - 2007-10-02 20:53 - 00094208 _____ () C:\Program Files\ATK Hotkey\ASLDRSrv.exe 2011-10-15 22:40 - 2007-08-07 23:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe 2012-12-07 17:27 - 2012-12-07 17:27 - 00167424 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe 2007-12-20 21:02 - 2007-12-20 21:02 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll 2011-10-15 22:46 - 2004-05-27 17:13 - 00057344 _____ () C:\Program Files\ATK Hotkey\CMSSC.dll 2011-10-15 22:46 - 2007-11-04 18:48 - 00106496 _____ () C:\Program Files\ATK Hotkey\MsgTranAgt.exe 2011-10-15 23:20 - 2007-07-09 21:48 - 00009216 _____ () C:\Program Files\ASUS\Splendid\GLCDdll.dll 2011-10-15 22:46 - 2007-11-28 16:39 - 02465792 _____ () C:\Program Files\ATK Hotkey\ATKOSD.exe 2011-10-15 22:46 - 2007-08-15 10:38 - 00147456 _____ () C:\Program Files\ATK Hotkey\WDC.exe 2011-10-15 22:44 - 2007-10-17 18:04 - 07737344 _____ () C:\Program Files\ATKOSD2\ATKOSD2.exe 2011-10-15 22:47 - 2006-10-25 14:37 - 00045056 _____ () C:\Program Files\ASUS\ATK Media\GERSTRING.dll 2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2014-12-12 13:52 - 2014-11-26 17:40 - 03758192 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk => C:\Windows\pss\CCC.lnk.Startup MSCONFIG\startupfolder: C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ctfmon.lnk => C:\Windows\pss\ctfmon.lnk.Startup MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: UIExec => "C:\Program Files\Mobile Partner Manager\UIExec.exe" MSCONFIG\startupreg: Windows Mobile-based device management => %windir%\WindowsMobile\wmdSync.exe ========================= Accounts: ========================== Administrator (S-1-5-21-1948944073-1962714127-1447560850-500 - Administrator - Disabled) Gast (S-1-5-21-1948944073-1962714127-1447560850-501 - Limited - Disabled) Martin (S-1-5-21-1948944073-1962714127-1447560850-1000 - Administrator - Enabled) => C:\Users\Martin ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{410054BB-1B4B-41D2-8A4E-2DDE004917B3} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{410054BB-1B4B-41D2-8A4E-2DDE004917B3} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #3 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: isatap.{F2BAE932-770E-45A4-87CD-65877E5C4EC7} Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #10 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Basissystemgerät Description: Basissystemgerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Basissystemgerät Description: Basissystemgerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/12/2014 03:49:51 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {54506326-e8c1-4aa2-9b43-f10c5b63647a} Error: (12/12/2014 01:49:45 PM) (Source: Perflib) (EventID: 1017) (User: ) Description: PolicyAgent Error: (12/12/2014 01:49:45 PM) (Source: Perflib) (EventID: 1005) (User: ) Description: OpenIPSecPerformanceDataC:\Windows\System32\ipsecsvc.dllPolicyAgent4 Error: (12/12/2014 01:49:45 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (12/12/2014 01:49:41 PM) (Source: Perflib) (EventID: 1010) (User: ) Description: EmdCacheC:\Windows\system32\emdmgmt.dll4 Error: (12/12/2014 01:48:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung FlashPlayerPlugin_15_0_0_189.exe, Version 15.0.0.189, Zeitstempel 0x54233581, fehlerhaftes Modul ShimEng.dll_unloaded, Version 0.0.0.0, Zeitstempel 0x4549bdb7, Ausnahmecode 0xc0000005, Fehleroffset 0x63dc4618, Prozess-ID 0x160c, Anwendungsstartzeit FlashPlayerPlugin_15_0_0_189.exe0. Error: (12/12/2014 01:48:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung FlashPlayerPlugin_15_0_0_189.exe, Version 15.0.0.189, Zeitstempel 0x54233581, fehlerhaftes Modul ShimEng.dll_unloaded, Version 0.0.0.0, Zeitstempel 0x4549bdb7, Ausnahmecode 0xc0000005, Fehleroffset 0x63dc4618, Prozess-ID 0x15e8, Anwendungsstartzeit FlashPlayerPlugin_15_0_0_189.exe0. Error: (12/12/2014 01:47:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung FlashPlayerPlugin_15_0_0_189.exe, Version 15.0.0.189, Zeitstempel 0x54233581, fehlerhaftes Modul ShimEng.dll_unloaded, Version 0.0.0.0, Zeitstempel 0x4549bdb7, Ausnahmecode 0xc0000005, Fehleroffset 0x63dc4618, Prozess-ID 0x9dc, Anwendungsstartzeit FlashPlayerPlugin_15_0_0_189.exe0. Error: (12/12/2014 01:47:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Fehlerhafte Anwendung FlashPlayerPlugin_15_0_0_189.exe, Version 15.0.0.189, Zeitstempel 0x54233581, fehlerhaftes Modul ShimEng.dll_unloaded, Version 0.0.0.0, Zeitstempel 0x4549bdb7, Ausnahmecode 0xc0000005, Fehleroffset 0x63dc4618, Prozess-ID 0x540, Anwendungsstartzeit FlashPlayerPlugin_15_0_0_189.exe0. Error: (12/12/2014 01:44:25 PM) (Source: VSS) (EventID: 12289) (User: ) Description: Volumeschattenkopie-Dienstfehler: Unerwarteter Fehler "CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3,0xc0000000,0x00000003,...)". hr = 0x80070037. Vorgang: PostFinalCommitSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider System errors: ============= Error: (12/12/2014 04:35:38 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (12/12/2014 04:28:22 PM) (Source: WMPNetworkSvc) (EventID: 14344) (User: ) Description: 0xc00d2711 Error: (12/12/2014 04:28:22 PM) (Source: WMPNetworkSvc) (EventID: 14344) (User: ) Description: 0xc00d2711 Error: (12/12/2014 04:27:51 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (12/12/2014 04:27:09 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: {9cfd4b14-8f9d-43c1-9616-4ac755908334}Gt {9cfd4b14-8f9d-43c1-9616-4ac755908334}t Error: (12/12/2014 04:26:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Util Higher Aurum%%3 Error: (12/12/2014 04:26:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Update Higher Aurum%%3 Error: (12/12/2014 03:53:57 PM) (Source: volsnap) (EventID: 14) (User: ) Description: Die Schattenkopien von Volume "C:" wurden aufgrund eines E/A-Fehlers auf Volume "C:" abgebrochen. Error: (12/12/2014 03:53:31 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden. Error: (12/12/2014 03:53:31 PM) (Source: atapi) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Ide\IdePort2 gefunden. Microsoft Office Sessions: ========================= Error: (12/12/2014 03:49:51 PM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {54506326-e8c1-4aa2-9b43-f10c5b63647a} Error: (12/12/2014 01:49:45 PM) (Source: Perflib) (EventID: 1017) (User: ) Description: PolicyAgent Error: (12/12/2014 01:49:45 PM) (Source: Perflib) (EventID: 1005) (User: ) Description: OpenIPSecPerformanceDataC:\Windows\System32\ipsecsvc.dllPolicyAgent4 Error: (12/12/2014 01:49:45 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (12/12/2014 01:49:41 PM) (Source: Perflib) (EventID: 1010) (User: ) Description: EmdCacheC:\Windows\system32\emdmgmt.dll4 Error: (12/12/2014 01:48:52 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581ShimEng.dll_unloaded0.0.0.04549bdb7c000000563dc4618160c01d01609fb187850 Error: (12/12/2014 01:48:26 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581ShimEng.dll_unloaded0.0.0.04549bdb7c000000563dc461815e801d01609eb9c63a0 Error: (12/12/2014 01:47:55 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581ShimEng.dll_unloaded0.0.0.04549bdb7c000000563dc46189dc01d01609d97c7f20 Error: (12/12/2014 01:47:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: FlashPlayerPlugin_15_0_0_189.exe15.0.0.18954233581ShimEng.dll_unloaded0.0.0.04549bdb7c000000563dc461854001d01609d3139100 Error: (12/12/2014 01:44:25 PM) (Source: VSS) (EventID: 12289) (User: ) Description: CreateFileW(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3,0xc0000000,0x00000003,...)0x80070037 Vorgang: PostFinalCommitSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider CodeIntegrity Errors: =================================== Date: 2012-05-24 18:00:15.370 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-05-24 18:00:15.215 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-20 21:27:47.386 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-20 21:27:47.272 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-20 21:26:18.007 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-20 21:26:17.890 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-20 21:24:59.919 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-20 21:24:59.799 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-10 20:17:44.912 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-11-10 20:17:44.791 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\atiumdag.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz Percentage of memory in use: 42% Total physical RAM: 3070.48 MB Available physical RAM: 1779.15 MB Total Pagefile: 6349.2 MB Available Pagefile: 4868.65 MB Total Virtual: 2047.88 MB Available Virtual: 1907.08 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:465.76 GB) (Free:181.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (LRMCFRE_DE_DVD) (CDROM) (Total:0.14 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 67B917F8) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
13.12.2014, 15:31 | #4 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.12.2014, 16:25 | #5 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozentCode:
ATTFilter ComboFix 14-12-10.03 - Martin 13.12.2014 15:54:37.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1613 [GMT 1:00] ausgeführt von:: c:\users\Martin\Contacts\Saved Games\Downloads\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Enabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\zak_lo0i7g.pad c:\users\Martin\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\users\Martin\AppData\Roaming\14001.004 c:\users\Martin\AppData\Roaming\14001.004\chrome.manifest c:\users\Martin\AppData\Roaming\14001.004\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.004\install.rdf c:\users\Martin\AppData\Roaming\14001.005 c:\users\Martin\AppData\Roaming\14001.005\chrome.manifest c:\users\Martin\AppData\Roaming\14001.005\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.005\install.rdf c:\users\Martin\AppData\Roaming\14001.007 c:\users\Martin\AppData\Roaming\14001.007\chrome.manifest c:\users\Martin\AppData\Roaming\14001.007\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.007\install.rdf c:\users\Martin\AppData\Roaming\14001.008 c:\users\Martin\AppData\Roaming\14001.008\chrome.manifest c:\users\Martin\AppData\Roaming\14001.008\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.008\install.rdf c:\users\Martin\AppData\Roaming\14001.009 c:\users\Martin\AppData\Roaming\14001.009\chrome.manifest c:\users\Martin\AppData\Roaming\14001.009\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.009\install.rdf c:\users\Martin\AppData\Roaming\14001.010 c:\users\Martin\AppData\Roaming\14001.010\chrome.manifest c:\users\Martin\AppData\Roaming\14001.010\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.010\install.rdf c:\users\Martin\AppData\Roaming\14001.011 c:\users\Martin\AppData\Roaming\14001.011\chrome.manifest c:\users\Martin\AppData\Roaming\14001.011\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.011\install.rdf c:\users\Martin\AppData\Roaming\14001.012 c:\users\Martin\AppData\Roaming\14001.012\chrome.manifest c:\users\Martin\AppData\Roaming\14001.012\components\AcroFF.txt c:\users\Martin\AppData\Roaming\14001.012\install.rdf c:\users\Martin\AppData\Roaming\Rywyt c:\users\Martin\AppData\Roaming\Rywyt\ilozz.okb c:\users\Martin\AppData\Roaming\srvblck5.tmp c:\windows\msdownld.tmp c:\windows\msvcr71.dll c:\windows\system32\ c:\windows\system32\drivers\etc\hosts.ics . . ((((((((((((((((((((((( Dateien erstellt von 2014-11-13 bis 2014-12-13 )))))))))))))))))))))))))))))) . . 2014-12-13 14:42 . 2014-12-13 14:42 -------- d-----w- c:\program files\VS Revo Group 2014-12-12 15:59 . 2014-12-12 15:59 -------- d-----w- c:\program files\GPU-Z 2014-12-12 15:35 . 2014-12-12 15:44 -------- d-----w- C:\FRST 2014-12-12 14:15 . 2014-12-12 14:15 -------- d-----w- c:\programdata\Malwarebytes 2014-12-12 14:14 . 2014-12-12 19:44 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2014-12-12 14:14 . 2014-12-12 14:14 119000 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-12-12 14:13 . 2014-12-12 14:13 79576 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-12-12 13:04 . 2014-06-15 22:18 1131664 ----a-w- c:\windows\system32\dfshim.dll 2014-12-12 13:04 . 2014-06-13 18:22 81560 ----a-w- c:\windows\system32\mscories.dll 2014-12-12 13:04 . 2014-06-13 18:22 156824 ----a-w- c:\windows\system32\mscorier.dll 2014-12-12 13:03 . 2014-10-10 01:00 146432 ----a-w- c:\windows\system32\msaudite.dll 2014-12-12 13:03 . 2014-10-09 23:22 619520 ----a-w- c:\windows\system32\adtschema.dll 2014-12-12 13:03 . 2014-10-10 01:01 449536 ----a-w- c:\windows\system32\termsrv.dll 2014-12-12 13:03 . 2014-10-10 01:00 1259008 ----a-w- c:\windows\system32\lsasrv.dll 2014-12-12 13:00 . 2014-08-27 00:55 2048 ----a-w- c:\windows\system32\msxml3r.dll 2014-12-12 13:00 . 2014-08-27 00:55 1249280 ----a-w- c:\windows\system32\msxml3.dll 2014-12-12 12:59 . 2014-09-19 00:50 278528 ----a-w- c:\windows\system32\schannel.dll 2014-12-12 12:58 . 2014-10-24 01:03 499200 ----a-w- c:\windows\system32\kerberos.dll 2014-12-12 12:58 . 2014-10-24 01:04 67072 ----a-w- c:\windows\system32\packager.dll 2014-12-12 12:57 . 2014-09-09 06:24 2048 ----a-w- c:\windows\system32\tzres.dll 2014-12-12 12:56 . 2014-08-12 02:25 729600 ----a-w- c:\windows\system32\IMJP10K.DLL 2014-12-12 12:54 . 2014-10-03 01:18 274432 ----a-w- c:\windows\system32\AUDIOKSE.dll 2014-12-12 12:54 . 2014-10-03 01:17 170496 ----a-w- c:\windows\system32\EncDump.dll 2014-12-12 12:54 . 2014-10-03 01:17 396800 ----a-w- c:\windows\system32\AudioEng.dll 2014-12-12 12:54 . 2014-10-03 01:17 316928 ----a-w- c:\windows\system32\audiosrv.dll 2014-12-12 12:54 . 2014-10-18 01:08 564224 ----a-w- c:\windows\system32\oleaut32.dll 2014-12-12 12:53 . 2014-09-04 23:27 143360 ----a-w- c:\windows\system32\drivers\fastfat.sys 2014-12-12 12:50 . 2014-12-12 12:50 -------- d-----w- c:\program files\Common Files\Java 2014-12-12 12:49 . 2014-12-12 12:49 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2014-12-12 12:43 . 2014-10-12 23:34 2054656 ----a-w- c:\windows\system32\win32k.sys 2014-12-03 18:06 . 2014-12-03 18:06 188304 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-12-13 15:13 . 2011-10-16 14:07 45056 ----a-w- c:\windows\system32\acovcnt.exe 2014-12-12 14:21 . 2012-07-18 10:38 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-12-12 14:21 . 2011-10-15 21:24 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-11-06 05:42 . 2014-11-06 05:42 341848 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl 2014-10-21 12:49 . 2013-04-12 01:54 98160 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-10-21 12:49 . 2013-04-12 01:54 136216 ----a-w- c:\windows\system32\drivers\avipbb.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"] @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"] @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"] @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"] @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 131480 ----a-w- c:\users\Martin\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "Steam"="c:\program files\Steam\Steam.exe" [2014-11-18 1940160] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "icq"="c:\users\Martin\AppData\Roaming\ICQM\icq.exe" [2013-03-16 27453288] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-03-01 18643560] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Adobe Speed Launcher"="1418483672" [X] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-10-17 7737344] "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-11-20 1021128] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1458176] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 4874240] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552] "DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2014-11-17 448856] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2014-12-12 703736] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2014-01-10 1861968] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-09-26 271744] "Avira Systray"="c:\program files\Avira\My Avira\Avira.OE.Systray.exe" [2014-11-20 126200] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKLM\~\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk] path=c:\users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk backup=c:\windows\pss\CCC.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^Martin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ctfmon.lnk] path=c:\users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk backup=c:\windows\pss\ctfmon.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC] 2006-11-10 10:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2014-09-26 17:19 271744 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management] 2008-01-21 02:23 215552 ----a-w- c:\windows\WindowsMobile\wmdSync.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr . Inhalt des "geplante Tasks" Ordners . 2014-12-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09 14:21] . 2014-12-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core.job - c:\users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-05 12:27] . 2014-12-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA.job - c:\users\Martin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-03-05 12:27] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=aee3b156000000000000001f3c8db1bf mStart Page = about:blank IE: {{07BA1DA9-F501-4796-8728-74D1B91A6CD5} - c:\program files\PokerStars.EU\PokerStarsUpdate.exe TCP: DhcpNameServer = 192.168.2.1 192.168.2.1 FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - ExtSQL: !HIDDEN! 2012-07-27 18:31; {9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}; c:\users\Martin\AppData\Roaming\14001.012 FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false FF - user.js: extensions.Softonic.rvrtMsg - Click Yes to keep current home page and default search settings, Click No to restore original settings FF - user.js: extensions.Softonic_i.hmpg - true FF - user.js: extensions.Softonic.hpOld - hxxp://google.de/ FF - user.js: extensions.Softonic.hpNew - hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=13&cc= FF - user.js: extensions.Softonic.keyWordUrl - hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q= FF - user.js: extensions.Softonic.dspOld - FF - user.js: extensions.Softonic.dspNew - Search the web (Softonic) FF - user.js: extensions.Softonic_i.dnsErr - true FF - user.js: extensions.Softonic_i.newTab - true FF - user.js: extensions.Softonic_i.vrsnTs - 1.6.7.412:24 FF - user.js: extensions.Softonic_i.smplGrp - none FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - aee3b156000000000000001f3c8db1bf FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15800 FF - user.js: extensions.delta.vrsn - 1.8.10.0 FF - user.js: extensions.delta.vrsni - 1.8.10.0 FF - user.js: extensions.delta.vrsnTs - 1.8.10.015:14 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - babsst FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - en FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=aee3b156000000000000001f3c8db1bf&q= FF - user.js: extensions.Softonic.id - aee3b156000000000000001f3c8db1bf FF - user.js: extensions.Softonic.appId - {7ABBFE1C-E485-44AA-8F36-353751B4124D} FF - user.js: extensions.Softonic.instlDay - 16038 FF - user.js: extensions.Softonic.vrsn - 1.8.21.14 FF - user.js: extensions.Softonic.vrsni - 1.8.21.14 FF - user.js: extensions.Softonic.vrsnTs - 1.8.21.1415:38 FF - user.js: extensions.Softonic.prtnrId - softonic FF - user.js: extensions.Softonic.prdct - Softonic FF - user.js: extensions.Softonic.aflt - OC FF - user.js: extensions.Softonic.smplGrp - none FF - user.js: extensions.Softonic.tlbrId - opencandy2013 FF - user.js: extensions.Softonic.instlRef - MOY00621 FF - user.js: extensions.Softonic.dfltLng - de FF - user.js: extensions.Softonic.excTlbr - false FF - user.js: extensions.Softonic.ffxUnstlRst - false FF - user.js: extensions.Softonic.admin - false FF - user.js: extensions.Softonic.autoRvrt - false FF - user.js: extensions.Softonic.rvrt - false FF - user.js: extensions.Softonic.hmpg - true FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=aee3b156000000000000001f3c8db1bf FF - user.js: extensions.Softonic.dfltSrch - true FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic) FF - user.js: extensions.Softonic.dnsErr - true FF - user.js: extensions.Softonic.newTab - true FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=aee3b156000000000000001f3c8db1bf . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - (no file) WebBrowser-{C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - (no file) HKCU-Run-Kivyokmiho - c:\users\Martin\AppData\Roaming\Invoug\guuxo.exe SafeBoot-WudfPf SafeBoot-WudfRd MSConfigStartUp-UIExec - c:\program files\Mobile Partner Manager\UIExec.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-12-13 16:14 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1948944073-1962714127-1447560850-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:df,1b,ab,34,4f,b8,8b,21,e5,24,36,ac,c2,91,15,1d,1a,32,a2,10,34,c8,54, 5a,65,f4,f1,ac,9b,cb,00,4a,62,8e,cb,e3,7d,2d,31,53,53,ab,4b,62,04,c7,f2,dc,\ "??"=hex:49,e4,72,97,ed,0e,f2,60,f7,00,2f,b3,1f,5e,cb,f8 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\ATK Hotkey\ASLDRSrv.exe c:\program files\ATKGFNEX\GFNEXSrv.exe c:\program files\Avira\AntiVir Desktop\sched.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe c:\program files\TeamViewer\Version7\TeamViewer_Service.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Avira\My Avira\Avira.OE.ServiceHost.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\ASUS\SmartLogon\sensorsrv.exe c:\windows\system32\conime.exe c:\program files\ATK Hotkey\Hcontrol.exe c:\program files\ATK Hotkey\MsgTranAgt.exe c:\program files\ASUS\Splendid\ACMON.exe c:\program files\P4G\BatteryLife.exe c:\windows\System32\ACEngSvr.exe c:\program files\ATK Hotkey\ATKOSD.exe c:\program files\ATK Hotkey\WDC.exe c:\windows\RtHDVCpl.exe c:\windows\ehome\ehmsas.exe c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-12-13 16:21:03 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-12-13 15:20 . Vor Suchlauf: 14 Verzeichnis(se), 192.011.239.424 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 200.771.719.168 Bytes frei . - - End Of File - - FD5291819EE731EFF80B3658FD419155 5C616939100B85E558DA92B899A0FC36 |
14.12.2014, 11:28 | #6 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Bei nutzung von mozila firefox cpu nutzung bei 100 prozent |
14.12.2014, 14:06 | #7 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozentCode:
ATTFilter <?xml version="1.0" encoding="UTF-16"?> -<mbam-log> -<header> <date>2014/12/14 13:08:27 +0100</date> <logfile>mbam-log-2014-12-14 (13-08-26).xml</logfile> <isadmin>yes</isadmin> </header> -<engine> <version>2.00.4.1028</version> <malware-database>v2014.12.14.04</malware-database> <rootkit-database>v2014.12.08.03</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> -<system> <osversion>Windows Vista Service Pack 2</osversion> <arch>x86</arch> <username>Martin</username> <filesys>NTFS</filesys> </system> -<summary> <type>threat</type> <result>completed</result> <objects>303957</objects> <time>969</time> <processes>0</processes> <modules>0</modules> <keys>0</keys> <values>0</values> <datas>0</datas> <folders>0</folders> <files>0</files> <sectors>0</sectors> </summary> -<options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> </items> </mbam-log> Code:
ATTFilter # AdwCleaner v4.105 - Bericht erstellt am 14/12/2014 um 13:44:06 # Aktualisiert 08/12/2014 von Xplode # Database : 2014-12-13.4 [Live] # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Martin - MARTIN-PC # Gestartet von : C:\Users\Martin\Contacts\Saved Games\Downloads\AdwCleaner_4.105.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\Askcom.xml Datei Gefunden : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\user.js Ordner Gefunden : C:\Program Files\Conduit Ordner Gefunden : C:\ProgramData\Ask Ordner Gefunden : C:\ProgramData\Babylon Ordner Gefunden : C:\Users\Martin\AppData\Local\Conduit Ordner Gefunden : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf Ordner Gefunden : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc Ordner Gefunden : C:\Users\Martin\AppData\LocalLow\Conduit Ordner Gefunden : C:\Users\Martin\AppData\LocalLow\PriceGong Ordner Gefunden : C:\Users\Martin\AppData\LocalLow\Softonic Ordner Gefunden : C:\Users\Martin\AppData\Roaming\Babylon ***** [ Tasks ] ***** Task Gefunden : BrowserProtect ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\a538bdae63de947 Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Smartbar Schlüssel Gefunden : HKCU\Software\Conduit Schlüssel Gefunden : HKCU\Software\Delta Schlüssel Gefunden : HKCU\Software\filescout Schlüssel Gefunden : HKCU\Software\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{90049ED9-794E-49AB-9C42-9005C1F541F6} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EE001F72-E820-4CF1-AB08-134A51CCC6AC} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EFF4AAD8-D55A-4E31-B1AA-8CE22B0F46A8} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic Schlüssel Gefunden : HKCU\Software\OCS Schlüssel Gefunden : HKCU\Software\systweak Schlüssel Gefunden : HKLM\SOFTWARE\a538bdae63de947 Schlüssel Gefunden : HKLM\SOFTWARE\Babylon Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2851647 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gefunden : HKLM\SOFTWARE\Conduit Schlüssel Gefunden : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gefunden : HKLM\SOFTWARE\Solvusoft Schlüssel Gefunden : HKLM\SOFTWARE\Uniblue ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16599 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=10&cc=&mi=aee3b156000000000000001f3c8db1bf -\\ Mozilla Firefox v34.0.5 (x86 de) [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.1000234.TWC_TMP_city", "MUENCHEN"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.1000234.TWC_TMP_country", "DE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.FirstTime", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.FirstTimeFF3", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.UserID", "UN55348821975465960"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.addressBarTakeOverEnabledInHidden", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.autoDisableScopes", -1); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.cbcountry_001", "DE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.cbfirsttime", "Tue Sep 04 2012 12:18:57 GMT+0200"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.defaultSearch", "FALSE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.embeddedsData", "[{\"appId\":\"129351532245275780\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...] [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.enableAlerts", "always"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.enableSearchFromAddressBar", "FALSE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.firstTimeDialogOpened", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.fixPageNotFoundError", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.fixPageNotFoundErrorInHidden", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.fixUrls", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.installId", "fft7D6A.tmp.exe"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.installType", "XPE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.isNewTabEnabled", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.isPerformedSmartBarTransition", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Anewtab\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://uTorrentBarDE.OurToolbar[...] [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.openThankYouPage", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.openUninstallPage", "FALSE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.scriptSource", "hxxp://127.0.0.1:10000/gui/"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.search.searchAppId", "129351532245275780"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.search.searchCount", "0"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.searchInNewTabEnabledInHidden", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"3\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2851647\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentBarDE.OurToolbar.com//xpi\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentBar_DE\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"1\"}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1346753932234"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_appsMetadata_lastUpdate", "1346753931819"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1346753933596"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_login_10.10.27.6_lastUpdate", "1346768334105"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1346753933738"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_searchAPI_lastUpdate", "1346753931133"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_serviceMap_lastUpdate", "1346763930917"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_toolbarContextMenu_lastUpdate", "1346753933446"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_toolbarSettings_lastUpdate", "1346775530876"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.serviceLayer_services_translation_lastUpdate", "1346763931428"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.settingsINI", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.shouldFirstTimeDialog", "false"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.smartbar.CTID", "CT2851647"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.smartbar.Uninstall", "0"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.smartbar.toolbarName", "uTorrentBar_DE "); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.toolbarBornServerTime", "4-9-2012"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.toolbarCurrentServerTime", "4-9-2012"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.toolbarDisabled", "true"); [cz4vwqy8.default] - Zeile gefunden : user_pref("CT2851647.url_history0001", "hxxp://bayimg.com/FaEfOAaCm:::clickhandler:::1346754087076,,,hxxp://bayimg.com/FaEfOAaCm:::clickhandler:::1346754087077,,,hxxp://bayimg.com/FAeFpAaCm:::clickhan[...] [cz4vwqy8.default] - Zeile gefunden : user_pref("browser.search.defaultengine", "Ask.com"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.admin", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.aflt", "OC"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.autoRvrt", "false"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.cntry", "DE"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.cv", "cv5"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dfltLng", "de"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dfltSrch", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dfltlng", "de"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dfltsrch", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dnsErr", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.dspOld", ""); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.envrmnt", "production"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.excTlbr", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.ffxUnstlRst", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.hdrMd5", "B299F4B8F503BC44405656696B726AFC"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.hmpg", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=13&cc="); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.hpOld", "hxxp://google.de/"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.hrdid", "aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.id", "aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.instlDay", "16038"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.instlRef", "MOY00621"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.instlday", "15559"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.instlref", "INF1205T01"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.isdcmntcmplt", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q="); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.keywordurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q="); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.lastVrsnTs", "1.6.7.412:24:42"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.mntrvrsn", "1.3.0"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.newTab", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.newtab", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.newtaburl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc="); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.prdct", "Softonic"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.propectorlck", 82921020); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.prtkhmpg", 1); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.prtkhmpgwndshow", 1); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.prtnrId", "softonic"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.prtnrid", "softonic"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.rvrt", "false"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search settings, Click No to restore original settings"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.savedVrsnTs", "1"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.sg", "az"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.similarsitesstorage-pid2", "c115f0c395705f96"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.smplGrp", "none"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.smplgrp", "none"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.srch", ""); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.srchprvdr", "Search the web (Softonic)"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.tlbrId", "opencandy2013"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=aee3b156000000000000001f3c8db1bf&q="); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.tlbrid", "base"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.tlbrsrchurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=1&cc=&q="); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.vrsn", "1.8.21.14"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1415:38:24"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.vrsni", "1.8.21.14"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic.vrsnts", "1.6.7.412:24:42"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic_i.dnsErr", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic_i.hmpg", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic_i.newTab", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic_i.smplGrp", "none"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.Softonic_i.vrsnTs", "1.6.7.412:24:42"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.admin", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.aflt", "babsst"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.autoRvrt", "false"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.dfltLng", "en"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.excTlbr", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.id", "aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.instlDay", "15800"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.instlRef", "sst"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.newTab", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.prdct", "delta"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.prtnrId", "delta"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.rvrt", "false"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.smplGrp", "none"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.tlbrId", "base"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.tlbrSrchUrl", ""); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.vrsn", "1.8.10.0"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.vrsnTs", "1.8.10.015:14:11"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.delta.vrsni", "1.8.10.0"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods._xpiupdate", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.aflt", "_#wbst"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.first_time", false); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.id", "_#b5eb6d2680a04ddcb932f1de2209df85"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.instlDay", "_#15282"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.sid", "_#b5eb6d2680a04ddcb932f1de2209df85"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.uninst", true); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.update", "_#v1.4.0"); [cz4vwqy8.default] - Zeile gefunden : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5"); -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [26698 octets] - [14/12/2014 13:44:06] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [26759 octets] ########## Code:
ATTFilter # AdwCleaner v4.105 - Bericht erstellt am 14/12/2014 um 13:56:25 # Aktualisiert 08/12/2014 von Xplode # Database : 2014-12-13.4 [Live] # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Martin - MARTIN-PC # Gestartet von : C:\Users\Martin\Contacts\Saved Games\Downloads\AdwCleaner_4.105.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\Program Files\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Babylon [/!\] Nicht Gelöscht ( Junction ) : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf Ordner Gelöscht : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\user.js ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKCU\Software\a538bdae63de947 Schlüssel Gelöscht : HKLM\SOFTWARE\a538bdae63de947 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2851647 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{90049ED9-794E-49AB-9C42-9005C1F541F6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EE001F72-E820-4CF1-AB08-134A51CCC6AC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EFF4AAD8-D55A-4E31-B1AA-8CE22B0F46A8} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8} Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\filescout Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\SOFTWARE\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Solvusoft Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7 ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16599 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v34.0.5 (x86 de) [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.1000234.TWC_TMP_city", "MUENCHEN"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.1000234.TWC_TMP_country", "DE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.FirstTime", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.FirstTimeFF3", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.UserID", "UN55348821975465960"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.addressBarTakeOverEnabledInHidden", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.autoDisableScopes", -1); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.cbcountry_001", "DE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.cbfirsttime", "Tue Sep 04 2012 12:18:57 GMT+0200"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.defaultSearch", "FALSE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.embeddedsData", "[{\"appId\":\"129351532245275780\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...] [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.enableAlerts", "always"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.enableSearchFromAddressBar", "FALSE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.firstTimeDialogOpened", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.fixPageNotFoundError", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.fixPageNotFoundErrorInHidden", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.fixUrls", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.installId", "fft7D6A.tmp.exe"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.installType", "XPE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.isNewTabEnabled", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.isPerformedSmartBarTransition", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"about%3Anewtab\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://uTorrentBarDE.OurToolbar[...] [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.openThankYouPage", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.openUninstallPage", "FALSE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.scriptSource", "hxxp://127.0.0.1:10000/gui/"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.search.searchAppId", "129351532245275780"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.search.searchCount", "0"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.searchInNewTabEnabledInHidden", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"3\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2851647\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentBarDE.OurToolbar.com//xpi\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentBar_DE\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"1\"}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1346753932234"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_appsMetadata_lastUpdate", "1346753931819"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1346753933596"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_login_10.10.27.6_lastUpdate", "1346768334105"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1346753933738"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_searchAPI_lastUpdate", "1346753931133"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_serviceMap_lastUpdate", "1346763930917"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_toolbarContextMenu_lastUpdate", "1346753933446"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_toolbarSettings_lastUpdate", "1346775530876"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.serviceLayer_services_translation_lastUpdate", "1346763931428"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.settingsINI", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.shouldFirstTimeDialog", "false"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.smartbar.CTID", "CT2851647"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.smartbar.Uninstall", "0"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.smartbar.toolbarName", "uTorrentBar_DE "); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.toolbarBornServerTime", "4-9-2012"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.toolbarCurrentServerTime", "4-9-2012"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.toolbarDisabled", "true"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("CT2851647.url_history0001", "hxxp://bayimg.com/FaEfOAaCm:::clickhandler:::1346754087076,,,hxxp://bayimg.com/FaEfOAaCm:::clickhandler:::1346754087077,,,hxxp://bayimg.com/FAeFpAaCm:::clickhan[...] [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.admin", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.cntry", "DE"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.cv", "cv5"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dfltlng", "de"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dfltsrch", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dspNew", "Search the web (Softonic)"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dspOld", ""); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.envrmnt", "production"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hdrMd5", "B299F4B8F503BC44405656696B726AFC"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hpNew", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=13&cc="); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hpOld", "hxxp://google.de/"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hrdid", "aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.id", "aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16038"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.instlday", "15559"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.instlref", "INF1205T01"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.isdcmntcmplt", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.keyWordUrl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q="); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.keywordurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=2&cc=&q="); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.lastVrsnTs", "1.6.7.412:24:42"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.mntrvrsn", "1.3.0"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.newTab", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.newtab", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.newtaburl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=15&cc="); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.propectorlck", 82921020); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prtkhmpg", 1); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prtkhmpgwndshow", 1); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prtnrid", "softonic"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.rvrtMsg", "Click Yes to keep current home page and default search settings, Click No to restore original settings"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.savedVrsnTs", "1"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.sg", "az"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.similarsitesstorage-pid2", "c115f0c395705f96"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.smplgrp", "none"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.srch", ""); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.srchprvdr", "Search the web (Softonic)"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=aee3b156000000000000001f3c8db1bf&q="); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.tlbrid", "base"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.tlbrsrchurl", "hxxp://search.softonic.com/INF1205T01/tb_v1?SearchSource=1&cc=&q="); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1415:38:24"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsnts", "1.6.7.412:24:42"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic_i.dnsErr", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic_i.hmpg", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic_i.newTab", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic_i.smplGrp", "none"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic_i.vrsnTs", "1.6.7.412:24:42"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.admin", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.dfltLng", "en"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.excTlbr", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.id", "aee3b156000000000000001f3c8db1bf"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.instlDay", "15800"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.newTab", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.prdct", "delta"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.rvrt", "false"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", ""); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.10.0"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.10.015:14:11"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.10.0"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods._xpiupdate", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.aflt", "_#wbst"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.fcmdVrsn", "1.2.7.5.4"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.first_time", false); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.id", "_#b5eb6d2680a04ddcb932f1de2209df85"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.instlDay", "_#15282"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.prtnrId", "_#facemoods.com"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.sid", "_#b5eb6d2680a04ddcb932f1de2209df85"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.uninst", true); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.update", "_#v1.4.0"); [cz4vwqy8.default\prefs.js] - Zeile gelöscht : user_pref("extensions.facemoods.vrsn", "_#1.4.17.5"); -\\ Google Chrome v ************************* AdwCleaner[R0].txt - [26840 octets] - [14/12/2014 13:44:06] AdwCleaner[S0].txt - [27941 octets] - [14/12/2014 13:56:25] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [28002 octets] ########## |
14.12.2014, 14:10 | #8 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozentCode:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Martin on 14.12.2014 at 14:03:28,16 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{010ED462-A34F-45AD-9B3E-1E76AF1F97B1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{019D5F8B-83B7-4083-AAC1-ECA71F710077} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{01DB3E95-A380-4281-9C74-0C75A578106C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{02655165-144E-4270-A1A0-AEBF5AF55A91} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{027F416A-F8C3-41E5-A668-183E4ED25538} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{02B89828-00BB-4A06-A761-849FA1B0AE7E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{02CB3360-E9CA-43FC-8FFB-AD16B093D3A9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{02D50A15-D725-483F-BA43-4C5DB81E0EA4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{033D729A-6C59-4376-B3C9-E40927B886E9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{039F9751-38EA-41A1-B638-54CCF9F808E1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{04079EE1-6DDC-4292-BE33-B42BC74C7A11} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0488E9AD-F52D-495E-9B54-5D0601BC731B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0503E4EF-8C2E-4E29-98F1-A541CA730DB9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{070BF0AE-EF09-4050-A4E8-6B7BA9FD1465} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{07218C21-ECBE-4068-AACB-72177C938E21} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{072423B0-1103-4915-8B65-7DBA3B7B70FC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{080A10D5-7259-4B1A-9ECE-1522A669FB3C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0882587D-BB46-498C-9060-DF8F748DEF36} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{091E58E8-B0AC-48D6-BFED-D3965F3D5423} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{09735228-7420-499E-97FE-EA43556E945A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{09A222EC-97B6-429F-8024-AFC93C88A558} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0A361892-F41D-4076-ADFB-DFF09EF6DF33} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0A5A6488-C7ED-48C6-B5B8-D2060E943252} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0A962495-A5E5-4DCE-B727-FB965F01622B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0ABBA4EA-103F-45A0-8D5E-321DEDD9EDB2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0AD55A67-142F-42C5-935C-96AC94B6B55F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0AD59E40-666F-41D1-A726-65E9706A9385} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0B5D849E-ECBF-422B-94DA-B25EE1F297FF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0B7C6AD4-836F-4418-9E3D-45703863E8D4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0C2CEE4B-B821-4EAF-AC98-228088FCF777} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0C3884CC-E3D8-419A-BAEC-7DBEF3F6ABE5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0C4D2580-0BDD-4E95-B879-ED854923B101} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0C9FCD46-4318-4EAB-B8A4-D38F80811B82} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0D72840D-E5B3-4A88-9E1C-60E36ED43A41} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0D89E794-90DB-44C0-B2D5-C1D63D149EB9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0DBC54FF-E326-4B34-9FB2-93DA399A537C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0E3FA846-BACC-4C31-B686-38F76BD3EF6F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0EDDACED-1DF3-401A-9ED7-0616E31CA5C4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0EE4769A-4DF0-49E0-8215-B434D07C2D90} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0EE82B8A-00A0-41FF-9CA5-B7D6FB4E166D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0F5F70CB-7C6C-4D3F-97AA-6496201DB40A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0F75A635-3501-41A2-B94B-4C8DE5AD474B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{0F8D6D1C-8B40-4E11-8068-FC182876F2E0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{100FB5B2-CC8B-4C30-99BF-9847C02AE64B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{10182441-C751-4BC5-BBA2-74F6269DD87E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{11CC2EBD-D491-40E1-9DBF-4D9B2470B86B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{138D77CB-5333-485D-9310-DBA565625906} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1392FEB0-DCA2-4611-BEEB-16AADF829DD6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{13DE0822-EF81-4804-8221-E65CDEBED2EB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{14176797-6216-46AE-8F8A-FA79F85F63D9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{147C5285-A221-4F1D-83CA-54DB55381212} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{152C1E4C-50A5-42F6-886B-59413AE94E43} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{15417FE5-7500-49A0-98E4-29FE31C95168} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{154429B8-2F0B-431C-BB21-5E467CA6198B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{15F4F11E-2A1B-4F1A-9A9B-45F89BB60976} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{171419B5-9E9F-47A8-95B8-9D774440D8F6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{172997B2-F0FD-42F3-81DF-37B95C90FFC2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{17D963BA-BF0A-4AAE-8DA2-5CE44DAC50D5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{180023D8-3650-468F-BBBE-B2ABF2B7DB1D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1835BC98-80BF-4A8A-B453-E844AAC0BB1A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1874E263-41F5-4692-A001-DD82C01DEF79} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{189C29E2-A93D-4592-918F-99F05594EEF2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{18B29495-BCDB-4CD4-840F-4181463C71B9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{18D1355A-4EB4-4646-AD59-59D25C8E697F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1921D69A-AAFB-4941-A24D-91CD83B6AE22} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{19857409-B232-43D1-A277-F4A86188BE8A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{198F3772-5E3A-4D15-BD60-95199DEACD6A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{19C7E112-D88E-43B5-BD70-1683A043C21C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{19E0823F-7E43-4DCF-9AB0-4685371FE3D0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1A11D97B-9245-433F-8904-94C0ADBFD8AD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1A54D57C-435B-49EB-A0A2-0941C40F9CAE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1A859F48-5F99-49C0-A995-D6B91D2263A7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1AA834A6-BFB1-4B41-82CD-25755E4A4B22} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1AD89113-B781-40F6-B957-F867170B44AE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1AE263FC-9665-4143-B529-2F249358243A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1B4993FF-2110-41F3-B3C8-8D865D28F7F2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1B8B4722-83B2-40F0-83C4-3CF00D59E8A0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1B9B96EE-4516-4B9D-91D7-270DE0FCC2B5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1C19D9BB-8104-4A30-97A5-69AC5F13861E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1C49D8DF-9013-4DBA-838F-75949196AF0D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1D0D394A-9250-4886-A50A-CDCC402EF139} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1D205FF2-3D21-4C4E-9001-E7D144C76F70} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1F499426-6250-4A44-80EF-EA40A5396648} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1F517FAB-66B5-4ED1-903A-FA07E1416142} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1F74EB9B-C8B2-410A-B1AC-4E6A3B83EAD2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{1FECC90C-3550-4B67-A51D-F1DF63C3235D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{20373AB7-4637-4EE3-9B78-748BE03F3802} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{203C7227-77C1-4784-AD7B-8AE6304C98CE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{21DCC720-CDD6-4F37-AF13-DE10C66BB075} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2248D8C7-986E-4ED8-BAE7-A4D6D7DDC24C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{22C2D18D-606F-4976-A43B-991EBC73084F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{22CC6A09-B500-491F-AE13-0C5C9D11B2A8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{22E1F980-C3E9-47B0-B518-EC07414B5EE5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{22E31719-0086-46EF-9D28-5328FBAB4A5E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2302C29F-3281-4066-8BE5-CF8799808755} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{23630688-3CC1-4129-A4EB-541DB24B6BCE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{237F65F3-CEBB-41EF-8D1E-C110B22C8A5E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{238D1D35-B49F-4359-8F4E-B9D48A62FE7B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2440B117-501A-445C-BE0D-970D1C3B2D95} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2442F737-28B8-456D-9107-1310FF4C3D2D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{24563825-C96D-480D-A845-8D7DE26D3607} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{24923B41-E74C-477F-8584-950ABD96D8BB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{24D3D2AA-ECC7-44D0-BF3F-97FCAB14E7E0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{254A0939-855D-47E1-ADD1-E7142F4E1936} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{25871C1D-52F8-4303-961A-3E3D765282A5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{25B56548-0BBE-4285-9657-1252091D9728} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{261D05D3-8E73-408F-9E28-17BAAC1C97E1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{261E15F9-E376-4C33-AC4E-0A2CC5590114} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{263AED4B-A377-4BA8-B576-E2BA9856F7DB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2677A0A7-0657-4247-9CB3-DF2E2FFB478A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{26CB6D01-8575-4028-A671-D8745F1B5C1B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{274AD121-A679-469F-99D6-5AC0B1267ED8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{27591635-0D8B-4EAD-8941-523072FE2F93} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{27ED0CAF-9D39-4D3F-9877-AB6830A65C0A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{282F1D82-614B-4004-9AAB-0979075800AA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{289DC46D-C745-4964-97DD-F5D8FD4B62BA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{29450087-F4E5-4937-972F-3DB83198221D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{299D688B-D694-4300-96F7-FFD8F959156B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{29C211D9-75D0-4F5F-87D5-8FC0A43F8C0E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2A4BA642-1B9D-4B03-B617-E6885038ACC0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2ABE04A3-D21C-407B-8828-7D5262ED90FE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2B186AE3-A026-4B83-887E-600A9FCE9385} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2C0E901A-A03D-4021-B2A7-E08222C866FA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2C222E64-3E79-4E3F-9804-372EB7B0A8B0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2C786B89-450E-49E3-8E88-DBD9AE602B3A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2D6021B3-DB9C-482F-8FF5-5B28AE3A34FA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2E3DCB96-8C2B-4739-81FF-7CC13AFCB936} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2FE44B6A-9EB0-49DD-B1D0-8FA1F699098D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{30076988-21CF-48D3-AB3F-F979DE0B0F12} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3035E893-1092-4B9A-8E99-71EFE799A7E6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{304E2150-0C5B-49F1-804F-D2D686875F28} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3104957D-485B-417F-8E19-244460A889D0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{318B0FE7-DE8D-4039-8616-AE2C6DAD20C5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{31A4641A-070A-46D7-BF7F-96A4AD5D4474} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{327496CA-1476-452A-BAD5-7440AC3DAFDB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{33D52C20-D8D5-45B1-BA1D-94CC40E20DAD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3406E003-EBF5-4712-B4D1-2D352F44374A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{346B1C5C-C91E-4D1F-B51D-4C9516EEDC9D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{358C10FB-4067-49D7-9C12-92753240496A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{362B3625-8DCD-49FC-B67B-358726DEC552} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{363EC9AA-ED3C-4825-BC8E-54B6C1B5B33C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{36852663-ACA1-4C76-AB8A-E554FD9AF38B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{36F228F7-A2FB-4460-8369-CF71A9212ACB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3736A244-C053-4180-9786-4D55C1645C89} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3762443A-EA89-4B27-A94E-6075BC59D308} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{37EE6EEB-1F29-4087-A950-1647CED64705} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{386E92E7-B5E8-463A-BE49-DB94C64FCF0B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{38CE0420-7DE7-4825-A334-F64D392B2E2A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A1A89C5-150C-4785-9A73-21F11F83EEAE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A643B4E-DDF8-422F-BDF8-86040B6540CD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A72C576-E12C-45CD-BAA6-47B1464ED3F5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3A820957-C36E-4275-A9BA-E137E79E53B5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3B0BF2B9-88B6-4A74-B4A5-974809E8E8AC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3B254288-2D13-470D-BB04-F3CC3B307767} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3B560FB1-2313-4CEF-ACA9-BFE1AEEBBE0D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3B7302ED-6CF6-4B0A-A7D2-489F1CA66F1F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3B76F663-868E-4C71-A5AE-93023D25212A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3BF7DA5F-9933-4499-BD75-6CFA89E308F7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3C939C6F-9F80-4DEC-BCFA-FCA65E22F802} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3DCEFD13-1C3C-42E4-B119-D0704FBD3C6F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3DF0253A-9FE9-4EB2-B0AA-376A5DCAC154} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3E60380A-16C4-405B-8A83-3F4E62834B74} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3E736805-8F13-44AF-B3AA-D84CB4A74BE9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{3FEFC9CC-F90B-48D1-8030-F07668B6CE3B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{400EB0F0-8FF8-4712-950E-4BF0FF09AF7A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{403BF1A2-E21E-4F6E-886A-009B8532CA01} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{40ECE5CA-0A52-43CC-9395-A2DF3FE818EC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4112A6C0-6AD9-4664-824B-A3E99ACECE3A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{413A1268-E1BB-4A26-9ECF-850D84268011} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{41DC2609-2CCF-494D-8693-96BE56CB9B1D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{423BFE39-78B9-487B-9B4E-C847CA1F17D2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{42F6A908-E325-4B5F-B246-86C633BEAF7E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{434E743F-CC0E-447B-806D-C0FEFD1E5AF0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{43C6910B-2374-4253-8292-3951265952C4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4484ED3C-2B78-4592-B0C5-BC5FD737F0AD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{44D1AEF7-3F97-486C-B9B2-D7AEACFC1C7C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{451ABFC0-E5D4-4BA3-90EB-F4EFC77A79F8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{45C8719A-DBF3-448F-AD42-743B252AFAD0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{464F2E15-08F4-425B-A0EA-00A0C0B4D747} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{47228BB6-443C-41A5-A143-84FD767FD12A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{476AC178-7B8F-4C51-9581-51772E069C65} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{47C56DF7-EB88-47CA-ADD8-75754A440113} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{48A83692-FB9C-4970-AD8F-A70E2D2EBE8A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{48ABADC1-898D-40DD-A26A-20BCF7BC0F9E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{48D42EAF-F21C-476D-BC2A-1F2523059944} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{48F69054-782F-454C-9BBB-AA5CE0F0F52F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{499409AF-B2B0-47A0-A140-7C2C1ABAB13F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{49AE55F0-DC66-4EEB-8DE2-27FAB7AB916B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{49B7EA1F-D242-4991-A6DB-85AD81BB6BED} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{49FA4E6C-CB61-4CFA-8241-73C865DA0508} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4A6D88EB-A6BF-4E5C-8955-EC294D8F8ACE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4A72DE00-22AF-46C5-BAC4-34330237840F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4ACD5DF8-7FF2-483F-9932-5A4951A9AEA1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4AD40B95-0E02-4AFC-84E0-B727BF6DCDF5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4B0E8F8C-8993-448C-A2FB-E15BD53DFE90} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4B5457C4-5C04-4B1F-8F50-AAEF7EBCF41E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4CF9A9A0-F248-412D-8F96-813A86FDAB47} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4D29583D-5128-489B-9FFF-C46FAB13B806} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4E40C86A-9A7C-44BD-AC20-B50F940D2C75} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4E7D1296-BE51-47DE-9518-EE3D4B3C2502} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4E934D76-E657-4B34-B7B8-216CE9A1C266} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4EFB2483-C7DB-4558-AECA-106D13E8EFD6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4EFBA43B-BEB7-4982-B4BA-FDAE9BCD371B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4F00EFDB-1F83-477D-A203-39EEA14667E1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4F0254EF-5BEC-40A0-A0A6-882B536974BF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4F044975-6B9C-4589-9F2B-9F7A5BE5C954} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4F1359E2-8875-4AE0-8564-BC3803E0D789} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{4F8C3ADB-8D55-4028-A501-6B42DE5E779A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{505560F5-4C55-42D0-A156-E0457E273E50} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5067EBB4-BFB4-443E-8500-1E34EC377574} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5119344B-288E-43A7-B8B0-B86FD74A7058} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{511A17B7-352B-443A-A5BD-555043C5C6DF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{524E0D8B-E014-47A5-9123-479D06EF7EEA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{526ABC47-9EA8-4764-8E3B-8CD99658EBA7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{529846B3-BF08-4C44-816D-5D5C7DFC9694} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{530F4FD8-BFB9-4616-98C8-3F071261A590} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5322F41E-9FB4-4CD5-947F-7C9458677349} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{53CC2769-51DE-4A44-8BBD-411EFFD09FD0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{549C5015-1104-446E-9C29-F351F59707C6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{54CE8683-D652-4EB1-93C3-05D3700541E8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{551707F6-2DCC-4225-91C5-5E4B517B1192} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{551C62D0-0FF4-4004-AF19-A2105F6CA478} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{557B60D0-A8D3-46D6-A583-FF35D44AE59C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{55E4845C-7924-4D10-9A75-A3AF80324053} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{55E80C52-1018-4BE0-BAFB-9BD19D832864} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{57559FBD-E70A-4675-8AD5-5395C52CD516} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{57756678-AC68-4C75-B825-5C087C42CFA2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{581F44CE-ED59-4033-8DB9-76FCEEDE042E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{58C95033-F317-401B-B178-0CC3A9964864} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5937404A-6F03-4659-90D8-99F792B180C2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{595629D5-AE26-40DD-974A-EB97CFA9B4E9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{59AFC3A8-29B8-473E-8DBB-9E61294D155A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{59BAC72D-C6D8-4730-B0F4-9D17F1EEA703} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5A52AC93-ED6D-451A-8FE0-07D8015FCE6F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5A57EAC8-6C77-423F-9CCF-D5167CD674FF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5A70F789-FA6E-4176-816C-3F98EFE4F0F8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5B2BCED6-B407-4FFD-978A-920E95812009} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5B547E03-03F7-4280-A893-690221949ABC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5B82B8E9-1BE1-46BB-AE7C-CBC21784A32C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5D252330-8701-4E13-A37E-464DB4403CDD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5D438D4F-99A5-4350-B2F1-F654F20E7F96} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5D5632F8-B907-42F0-9897-CDAA2203E178} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5E06B4BB-ED2E-4C69-93A1-5F210FFA98B1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5E5DEB4E-D7B1-420C-9A95-8F167796B698} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5F0FA5F7-F5F0-40AA-92B6-D54B5E86918B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5F718F17-CB35-4629-B41C-E9F5F8C4EBB3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{5F991C1F-D896-4A93-B47D-372E8EE62213} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{60067673-32DD-45EA-A88A-3CB07994C49A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{609F1EE0-BC8F-4F2F-8BA0-C8DFFEFCB5B5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{612D902B-3A02-44B7-A80D-A7E0130C9D1B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{621A3CBE-06C8-4EBD-A503-8DE3C720BC83} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6290BF29-D3FC-4F90-BEA5-6B39BD893CF7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6292E5EB-BFFB-4167-BE9D-8BF82C677FAD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{629E5C73-52E5-4E6F-9184-72C398E1B1C6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{62AEC6EC-EC89-4FB2-9601-61B9CDB44847} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{630DE86F-EEF8-4440-B903-D8A0D837067B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{63560C74-9349-457B-A24A-74F7AA00BA12} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{638F51C9-9B1F-4847-813C-50782886264E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6446053F-35BD-4CDD-A72A-3A31B7470C06} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64D1494B-478A-4281-8159-09A8005FF3D2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64E7ECF8-2BF6-492C-87E1-B31FFF2C8A67} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64E8BAAC-58A3-4F5E-A426-7E2E810E8F65} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{64ED1F3E-BE07-4FF3-9D77-FE592750AF77} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{65342BE2-144A-4997-BC06-F3D8529072C4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6539956E-8FD2-49A7-A81C-D19FA4BF4E11} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{658D097B-6683-4CDD-8FCE-B3134A39A343} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{65A66F13-BE48-422E-9B01-76EAE41D6B80} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{66335769-1C85-42E8-9EE5-B7A5C50FD697} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6657738F-0D99-4BBD-82FA-7E3AADC51B7E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{66B33A3E-C815-4E01-B970-F1F96021120F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{66D25F4B-A250-45FD-8B2F-A6C4BDAD25F5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{66D95F80-E214-4CA2-B2D2-F1B608CB8D8C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{678D682B-7CDE-4944-9BA9-BDF1C184831F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{681E5FA0-A565-4215-9929-0D3756F44ACD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{681F76CF-FFDB-4EEE-AA24-B14E19D026E4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{682AB92E-D79B-4165-B329-84E1B38C0855} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6859DBC6-A717-4817-A691-E5702151AB7F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{68948C0B-33F3-43D5-93C1-2BD5207D0991} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{69DFBBB6-C34B-4B65-AFAC-A4EEA8775974} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6A03A2E2-2C0B-40C0-A014-F0E3C4A7FF73} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6A03D334-E0EC-4321-B686-2812AD561549} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6A5EFE9B-930A-4441-8D77-0D67CE7BCCB7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6ACD1C8F-A70D-4715-A926-47641DF765BD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6B5CD0F2-4F8F-4E74-8B1C-4135C5D85A06} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6C3D6016-E0E5-4234-9185-F826E51059BF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6D149B70-540E-436E-A023-133FA01A6AEE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6D48D70F-0DDD-420C-95EB-E464031745A5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6E264F7B-73EA-44BF-90A0-5FA56ADD76DB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6EEB76A5-796B-4B2F-9C00-594EF1057A82} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{6F45B65F-33ED-428B-80F8-EAF44819E643} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{700F70F3-7BF4-4620-BD51-7525276B5A8A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{703A4221-443A-4C07-A609-A48CCBFE0469} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{705400C4-4F06-4A6C-9C8B-C8BDB9759CA4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{70981B4F-1FEB-48D2-892F-8FA1636218C4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{70C8016B-BB20-4EE3-ADE8-912A68CB6694} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{715AF006-049A-480D-811A-65DAA6B3B1E5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7204FD78-4093-49C7-B23C-B9147A2F1FD9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{72604E25-9860-4DC1-9308-0B9C00EDFE20} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{726B5653-28EE-47F0-A455-4BA8BA2948F1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{727A7C58-1D6F-47B0-8441-F5ED81876A87} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{730D0127-3C4E-4821-9372-166149F613E2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7360A83A-2293-453B-AC7A-AF3E0FF9248A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7385C78E-7EB4-4E9E-9AD9-0E84AA432197} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{73927B01-D985-4BA7-ACEC-8C4A9391C7AF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{73A27CD1-AFC8-4B38-B7A4-5E55AD6172DE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{749813DA-644A-4CF3-8668-7C5FE3C121C7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{74A6B488-96BD-495B-8ABE-C69AFFBF5E2E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{74D98609-9DF2-415B-AC01-6F91B8307467} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{753F5647-6C0A-40D4-8F9B-86804E0C8F5F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{75948AD8-9E3B-4C91-A2A9-AC75BDAA7A16} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{75C58BF0-C645-4F31-9A2C-576CF7D9C93A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{75F5D532-991F-4603-84D6-BAB19295BDB3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{765F4721-CA6B-4126-B989-04FEF2E2767F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{76A949F1-027A-4B80-9FD6-35DBD2DDF5DF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{76CEA189-C2F3-41AC-8BD8-98A118E3357A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7738D441-C802-4AAD-8024-81E29E3C1388} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{77459836-7E27-4604-B5BD-F7A0A57CCEB5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{774DB708-1CF2-4E3B-ACAC-0D36BDDDBF7E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{77AEE2B1-4B17-4888-A2CB-3B46ECB3806D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{77B48DAF-D6D1-46D2-A56F-54BD18452AE9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{77C59AEB-D4BF-421E-AF7A-3AB7F47498AD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7854C3C2-1A94-44BE-82C6-6216B9C0F549} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{78854F9B-4A9C-4BF7-9C95-653D640715C8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7886CF8D-558E-48DE-B5D4-06587454AE75} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{78FF76A0-FC27-4B52-A7CB-EFCB60E2A2E4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7A642F06-9E9B-43F7-B60B-CAA00B4D38C5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7A939907-D2DB-4608-8A1A-B134DC82DC67} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7AB011C9-40BA-45D4-A12F-873D8E413060} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7AB69B8B-C8F8-42EE-86AC-8344BEFCC2FE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7B7D46E7-B1A0-420D-8F2F-81A41906687F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7B9D673E-BDBB-4562-920C-C8483D494A46} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7BD6A126-750A-48D6-ACAE-40AC2B4D3B2F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7CB8AA7A-1AFA-46A0-ADCA-661458B14278} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7CD36E51-B9F8-4E97-8E1E-EBCB35060E94} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7E4AB20E-DC3A-4CC1-A607-66D655608624} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7ECACF06-A65B-4065-B2E2-2E2422DB3053} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7F81D334-6656-48CA-A581-B9EBC9EF4C32} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7FE42E8D-78A0-40FA-A7E6-4D058F54925B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{7FE86E90-E720-42EE-BB30-1DEF585C05DD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8036EB36-4475-4B21-B2B6-884459C9128B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8048366D-7B95-4684-842C-CF410D93A25D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{805DEC3C-C5E6-41A2-BC0C-FBE6C9A39E57} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{807EACA1-5DDE-4BBE-89B0-8919B0A507F7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{81057419-C7CE-4BDF-BFC8-FBABA757614F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{810957A6-62B2-4DFB-8CA0-B9A8874B0C2E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{816AB6F3-6BBF-4DB9-89C7-316BD4E5521E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{81D4E1A3-519A-4433-B5EE-D371B424204A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8213BF0A-AABA-4839-AAAB-D8704D9FA3BA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{82578B43-B7AA-4C3F-A226-BD7E003456D7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{825A9C6B-E799-44E4-BFC6-CBD4CA21DFFF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{82AE8B49-2D36-446F-B22B-692889B9F31C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{837EA42B-3350-419D-B68E-8AB71064F659} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{838D4C27-22D6-4FEA-9AE9-CF0694594FE1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{83C51246-03D2-458F-9C65-0CD9B0BDBD77} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{84406EAE-EFD9-456C-9404-050ADBFED4AE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8462D50F-41EF-4A08-88A5-ED1768585039} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{846CD709-27C1-4D17-B9DF-229E33A0798F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{84810361-BAD4-402C-AE52-67F5633CBEFF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{848B2F9B-30B2-41FD-8D1B-956941C0FE7A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{84F71F86-FD7C-456A-96E7-E37AD64659AF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8509D0CE-A006-4074-AB34-6E88BE193BF2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{857A6A6B-A0CF-473F-A638-0854A16B3536} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{85902E8D-9EE5-4F4F-9450-5441673AE68D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8793083F-75A3-4547-9A9F-146B18990AC8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{892F6857-03C8-4DAF-B406-561D3B2CB598} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{894F0886-754B-4AE1-B38D-C8DBC231FDDB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8A5FF611-D021-4766-9791-970CC4CD1044} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8BE91593-80AF-48FD-9AE6-FC9F7C905BBF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8C04D21E-6115-4F1D-AAED-30F56945146D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8C2459AF-BBF5-4A1A-8528-E25F95A37A60} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8C5F9807-BE70-47A1-BCE2-9EE2F11974B4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8CCA185D-49E4-4529-A381-BA10015F62AB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8D0585C8-5574-47D7-AB88-45524DA4D48E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8D285DF0-ABA3-4AD1-8A86-1E5FDB6C6FBA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8DBF70D9-CA90-4A74-824D-573FAF798782} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8EDA8A81-6378-434C-BCA9-1708DB75C4E5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8EE4E5C0-F0F5-4465-B58C-05325C1637DE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{8F40EE77-9234-4D2F-90B1-B0756244021A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{90DE48CE-59C6-481A-8B59-438329052161} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9166B783-C699-44E1-9D47-BC2BFB27FC9F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9209CDFB-5E53-4E38-9E68-E3A581E396BC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{920D6DD5-3187-4699-BD20-3CA306CB4990} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{922AD259-E31D-48F8-881B-FFC23FFB2459} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{92381198-EBD9-443B-AA99-2FF8CC85F809} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{92892D13-F71A-4330-91FB-EDE37380FC18} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{92D2A085-FAB2-4515-8269-6E526DBD1F9E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{93314B9A-0006-440A-9115-20A76C2C3E15} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{93518173-4A17-4EAF-B005-AF155CD44B8B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{93C7E7AB-C14D-43BE-85B0-1D1045A6C980} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{946934F4-1223-48F4-93E1-43C6C528BB0C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{94CA9E23-3D48-4612-B739-6B56509EF578} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{951F154A-B644-4811-A732-D3A31001556F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{95373EEC-D00C-48F5-8615-BE22D7B59ED4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{95C56411-5CBB-416E-B1E3-9850A8F92AE7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{95D8D39D-BCBC-4F10-9200-11F3092C78CA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{95E9AEA3-C667-4530-B772-2392A4DAF7F1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{960C6509-2192-4761-A397-E1004D9FC625} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{961F407D-67E4-4871-AA47-DA68F1C92672} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9630FC60-8046-4671-B70A-AED84F9DD880} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{965270AA-B911-4F1C-ABF7-80B34EF818CB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{96D96941-E027-4DA3-AFB6-199986043461} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9786D280-0EB5-4334-92E5-603B4F9CF8AE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{97921579-967A-4FB5-9C0D-BBBC2BAC9BE3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{986E0800-8566-4BA9-ABB4-A5DD934CE9FD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{987074A4-1C52-488C-BDDD-FF33BB0AE8DB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9910901F-F4F9-4622-A505-A5E015142CC1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{99AB311A-393A-4C1C-B1F4-B8C04DEF10E3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9A6E1E5F-8305-48B9-B6AD-BB094DBA9C3A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9A7F1891-D9EF-4A5A-A688-282CF7AB6DCF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9A8BCE08-A10E-45FA-8F10-A7EC540763FC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9ACA7061-EA22-406A-884D-1FBD5FBF48BD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9ACF19D2-0DFE-4BBB-948D-1D4AC0D131A0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9AF93C49-4485-4D53-B8CC-66447B0A6FC0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9AFC710D-CD91-46FE-825D-2FCD4FF605AF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9B1F932A-F653-4FD9-B6F6-8B8A2DC244BE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9B28AFB6-ACA0-40B4-8512-7AFD8FDB37A8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9B2F113E-94E1-4040-9243-26AC090C5065} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9B8AC768-2F62-4970-96B0-04ED398A8088} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9BCF709F-5EF6-4004-8608-1AF638EAEBD4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C26A75D-0A80-476B-8279-7BA5C8DEACF9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C3892AB-F214-4839-91DC-7E10579B23AA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C3F9FFA-5CC3-4F44-A715-B4C64ACC098E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C4618D3-8ACD-46F3-A00D-D71155AAB00B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C77E8D4-CCA3-4F65-B199-93E09B425388} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9C982085-B6C0-4143-A20A-2E0E652846E1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9DC1344F-6B58-4CEC-991B-41673053457F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9E0434B4-D73B-4EFC-89FB-CD126EB9FB73} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9E2D0ACA-B989-47F6-AC81-4B4A4C9CEB08} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9F5768AA-C57A-4538-804C-E5C1902018BE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{9F9C1946-76EC-4643-B326-AAF6394EA93C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A09EF474-C785-46BB-9522-A525A8388D9C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A0E156C4-DF6A-4BAF-8E3C-A59EF5E64DED} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A127BB12-59CA-4D36-A8E9-EAC3577E6B5D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A1485FA4-FB40-4E44-9452-707954BCE890} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A16A5989-6927-4FD0-988D-2FD38ED52366} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A1AA6BF6-847D-4DD4-80AA-3E830C0DE426} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A1C57E40-D31E-4FF5-A1EF-28E76597EA35} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A1F834E4-BAA9-4B94-8C9D-0EB63A9E01F5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A2AB87E8-ACFC-438C-948B-BBD333A99EB2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A2F8F1A6-CF13-475A-80D0-DC7FA1398080} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A3359739-6019-4DFC-B462-EF13996658AF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A52E681B-A501-4B83-A2ED-D1DCB2221CF5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A5C549AD-C0A7-41C4-B2CE-FC29AE357C3C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A5CD502E-F502-4D56-865A-9414DE9C3672} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A5D093D6-7D65-461F-AF36-85A6B8F6A146} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A63B8730-048C-4A43-9C1E-88574A4CB8B0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A6AB49E2-C5C1-43CF-A14D-D373286FE6BF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A6E15431-F945-4CC2-A2B6-2236D2B4E28C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A6ECFA92-D869-4C2C-A4D2-283A4962CE00} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A7AC8617-26FE-4C91-B696-D95D8A90C106} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A816397F-F389-4924-9C17-E2CD99BA8A55} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A878978F-E8FC-4DEE-A9E6-5D3EA1643E4E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A9716122-8911-48D1-A5D2-4E74AA5EC91E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A9A15A05-139B-4913-AE67-374510927DF3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{A9E59610-5AF2-4809-88D3-38FA2049DBD4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AAF5E0F2-9E1D-4D4F-8C84-F8CDF4367138} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AB0DA598-0DCA-4E2F-B5CA-20D4FC7946DB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ab275791-70d8-56c6-f53a-376071dbad22} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AC3EEA98-CDC4-4E68-ADCA-2A7307F76A08} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ACA0FE20-1DDC-4DD4-9E07-B8F9E3844DAB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ACE2AA6A-7939-4819-BD08-14E359618744} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ACF504B1-3E73-45DA-B838-C2678C4E9E32} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AD5EFFFD-4795-40D6-9DBA-4A9E60E248E7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ADDAEBEE-A2C6-42AD-8B6E-DDB06831E2ED} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ADF2D2D9-CC74-4498-9212-FA32FF75DC6F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AE85C657-FBC9-4F86-BE2B-2DEF4F10D7EA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AEFB7432-7523-473E-B328-1DD79322251C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AF0CD2F3-A722-41E7-980B-E54F779B030C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AF36DFC9-6E64-40AD-B043-5C976C604747} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{AFF1F1F6-0C59-4613-9D1A-3B8CE93FB6F2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B009B33A-6C43-4791-8286-76BE3A2480F7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B04D05C5-ABC6-4EF5-9F1D-DA3CFD707E68} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B19DD91E-31EC-4167-A4F8-0E60F287C51C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B1F3A45E-03B5-4F5F-894A-BAD535FF4087} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B204EAF4-2615-49B9-B484-A1943A99C65E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B2E110C4-D410-4694-B3E1-82A9ED279984} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B2E74929-F8EA-4566-B9C3-6B4FD04004C7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B2FF8AD6-D336-4971-ADC6-347F2185AA77} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B3209F09-A7BF-4359-8627-666FA7BAF8B1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B383AE96-82F8-4C43-923B-F52F7985A71E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B3E1B806-A1B3-4FCA-9682-5521A2EE4915} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B406A0C8-2E61-451A-AA2D-B355FE1F0212} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B43DB669-28CA-4835-A1EB-34F17C2D4816} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B597F4D8-199F-44BE-A3CF-6D601DF76DF3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B5C7E642-1406-495A-A477-D5B8FF2AEB94} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B65C457E-D036-470B-8819-0D3DF54CCD73} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B68958BF-31E7-4C2D-87C9-8FCA3E2863C6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B6E1F448-CBC0-4C98-92E3-9DA8CD8C9CBB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B6FEBE8D-49A1-44BE-8250-D0C8DF33443F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B708A57F-451E-47E9-8932-AF13D5CF9AE6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B805FE50-8179-4205-A60D-2A79B7AD4873} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B89F52AE-6D67-46AF-96FF-4D78235751E7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B8C38225-1813-488B-B855-D2D6772841CF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B977DCB0-F3AD-4DE8-874F-BB31B957C727} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B9808DDC-833B-458C-A213-27720B1F6667} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{B9B435FA-FD27-47DE-A3A4-F90DD85AB6B1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BA36B657-D493-4164-A95D-AB9D3FE7542A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BA81C8C4-15E6-46A3-AA43-2EF2D377FFAA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BAD6A660-B4E8-4C77-8A81-AE63D2686545} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BB2933C6-6E76-4ADD-A52E-6B751C654DCA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BBB766DA-ADE0-4F93-B613-1EA20F333E97} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BBD34AD5-1188-4E37-882B-29B82F779834} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BC36EE21-2D4F-47D5-A182-4C8B39756F99} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BC8AF779-077D-468E-8E59-D7EC8B48DE15} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BD1F1D49-81AA-4858-A8D5-1E4CB94323DE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BD922557-EFD9-4C9A-A8BF-721AF018774D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BDB667CF-A6C3-42F4-B2DA-072E3CFE7DCD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BDC6B05B-3E5E-4A25-B28A-0014185BC2EE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BEDA0DD9-4290-410E-814C-E6EBF9BD6F8B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BF7674E8-8870-4F31-8695-23FB0A9615C2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{BFD3EDE3-96A3-4D31-880A-E13F5B0FD03A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C00FCD98-0A6A-462A-A707-74D702147E61} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C0C27B5F-2F31-4201-B1D2-CF66EC1A7199} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C1121303-0D8E-4F62-B8EC-E4F6F13E0C32} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C1AF9E71-C7E5-4AB0-A6ED-C05A03B27A1C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C1C52130-6F02-4AC0-97C3-58C19CEE882B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C1DDC17C-58D4-4FC9-994F-CDC84E1C4DBE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C1F01B9E-D991-41A9-92B0-A8ECE47FC76A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C1FD474A-2914-4EBA-A72A-38CD8966F9C9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C217A491-457C-4ED4-899D-5DC1A17C6D36} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C27B3152-9046-42F1-98D4-CBFBAE2DE19D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C3D988BC-89A8-458C-9294-21757B08A00E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C4401150-5BFB-47F8-A05B-F8A8AF83BCCD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C44C4AE6-1DE9-415B-9ADF-F6861E7FC411} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C4632A1C-3F64-448A-AF95-9B703663CAB0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C463A328-E4BB-45BB-9CD9-7EC0989C880F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C4865FDE-F011-4271-9643-B4DEB5996BD8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C530B166-8D5E-46DA-8BE5-8A1B5CDBCD3A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C575AA17-7A7B-44A4-AC06-523C88DCD566} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C578BAAA-E9A2-4058-AD9E-F0991789B1DC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C5C59CF3-807C-4C07-9202-39B5786FEBEF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C5F0277D-0938-4BE4-A0A1-2FCCE39F53DE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C6F17828-A6DA-49D7-8AE0-9174B90DE875} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C6F90DE8-FBD2-4734-A327-E0F172E82E38} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C714D676-89AA-46D8-B1CC-912EFAC88AFF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C779596F-E799-4F4C-A011-CECA7D5EC8F6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C79E6D5F-0279-4C03-BC0D-B9FB96C7B952} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C8143750-8D0A-4DFE-BF8C-917291A760A4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C82C3119-666E-472E-AE8D-DC07990158A2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C884C427-1920-4D48-8AD4-8B521FBA021E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C8A5833D-744D-4ECF-9CCC-2F351E2D843B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C919B83E-1A72-4B84-BB09-7DA382E69C4E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{C9DB66B3-A271-4B01-8322-96B0F32CECE5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CA8274BC-BC83-4302-A80B-28ACD4267A4A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CA97CA09-C2F2-4BA7-B7DE-887EE6067C90} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CAE25CE8-8FC0-491A-A909-26DEEB8F8BF1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CB05C167-E0D5-4342-85CD-D7949413A9DD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CB177769-4ECC-4358-AC73-FC195109E5D5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CBF12E0B-43B4-406E-9ED0-2E1434C1B8C9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CC753D80-7452-44D5-A67D-17380729A035} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CC9DA57C-A1E0-4B77-B5DE-0C86343CE26A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CD568559-8A8D-46D4-95FD-EE25DB0F7780} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CD7E1ED7-C4A9-47C5-8669-E8634C6EB637} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CDF25736-0733-4686-8B1A-9867F36DF1CF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CE54E625-CF2D-4A80-A8A3-60401F03CEB5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CEA05926-3B12-48EE-8FEA-5D7605752F45} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CEEABC1B-BC28-464D-9AE9-555C4BB7B459} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CF59B945-B3F2-4CB2-92F2-3565CAFC7D9A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D019060D-3E24-4368-83CE-05691C02AFA0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D03ACC81-2205-4BAA-8FA2-52ED770A85D1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D03FFDB1-7A8F-4D99-9307-79DFC6C546D1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D04A7A3A-9E86-4991-B75E-56A0C8904D01} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D0A6C7F3-DA37-498C-9F53-078F668719E1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D10743AF-4C06-4590-B8D5-B9138416A22A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D109B36D-CEA3-4A78-A694-0CDBA07BECE6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D158778B-B3E3-4C39-9E3A-BB3D5AC9887D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D1832C40-2CFA-4C19-84C3-AA59770A11DA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D1A23FEA-382F-4A2D-A68B-AFCFA4FB1387} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D1DE4100-4D5D-4DCC-91AE-19E77F11C7E0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D21F435F-5E7C-481E-8F6A-C6CC2512B459} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D24DBE36-DA02-4B97-81E4-E0222E91537F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D27AB780-936D-4A6F-BE2D-06E7FC7F8E89} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D28B7B77-D0B9-4480-9091-B112AB92075A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D3011767-2D19-47D7-9BFB-8785F874772E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D439ED93-9492-40A6-8F9B-8D09AE8EFA4B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D4C4B181-1753-4797-B69E-92B943058D85} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D4C8E5C9-FF61-4CA2-9B96-BCA81EE4EF05} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D4C8EA00-BD0D-43DB-8894-620BCF2A7719} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D4EB429D-FDF9-4DB6-BA6C-CFD4B718EFD5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D6530CFF-F644-4325-9F68-6B99D2BC3E22} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D67A65AF-3CF2-4264-BD1C-F8F6CC84B080} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D6E03C01-96B0-4547-B5C6-395A4737BAE2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D78DCFF9-192D-4790-831D-6ADD58B64C99} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D801A3FA-04C3-46FE-B38D-BB1ED67DEF02} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D8084BFE-0C6D-44D3-8ADD-54F4A3919B77} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D81204C5-A5F7-4F13-88F0-AB6EAB310A81} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D88D81A0-7843-4D6A-B604-5C898A7218F6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D893E31F-014E-4F4A-8341-A094A5F3E7C7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D94A578E-DDCD-4F75-9498-6D2ED54AE5FC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D99E841C-C3B9-4C6E-B0B4-CDF5B81313B5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D9B18BFD-4A2F-4663-9211-ABCB171B740B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D9BA5210-E8CE-4B9F-AA72-BDE4C48A5B61} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D9BD3BD6-6D89-4E2A-B42B-2DBB2B95E1CE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D9E5D38A-69CE-41ED-8CA9-506343519366} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D9F28805-9A1B-482B-88A5-76AB358D1092} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{D9FCA20B-1AEB-4CD9-9D89-6DA7E96A8600} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DA725348-BB8B-4E79-AD04-A70DB056A5BD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DA7B5347-9CE5-4A36-A20B-5E2445EB6A68} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DB133999-A56F-4A3A-A6B1-FC129DD81D4B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DB6B6FCD-9EFC-40C9-9E04-F9725C17C2FB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DB8079EE-4428-4C38-9DB5-9ED5EC891762} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DC13AF1A-3D6C-4FA7-BCB3-9CB68ACDCC22} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DC5D79D5-A9B3-4A21-A8D5-7D2F4F8F2CC0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DCBB5ADE-64A9-45E2-A0EA-4B96D4F1E7A4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DD5292E8-80DA-4CDE-9174-CD9A3E42EC71} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DDAB8200-68AE-4C80-9497-9AD74B5B1625} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DDB40BCD-B9BA-484A-AFC8-C8488EB91FC4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DDD77F72-8578-4708-B460-35A65E872904} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DDDDE98D-F508-4511-B49D-AB1B72EC96D7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DE536D26-0ADA-48FF-8556-5FEDD5D5072B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DE8188AF-30E2-4611-B1AE-CC0972BB0C6B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DED7CA6B-A5D0-43FD-8024-892259D2B688} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DEDA6D42-045C-4465-AC50-603F447E19FD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DEE37BFB-C85E-4D60-A670-EE18344655EB} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DF5C357B-0A12-40B8-A25F-5F5AB24A1F45} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{DFAFBBD2-733F-43F9-9927-00682C2FE7A9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E097A6EB-857C-487D-BA61-496F5BB4A0C1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E1533C0A-994D-4451-A21C-6F3BB68E548D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E21E43D0-7DC6-40F7-963B-884AE0BCDEBD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E220FB08-E296-4D34-951A-40DBE11E1CEE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E243F4B1-AC4A-45DC-AC1A-DB4698EACBFA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E258A155-5EA6-4E2B-8600-B60E1EAD6544} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E2A1257C-9F9B-40CB-9197-89B13194D96C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E2BAAFF0-1B7A-4912-BE41-3325ECE36705} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E3110385-21DE-4AD4-A9D8-5911B73EC8AC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E339ECBB-822F-4BF6-94F1-04BC6C9BA25F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E363CD3D-5099-4E79-A8DA-E4F7026B3323} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E387BD6A-EAE1-4749-AE4F-C7D97D1C8848} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E3A37AB1-737C-4E07-8C3D-E05398C09A71} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E3AA6744-E79A-43F0-B7DF-CCC85DBB3EFF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E4224106-3E8E-4B44-9C2A-AD5E84CCF286} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E4BA3516-5FC7-491E-A53B-A2BA117DC4A8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E4E7562A-6E16-4875-9BB4-92C296EE044C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E60E7504-3F47-4557-9409-7171B64F316C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E615AD08-F482-4CD5-A406-03C7873F25E3} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E6A188AE-32DD-4FB7-883B-32FC56F110E8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E6C91E4F-8504-47CA-91BC-7EE3F626D5D1} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E6C9CE57-DF3F-4569-BE5E-C8D7750A20C9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E72756BF-1630-4F70-877E-B480464045EC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E777490A-FCA6-4B30-9E11-5A7A4180BCDA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{E7E4488C-8E42-48A6-A6A1-DAD950E3D629} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EA846900-EF7E-4A5B-B4AA-F82D790CE63E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EAEDEA7D-FDB4-4ADC-A34C-32CC0B668D3B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EAFE0F28-6595-41A5-8B45-DCC89EF5C727} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EB057F5C-31DD-4A26-AA51-8F8F09BD8719} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EB969BD2-FB1C-4E12-AE83-939615C435A0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EBAE4BD3-6E74-4061-803C-4C09DE35BAA8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EBCAE24B-7B88-425B-880D-C39AC7127021} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EBD6881B-1DB7-4526-8B91-276427E4C7A7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EC437614-E654-472B-81E7-355E11401A43} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ECDF9A6A-F627-4165-833C-A4F65CA0D648} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ED59A49A-6EFD-41DF-84B4-5B740B352BC9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{ED8DFCCF-8208-4C44-9D60-DBC59C46917C} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EDA6841B-B730-4674-8502-585E0854A6CD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EE31A1A3-BDDC-4BB0-AAB3-4F8789F8B7B0} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EE93B330-B2F3-4B7C-8A18-B7C0081EACA9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EF06AD2D-7A33-45C7-968B-332372D11083} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{EF87462E-9D18-4CE1-8317-520A0E8884B9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F0C0992D-E2BB-4D0E-B01A-EBA81983FEA7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F1296B1C-C715-47CD-8E9F-227727A4DC73} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F17FB773-94F8-49E1-A535-81CC5BA584D6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F1A18666-E1C1-49E0-8270-240EA654316A} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F1D68794-C12E-4C7F-9BF4-704FD6256ADA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F28CA157-8AD7-4131-B9C0-01095401041B} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F2CB0E52-3885-4A83-99B3-EBBBDD5B4BC5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F3F74ACD-9886-42AD-A9A5-54477DDBFDD5} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F4226E1F-DC67-4F2C-AB17-931A69CAFF75} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F4AC1980-96E5-453B-9EE3-4E3208D5FF95} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F5A0F781-74F0-4141-8AD5-B06A7B0F9DDC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F6159614-B861-40C8-BBF5-0838A0758019} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F61CD452-5BBA-4074-98D7-BE63B66C3CBA} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F670BAD1-2AF6-467A-930B-5D839EACDBBC} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F70CDC79-FCEB-40CC-B05C-A182853E6241} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F73F7DE2-698B-41DC-A036-9D555FBE80A6} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F7BB6C85-8F8F-4036-B28C-B28EF3FF12FE} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F805E611-3B7B-4CEA-92B7-EC66EA309187} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F8DDA7A1-8D46-4A63-B330-FE618C7F5CE7} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{F9E0F77A-FE74-4BF2-9748-B0AE182ECB43} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FA06A819-A287-4625-B41D-A058A2142F51} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FA8125B9-6CFB-4268-B0EE-C6265EBFEBB9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FAEF3F72-10B1-4712-BB2C-00DF6BCD96DD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FB5FFA69-65D5-4F81-B392-A2BCFF5976DF} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FC0DE1AF-B02B-443D-B121-D0BF25771D15} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FCD4718A-5CC3-4358-920E-2FB0155662D2} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FD3CDB93-2DAA-4D49-ACF6-1B7789495810} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FD8465FF-76E3-4492-920C-D8989FC37CE8} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FDB45767-0D61-4CBA-B17C-9FDC941D9CA4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FDC2F7C4-7CD2-42C1-975A-168F9FEF00B9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FDD15A1D-0583-4976-8A89-8CE56B07F4D9} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FDF59BBE-F582-4289-AACB-D444946D696D} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FE37011B-57AB-45CA-B649-509F3380E7FD} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FE3E09DA-F419-4DE8-93A9-08F2C5C1A47F} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FE775748-33A9-4036-9AB4-8F55A005D66E} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FF4FA75D-DD56-453E-94F9-B1FF374B1462} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FF724790-1D84-4111-92F3-BFBB022AB2D4} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{FFF55794-147F-4FFC-80E2-E29157D28EC5} ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted: [Folder] C:\Users\Martin\AppData\Roaming\mozilla\firefox\profiles\cz4vwqy8.default\smartbar Emptied folder: C:\Users\Martin\AppData\Roaming\mozilla\firefox\profiles\cz4vwqy8.default\minidumps [94 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 14.12.2014 at 14:08:08,53 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
14.12.2014, 20:41 | #9 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozentESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.12.2014, 18:52 | #10 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozent eine zusätzlich frage wenn eset was findet soll das dann gelöscht werden oder einfach auch beenden? also fertig stellen dann am ende ok frage beantwortet durch die bildanleitung wer lesen kann ist klar im vorteil Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=dade0bca4741d84e96719a9c49e2e8c7 # engine=21551 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-12-15 05:11:54 # local_time=2014-12-15 06:11:54 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 150022 163172492 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 98550 256153042 0 0 # scanned=279632 # found=10 # cleaned=0 # scan_time=21440 sh=97BCCD25561F44E9B13F05F6EEF083C9CE9BA529 ft=1 fh=641f1fb3d2e699c4 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir" sh=45349D99BA9A99F47EC6DE5F0E9E86F6F47E47A2 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\user.js.vir" sh=B81F39785036CE43E9666210252F22C9F4DC3C51 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\prefs.js" sh=B850F2383B165D5AD84F0E4008B90711DAC37258 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\prefs.js.BAK" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\Burnout Paradise\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\Burnout Paradise\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=AEE0B5F1AE8564D7E4CCD032EDF7AD88339BFF4E ft=1 fh=88c3bdc65b0afccf vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\Contacts\Saved Games\Downloads\ASUS_X71_X71SL_Treiber_Update_10-2014.exe" sh=04B1C6FF4F297271D364497B4D1EF3613E3BFAB0 ft=1 fh=1e8dae053b500af2 vn="Variante von Win32/BSDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\Contacts\Saved Games\Downloads\Brothersoft_downloader_For_Dragon_Age.exe" sh=BF1815D99F69EC6B4AAD1C861E65BF2DD43A5B2E ft=1 fh=832a0a7525b94e9d vn="Win32/SoftonicDownloader.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\Contacts\Saved Games\Downloads\SoftonicDownloader_fuer_command-conquer-3-tiberium-wars.exe" sh=D1A1D234F53A02EC73EBC18F593464F0171284C3 ft=1 fh=fc6d56b5f6d6d647 vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Martin\Contacts\Saved Games\Downloads\SoftonicDownloader_fuer_dragon-age-2-rise-to-power.exe" UNSUPPORTED OPERATING SYSTEM! ABORTED! FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2014 02 Ran by Martin (administrator) on MARTIN-PC on 15-12-2014 10:51:35 Running from c:\Users\Martin\Contacts\saved games\downloads Loaded Profile: Martin (Available profiles: Martin) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files\ATK Hotkey\AsLdrSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATK Hotkey\MsgTranAgt.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe () C:\Program Files\ATK Hotkey\WDC.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ATKOSD2\ATKOSD2.exe [7737344 2007-10-17] () HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [61440 2006-11-02] (ASUSTeK Computer INC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [icq] => C:\Users\Martin\AppData\Roaming\ICQM\icq.exe [27453288 2013-03-16] (ICQ) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation) Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation) Winsock: Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog5 06 C:\Windows\system32\winrnr.dll [19968] (Microsoft Corporation) Winsock: Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 25 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 26 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 27 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 28 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 29 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 30 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1948944073-1962714127-1447560850-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\abs@avira.com [2014-10-21] FF Extension: DownloadHelper - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-05-23] FF Extension: Green Fox - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{d122ad80-ff45-11dd-87af-0800200c9a66} [2013-10-21] FF Extension: 1-Click YouTube Video Downloader - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-05-24] FF Extension: In The Dark - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{86FA6F53-95FE-7A69-D8C3-E1454281F8B6}.xpi [2013-10-21] FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-08-06] FF Extension: BlockSite - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}.xpi [2012-09-27] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-10-16] FF HKLM\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found] Chrome: ======= CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-04-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-02] () [File not signed] R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] () [File not signed] R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] S2 Util Higher Aurum; "C:\Program Files\Higher Aurum\bin\utilHigherAurum.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-07-25] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-29] (Disc Soft Ltd) S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [49528 2012-07-26] (G Data Software AG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-07-25] () R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-04-12] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 USBAAPL; System32\Drivers\usbaapl.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 00:11 - 2014-12-15 00:11 - 00000000 ____D () C:\Program Files\ESET 2014-12-14 19:27 - 2014-12-14 19:27 - 00000000 ____D () C:\Users\Martin\AppData\Local\Criterion Games 2014-12-14 17:36 - 2014-12-14 17:36 - 00003034 _____ () C:\Windows\system32\ealregsnapshot1.reg 2014-12-14 17:18 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-12-14 17:18 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-12-14 17:18 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-12-14 17:18 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-12-14 17:18 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-12-14 17:18 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-12-14 17:18 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-12-14 17:18 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-12-14 17:18 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-12-14 17:18 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-12-14 17:18 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-12-14 17:18 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-12-14 17:18 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-12-14 17:18 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-12-14 17:18 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-12-14 17:18 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-12-14 17:18 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-12-14 17:18 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-12-14 17:18 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-12-14 17:18 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-12-14 17:18 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-12-14 17:18 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-12-14 17:18 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-12-14 17:17 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-12-14 17:17 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-12-14 17:17 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-12-14 17:17 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-12-14 17:17 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-12-14 17:17 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-12-14 17:17 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-12-14 17:17 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-12-14 17:17 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-12-14 17:17 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-12-14 17:17 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-12-14 17:17 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-12-14 17:17 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-12-14 17:17 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-12-14 17:17 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-12-14 17:17 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-12-14 17:17 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-12-14 17:17 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-12-14 17:17 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-12-14 17:17 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-12-14 17:17 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-12-14 17:17 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-12-14 17:17 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-12-14 17:17 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-12-14 17:17 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-12-14 17:17 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-12-14 17:17 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-12-14 13:55 - 2014-12-14 13:55 - 00000000 ____D () C:\Windows\ERUNT 2014-12-14 13:43 - 2014-12-14 13:56 - 00000000 ____D () C:\AdwCleaner 2014-12-14 13:31 - 2014-12-14 13:31 - 00000374 _____ () C:\mbam.txt 2014-12-14 13:07 - 2014-12-14 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-14 13:07 - 2014-12-14 13:07 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-12-14 13:07 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-14 13:07 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-14 11:25 - 2014-12-14 11:25 - 00000000 ____D () C:\Users\Martin\Burnout.Paradise.The.Ultimate.Box.1.1.0.0.Only.Crack-BAT 2014-12-14 10:46 - 2014-12-14 11:25 - 00000000 ____D () C:\Users\Martin\Burnout Paradise 2014-12-14 02:49 - 2014-11-07 02:33 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-14 02:49 - 2014-11-04 01:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-14 02:38 - 2014-12-03 03:06 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-12-14 02:37 - 2014-11-24 21:44 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-12-14 02:37 - 2014-11-24 21:41 - 12369920 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-14 02:37 - 2014-11-24 21:40 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-14 02:37 - 2014-11-24 21:37 - 09740800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-14 02:37 - 2014-11-24 21:35 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-14 02:37 - 2014-11-24 21:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-14 02:37 - 2014-11-24 21:34 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-14 02:37 - 2014-11-24 21:34 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-14 02:37 - 2014-11-24 21:33 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-14 02:37 - 2014-11-24 21:32 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-12-14 02:37 - 2014-11-24 21:32 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-12-14 02:17 - 2014-12-14 02:17 - 00000000 ____D () C:\Program Files\Microsoft ATS 2014-12-13 16:21 - 2014-12-13 16:21 - 00021397 _____ () C:\ComboFix.txt 2014-12-13 15:49 - 2014-12-13 16:21 - 00000000 ____D () C:\Qoobox 2014-12-13 15:49 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-12-13 15:49 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-12-13 15:49 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-13 15:48 - 2014-12-13 16:17 - 00000000 ____D () C:\Windows\erdnt 2014-12-13 15:42 - 2014-12-13 15:42 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-12-12 16:59 - 2014-12-12 16:59 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z 2014-12-12 16:59 - 2014-12-12 16:59 - 00000000 ____D () C:\Program Files\GPU-Z 2014-12-12 16:35 - 2014-12-15 10:51 - 00000000 ____D () C:\FRST 2014-12-12 15:15 - 2014-12-14 13:07 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-12 15:14 - 2014-12-14 13:07 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-12 15:14 - 2014-12-12 20:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-12-12 15:13 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-12 14:04 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-12-12 14:03 - 2014-10-10 02:01 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-12-12 14:03 - 2014-10-10 00:22 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-12-12 13:58 - 2014-10-24 02:04 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-12-12 13:58 - 2014-10-24 02:03 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-12-12 13:56 - 2014-08-12 03:25 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-12-12 13:54 - 2014-10-18 02:08 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-12-12 13:54 - 2014-10-03 02:18 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-12-12 13:53 - 2014-09-05 00:27 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-12-12 13:52 - 2014-12-12 13:52 - 00000853 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-12 13:50 - 2014-12-12 13:50 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-12-12 13:50 - 2014-12-12 13:49 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-12-12 13:43 - 2014-10-13 00:34 - 02054656 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 09:59 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-15 09:59 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-15 03:14 - 2011-10-16 05:43 - 01719454 _____ () C:\Windows\WindowsUpdate.log 2014-12-15 00:49 - 2011-10-15 21:15 - 00092672 _____ () C:\Users\Martin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-14 18:21 - 2012-07-18 11:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-14 17:56 - 2006-11-02 11:33 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-14 17:36 - 2012-07-26 00:54 - 00000000 ____D () C:\Users\Martin\AppData\Local\Downloaded Installations 2014-12-14 17:35 - 2011-10-15 22:47 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-12-14 17:32 - 2012-03-05 05:22 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA.job 2014-12-14 17:26 - 2012-10-03 13:31 - 00000000 ___RD () C:\Users\Martin\desk 2014-12-14 17:18 - 2013-07-17 18:06 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-12-14 14:32 - 2012-03-05 05:22 - 00001120 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core.job 2014-12-14 14:00 - 2011-10-16 15:07 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-12-14 13:59 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-14 13:58 - 2008-01-21 03:47 - 00543150 _____ () C:\Windows\PFRO.log 2014-12-14 13:58 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32 2014-12-14 13:57 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-14 11:25 - 2011-10-15 20:54 - 00000000 ____D () C:\Users\Martin 2014-12-14 10:35 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2014-12-14 03:21 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-12-14 02:44 - 2013-07-17 17:50 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-14 02:40 - 2006-11-02 11:24 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-12-14 02:35 - 2011-10-15 21:04 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-12-14 02:30 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-12-14 02:30 - 2012-04-11 17:38 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype 2014-12-14 02:29 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Steam 2014-12-14 01:51 - 2012-09-02 14:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\vlc 2014-12-13 16:21 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default 2014-12-13 16:21 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2014-12-13 16:14 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini 2014-12-13 01:34 - 2013-10-09 12:40 - 00000000 ___RD () C:\Users\Martin\Dropbox 2014-12-12 23:11 - 2013-10-09 12:31 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Dropbox 2014-12-12 22:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-12-12 16:24 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\L2Schemas 2014-12-12 16:05 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-12-12 15:45 - 2013-10-09 12:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-12-12 15:21 - 2012-07-18 11:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-12-12 15:21 - 2011-10-15 22:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-12-12 15:05 - 2011-11-16 21:08 - 00000000 ____D () C:\Users\Martin\AppData\Local\Adobe 2014-12-12 14:16 - 2014-10-21 13:58 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 14:15 - 2013-04-12 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 14:15 - 2013-04-12 02:54 - 00000000 ____D () C:\Program Files\Avira 2014-12-12 14:10 - 2006-11-02 13:47 - 00240296 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-12 14:08 - 2012-05-16 10:30 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-12-12 13:52 - 2014-09-11 21:38 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-12-12 13:52 - 2011-10-15 21:10 - 00000865 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-12 13:50 - 2013-11-04 22:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-12-12 13:49 - 2011-10-15 22:26 - 00000000 ____D () C:\Program Files\Java 2014-12-12 13:31 - 2011-11-16 14:19 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-12-12 13:25 - 2014-11-05 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2014-12-12 13:25 - 2011-11-10 21:56 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-12-12 13:25 - 2011-11-10 21:28 - 00000000 ____D () C:\Program Files\DivX 2014-12-12 13:25 - 2011-11-10 21:27 - 00000000 ____D () C:\ProgramData\DivX 2014-11-24 14:04 - 2011-10-16 11:25 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ZeroAccess: C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22}\n ZeroAccess: C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\@ Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\temp\avgnt.exe C:\Users\Martin\AppData\Local\temp\Quarantine.exe C:\Users\Martin\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 02:07 ==================== End Of Log ============================ --- --- --- --- --- --- also es läuft auf jeden um vieles besser als vorher dafür schonmal in aller form danke |
15.12.2014, 21:20 | #11 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.12.2014, 19:25 | #12 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozent jetzt ne dofe frage warum erst deinstalieren dann zurücksetzen denke das das ein downloadlink sein sollte wenn ja mache ich den download einfach über die herstellerseite oder wenn das nicht so gemeint war dann erkläre mir bitte was ich da machen soll FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2014 02 Ran by Martin (administrator) on MARTIN-PC on 15-12-2014 21:53:45 Running from c:\Users\Martin\Contacts\saved games\downloads Loaded Profile: Martin (Available profiles: Martin) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files\ATK Hotkey\AsLdrSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\ScanToPCActivationApp.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATK Hotkey\MsgTranAgt.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ATK) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPNetworkCommunicator.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ATKOSD2\ATKOSD2.exe [7737344 2007-10-17] () HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [61440 2006-11-02] (ASUSTeK Computer INC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [icq] => C:\Users\Martin\AppData\Roaming\ICQM\icq.exe [27453288 2013-03-16] (ICQ) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [HP Officejet 6500 E710a-f (NET)] => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\RunOnce: [Adobe Speed Launcher] => 1418676051 ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation) Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation) Winsock: Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog5 06 C:\Windows\system32\winrnr.dll [19968] (Microsoft Corporation) Winsock: Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 25 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 26 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 27 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 28 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 29 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 30 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1948944073-1962714127-1447560850-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Extension: Avira Browser Safety - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\abs@avira.com [2014-10-21] FF Extension: DownloadHelper - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-05-23] FF Extension: Green Fox - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{d122ad80-ff45-11dd-87af-0800200c9a66} [2013-10-21] FF Extension: 1-Click YouTube Video Downloader - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-05-24] FF Extension: In The Dark - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{86FA6F53-95FE-7A69-D8C3-E1454281F8B6}.xpi [2013-10-21] FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-08-06] FF Extension: BlockSite - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cz4vwqy8.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}.xpi [2012-09-27] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-10-16] FF HKLM\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found] Chrome: ======= CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-04-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-02] () [File not signed] R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] () [File not signed] R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] S2 Util Higher Aurum; "C:\Program Files\Higher Aurum\bin\utilHigherAurum.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-07-25] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-29] (Disc Soft Ltd) S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [49528 2012-07-26] (G Data Software AG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-07-25] () R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-04-12] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 USBAAPL; System32\Drivers\usbaapl.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 12:10 - 2014-12-15 12:10 - 00000773 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk 2014-12-15 12:09 - 2014-12-15 12:09 - 00002158 _____ () C:\Users\Public\Desktop\HP Officejet 6500 E710a-f.lnk 2014-12-15 12:09 - 2014-12-15 12:09 - 00001090 _____ () C:\Users\Public\Desktop\Shop für Zubehör - HP Officejet 6500 E710a-f.lnk 2014-12-15 12:09 - 2014-12-15 12:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\HpUpdate 2014-12-15 12:09 - 2014-12-15 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-12-15 12:09 - 2012-10-17 04:04 - 00580712 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPM5512.dll 2014-12-15 12:03 - 2014-12-15 12:10 - 00000000 ____D () C:\Program Files\HP 2014-12-15 12:03 - 2014-12-15 12:03 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-12-15 12:03 - 2014-12-15 12:03 - 00000000 ____D () C:\ProgramData\HP 2014-12-15 12:02 - 2014-12-15 12:12 - 00000000 ____D () C:\Users\Martin\AppData\Local\HP 2014-12-15 00:11 - 2014-12-15 00:11 - 00000000 ____D () C:\Program Files\ESET 2014-12-14 19:27 - 2014-12-14 19:27 - 00000000 ____D () C:\Users\Martin\AppData\Local\Criterion Games 2014-12-14 17:36 - 2014-12-14 17:36 - 00003034 _____ () C:\Windows\system32\ealregsnapshot1.reg 2014-12-14 17:18 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-12-14 17:18 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-12-14 17:18 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-12-14 17:18 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-12-14 17:18 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-12-14 17:18 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-12-14 17:18 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-12-14 17:18 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-12-14 17:18 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-12-14 17:18 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-12-14 17:18 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-12-14 17:18 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-12-14 17:18 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-12-14 17:18 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-12-14 17:18 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-12-14 17:18 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-12-14 17:18 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-12-14 17:18 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-12-14 17:18 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-12-14 17:18 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-12-14 17:18 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-12-14 17:18 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-12-14 17:18 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-12-14 17:17 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-12-14 17:17 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-12-14 17:17 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-12-14 17:17 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-12-14 17:17 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-12-14 17:17 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-12-14 17:17 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-12-14 17:17 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-12-14 17:17 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-12-14 17:17 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-12-14 17:17 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-12-14 17:17 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-12-14 17:17 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-12-14 17:17 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-12-14 17:17 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-12-14 17:17 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-12-14 17:17 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-12-14 17:17 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-12-14 17:17 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-12-14 17:17 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-12-14 17:17 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-12-14 17:17 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-12-14 17:17 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-12-14 17:17 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-12-14 17:17 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-12-14 17:17 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-12-14 17:17 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-12-14 13:55 - 2014-12-14 13:55 - 00000000 ____D () C:\Windows\ERUNT 2014-12-14 13:43 - 2014-12-14 13:56 - 00000000 ____D () C:\AdwCleaner 2014-12-14 13:31 - 2014-12-14 13:31 - 00000374 _____ () C:\mbam.txt 2014-12-14 13:07 - 2014-12-14 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-14 13:07 - 2014-12-14 13:07 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-12-14 13:07 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-14 13:07 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-14 11:25 - 2014-12-14 11:25 - 00000000 ____D () C:\Users\Martin\Burnout.Paradise.The.Ultimate.Box.1.1.0.0.Only.Crack-BAT 2014-12-14 10:46 - 2014-12-14 11:25 - 00000000 ____D () C:\Users\Martin\Burnout Paradise 2014-12-14 02:49 - 2014-11-07 02:33 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-14 02:49 - 2014-11-04 01:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-14 02:38 - 2014-12-03 03:06 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-12-14 02:37 - 2014-11-24 21:44 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-12-14 02:37 - 2014-11-24 21:41 - 12369920 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-14 02:37 - 2014-11-24 21:40 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-14 02:37 - 2014-11-24 21:37 - 09740800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-14 02:37 - 2014-11-24 21:35 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-14 02:37 - 2014-11-24 21:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-14 02:37 - 2014-11-24 21:34 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-14 02:37 - 2014-11-24 21:34 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-14 02:37 - 2014-11-24 21:33 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-14 02:37 - 2014-11-24 21:32 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-12-14 02:37 - 2014-11-24 21:32 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-12-14 02:17 - 2014-12-14 02:17 - 00000000 ____D () C:\Program Files\Microsoft ATS 2014-12-13 16:21 - 2014-12-13 16:21 - 00021397 _____ () C:\ComboFix.txt 2014-12-13 15:49 - 2014-12-13 16:21 - 00000000 ____D () C:\Qoobox 2014-12-13 15:49 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-12-13 15:49 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-12-13 15:49 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-13 15:48 - 2014-12-13 16:17 - 00000000 ____D () C:\Windows\erdnt 2014-12-13 15:42 - 2014-12-13 15:42 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-12-12 16:59 - 2014-12-12 16:59 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z 2014-12-12 16:59 - 2014-12-12 16:59 - 00000000 ____D () C:\Program Files\GPU-Z 2014-12-12 16:35 - 2014-12-15 21:53 - 00000000 ____D () C:\FRST 2014-12-12 15:15 - 2014-12-14 13:07 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-12 15:14 - 2014-12-14 13:07 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-12 15:14 - 2014-12-12 20:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-12-12 15:13 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-12 14:04 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-12-12 14:03 - 2014-10-10 02:01 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-12-12 14:03 - 2014-10-10 00:22 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-12-12 13:58 - 2014-10-24 02:04 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-12-12 13:58 - 2014-10-24 02:03 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-12-12 13:56 - 2014-08-12 03:25 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-12-12 13:54 - 2014-10-18 02:08 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-12-12 13:54 - 2014-10-03 02:18 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-12-12 13:53 - 2014-09-05 00:27 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-12-12 13:50 - 2014-12-12 13:50 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-12-12 13:50 - 2014-12-12 13:49 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-12-12 13:43 - 2014-10-13 00:34 - 02054656 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 21:51 - 2011-10-20 11:39 - 00000000 ____D () C:\Users\Martin\AppData\Local\Windows Live 2014-12-15 21:21 - 2012-07-18 11:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-15 20:54 - 2011-10-16 05:43 - 01732220 _____ () C:\Windows\WindowsUpdate.log 2014-12-15 20:49 - 2008-01-21 03:47 - 00545204 _____ () C:\Windows\PFRO.log 2014-12-15 20:49 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-15 20:49 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-15 20:49 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-15 20:48 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-15 12:09 - 2011-10-15 20:54 - 00000000 ____D () C:\Users\Martin 2014-12-15 12:03 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32 2014-12-15 00:49 - 2011-10-15 21:15 - 00092672 _____ () C:\Users\Martin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-14 17:56 - 2006-11-02 11:33 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-14 17:36 - 2012-07-26 00:54 - 00000000 ____D () C:\Users\Martin\AppData\Local\Downloaded Installations 2014-12-14 17:35 - 2011-10-15 22:47 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-12-14 17:32 - 2012-03-05 05:22 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA.job 2014-12-14 17:26 - 2012-10-03 13:31 - 00000000 ___RD () C:\Users\Martin\desk 2014-12-14 17:18 - 2013-07-17 18:06 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-12-14 14:32 - 2012-03-05 05:22 - 00001120 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core.job 2014-12-14 14:00 - 2011-10-16 15:07 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-12-14 10:35 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2014-12-14 03:21 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-12-14 02:44 - 2013-07-17 17:50 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-14 02:40 - 2006-11-02 11:24 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-12-14 02:35 - 2011-10-15 21:04 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-12-14 02:30 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-12-14 02:30 - 2012-04-11 17:38 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype 2014-12-14 02:29 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Steam 2014-12-14 01:51 - 2012-09-02 14:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\vlc 2014-12-13 16:21 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default 2014-12-13 16:21 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2014-12-13 16:14 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini 2014-12-13 01:34 - 2013-10-09 12:40 - 00000000 ___RD () C:\Users\Martin\Dropbox 2014-12-12 23:11 - 2013-10-09 12:31 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Dropbox 2014-12-12 22:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-12-12 16:24 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\L2Schemas 2014-12-12 16:05 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-12-12 15:45 - 2013-10-09 12:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-12-12 15:21 - 2012-07-18 11:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-12-12 15:21 - 2011-10-15 22:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-12-12 15:05 - 2011-11-16 21:08 - 00000000 ____D () C:\Users\Martin\AppData\Local\Adobe 2014-12-12 14:16 - 2014-10-21 13:58 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 14:15 - 2013-04-12 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 14:15 - 2013-04-12 02:54 - 00000000 ____D () C:\Program Files\Avira 2014-12-12 14:10 - 2006-11-02 13:47 - 00240296 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-12 13:50 - 2013-11-04 22:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-12-12 13:49 - 2011-10-15 22:26 - 00000000 ____D () C:\Program Files\Java 2014-12-12 13:31 - 2011-11-16 14:19 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-12-12 13:25 - 2014-11-05 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2014-12-12 13:25 - 2011-11-10 21:56 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-12-12 13:25 - 2011-11-10 21:28 - 00000000 ____D () C:\Program Files\DivX 2014-12-12 13:25 - 2011-11-10 21:27 - 00000000 ____D () C:\ProgramData\DivX 2014-11-24 14:04 - 2011-10-16 11:25 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ZeroAccess: C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22}\n ZeroAccess: C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\@ Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\temp\avgnt.exe C:\Users\Martin\AppData\Local\temp\Quarantine.exe C:\Users\Martin\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 21:04 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- erster log ohne zweiter nach Neuinstallation und zurücksetzen firefox FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2014 02 Ran by Martin (administrator) on MARTIN-PC on 15-12-2014 22:01:14 Running from c:\Users\Martin\Contacts\saved games\downloads Loaded Profile: Martin (Available profiles: Martin) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files\ATK Hotkey\AsLdrSrv.exe () C:\Program Files\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (ASUS) C:\Program Files\ASUS\SmartLogon\sensorsrv.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdSync.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\ScanToPCActivationApp.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe () C:\Program Files\ATK Hotkey\MsgTranAgt.exe (ATK) C:\Program Files\ASUS\Splendid\ACMON.exe (ATK) C:\Program Files\P4G\BatteryLife.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (ASUSTeK) C:\Windows\System32\ACEngSvr.exe () C:\Program Files\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPNetworkCommunicator.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ATKOSD2] => C:\Program Files\ATKOSD2\ATKOSD2.exe [7737344 2007-10-17] () HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [61440 2006-11-02] (ASUSTeK Computer INC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor) HKLM\...\Run: [Windows Mobile-based device management] => C:\Windows\WindowsMobile\wmdSync.exe [215552 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [icq] => C:\Users\Martin\AppData\Roaming\ICQM\icq.exe [27453288 2013-03-16] (ICQ) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Run: [HP Officejet 6500 E710a-f (NET)] => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\RunOnce: [Adobe Speed Launcher] => 1418676051 ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1948944073-1962714127-1447560850-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation) Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation) Winsock: Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation) Winsock: Catalog5 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog5 06 C:\Windows\system32\winrnr.dll [19968] (Microsoft Corporation) Winsock: Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 23 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 24 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 25 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 26 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 27 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 28 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 29 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Winsock: Catalog9 30 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\g54jn8mp.default-1418677152781 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.19 -> C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1948944073-1962714127-1447560850-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Martin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-10-16] FF HKLM\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 FF HKU\S-1-5-21-1948944073-1962714127-1447560850-1000\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Martin\AppData\Roaming\14001.012 Chrome: ======= CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-04-06] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-12-12] (Avira Operations GmbH & Co. KG) R2 ASLDRService; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [94208 2007-10-02] () [File not signed] R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-07] () [File not signed] R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed] S2 Util Higher Aurum; "C:\Program Files\Higher Aurum\bin\utilHigherAurum.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ASMMAP; C:\Program Files\ATKGFNEX\ASMMAP.sys [13880 2007-07-24] () R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2013-07-25] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-21] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-26] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-29] (Disc Soft Ltd) S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [49528 2012-07-26] (G Data Software AG) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2013-07-25] () R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1769984 2007-10-01] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-04-12] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 ipswuio; System32\DRIVERS\ipswuio.sys [X] S3 massfilter; system32\drivers\massfilter.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S3 USBAAPL; System32\Drivers\usbaapl.sys [X] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 21:57 - 2014-12-15 21:57 - 00000865 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-15 21:57 - 2014-12-15 21:57 - 00000853 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-15 21:57 - 2014-12-15 21:57 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-12-15 21:57 - 2014-12-15 21:57 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-12-15 12:10 - 2014-12-15 12:10 - 00000773 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR-Registrierung.lnk 2014-12-15 12:09 - 2014-12-15 12:09 - 00002158 _____ () C:\Users\Public\Desktop\HP Officejet 6500 E710a-f.lnk 2014-12-15 12:09 - 2014-12-15 12:09 - 00001090 _____ () C:\Users\Public\Desktop\Shop für Zubehör - HP Officejet 6500 E710a-f.lnk 2014-12-15 12:09 - 2014-12-15 12:09 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\HpUpdate 2014-12-15 12:09 - 2014-12-15 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2014-12-15 12:09 - 2012-10-17 04:04 - 00580712 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPM5512.dll 2014-12-15 12:03 - 2014-12-15 12:10 - 00000000 ____D () C:\Program Files\HP 2014-12-15 12:03 - 2014-12-15 12:03 - 00000057 _____ () C:\ProgramData\Ament.ini 2014-12-15 12:03 - 2014-12-15 12:03 - 00000000 ____D () C:\ProgramData\HP 2014-12-15 12:02 - 2014-12-15 12:12 - 00000000 ____D () C:\Users\Martin\AppData\Local\HP 2014-12-15 00:11 - 2014-12-15 00:11 - 00000000 ____D () C:\Program Files\ESET 2014-12-14 19:27 - 2014-12-14 19:27 - 00000000 ____D () C:\Users\Martin\AppData\Local\Criterion Games 2014-12-14 17:36 - 2014-12-14 17:36 - 00003034 _____ () C:\Windows\system32\ealregsnapshot1.reg 2014-12-14 17:18 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-12-14 17:18 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-12-14 17:18 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-12-14 17:18 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-12-14 17:18 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-12-14 17:18 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-12-14 17:18 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-12-14 17:18 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-12-14 17:18 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-12-14 17:18 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-12-14 17:18 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-12-14 17:18 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-12-14 17:18 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-12-14 17:18 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-12-14 17:18 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-12-14 17:18 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-12-14 17:18 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-12-14 17:18 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-12-14 17:18 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-12-14 17:18 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-12-14 17:18 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-12-14 17:18 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-12-14 17:18 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-12-14 17:18 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-12-14 17:18 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-12-14 17:18 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-12-14 17:17 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-12-14 17:17 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-12-14 17:17 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll 2014-12-14 17:17 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-12-14 17:17 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-12-14 17:17 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-12-14 17:17 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-12-14 17:17 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-12-14 17:17 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-12-14 17:17 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-12-14 17:17 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-12-14 17:17 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-12-14 17:17 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-12-14 17:17 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-12-14 17:17 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-12-14 17:17 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-12-14 17:17 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-12-14 17:17 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-12-14 17:17 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-12-14 17:17 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-12-14 17:17 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-12-14 17:17 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-12-14 17:17 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-12-14 17:17 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-12-14 17:17 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-12-14 17:17 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-12-14 17:17 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-12-14 13:55 - 2014-12-14 13:55 - 00000000 ____D () C:\Windows\ERUNT 2014-12-14 13:43 - 2014-12-14 13:56 - 00000000 ____D () C:\AdwCleaner 2014-12-14 13:31 - 2014-12-14 13:31 - 00000374 _____ () C:\mbam.txt 2014-12-14 13:07 - 2014-12-14 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-12-14 13:07 - 2014-12-14 13:07 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-12-14 13:07 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-12-14 13:07 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-12-14 11:25 - 2014-12-14 11:25 - 00000000 ____D () C:\Users\Martin\Burnout.Paradise.The.Ultimate.Box.1.1.0.0.Only.Crack-BAT 2014-12-14 10:46 - 2014-12-14 11:25 - 00000000 ____D () C:\Users\Martin\Burnout Paradise 2014-12-14 02:49 - 2014-11-07 02:33 - 00974848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-14 02:49 - 2014-11-04 01:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-14 02:38 - 2014-12-03 03:06 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-12-14 02:37 - 2014-11-24 21:44 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-12-14 02:37 - 2014-11-24 21:41 - 12369920 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-14 02:37 - 2014-11-24 21:40 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-14 02:37 - 2014-11-24 21:37 - 09740800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-14 02:37 - 2014-11-24 21:35 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-14 02:37 - 2014-11-24 21:35 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-14 02:37 - 2014-11-24 21:34 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-14 02:37 - 2014-11-24 21:34 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-14 02:37 - 2014-11-24 21:33 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-14 02:37 - 2014-11-24 21:33 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-14 02:37 - 2014-11-24 21:32 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-14 02:37 - 2014-11-24 21:32 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-12-14 02:37 - 2014-11-24 21:32 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-12-14 02:17 - 2014-12-14 02:17 - 00000000 ____D () C:\Program Files\Microsoft ATS 2014-12-13 16:21 - 2014-12-13 16:21 - 00021397 _____ () C:\ComboFix.txt 2014-12-13 15:49 - 2014-12-13 16:21 - 00000000 ____D () C:\Qoobox 2014-12-13 15:49 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-12-13 15:49 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-12-13 15:49 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-12-13 15:49 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-12-13 15:48 - 2014-12-13 16:17 - 00000000 ____D () C:\Windows\erdnt 2014-12-13 15:42 - 2014-12-13 15:42 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-12-12 16:59 - 2014-12-12 16:59 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z 2014-12-12 16:59 - 2014-12-12 16:59 - 00000000 ____D () C:\Program Files\GPU-Z 2014-12-12 16:35 - 2014-12-15 22:01 - 00000000 ____D () C:\FRST 2014-12-12 15:15 - 2014-12-14 13:07 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-12-12 15:14 - 2014-12-14 13:07 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-12-12 15:14 - 2014-12-12 20:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-12-12 15:13 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-12-12 14:04 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-12-12 14:04 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-12-12 14:03 - 2014-10-10 02:01 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-12-12 14:03 - 2014-10-10 02:00 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-12-12 14:03 - 2014-10-10 00:22 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-12-12 14:00 - 2014-08-27 01:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-12-12 13:58 - 2014-10-24 02:04 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-12-12 13:58 - 2014-10-24 02:03 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-12-12 13:56 - 2014-08-12 03:25 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-12-12 13:54 - 2014-10-18 02:08 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-12-12 13:54 - 2014-10-03 02:18 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-12-12 13:54 - 2014-10-03 02:17 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-12-12 13:53 - 2014-09-05 00:27 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2014-12-12 13:50 - 2014-12-12 13:50 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-12-12 13:50 - 2014-12-12 13:49 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-12-12 13:49 - 2014-12-12 13:49 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-12-12 13:43 - 2014-10-13 00:34 - 02054656 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-15 21:51 - 2011-10-20 11:39 - 00000000 ____D () C:\Users\Martin\AppData\Local\Windows Live 2014-12-15 21:21 - 2012-07-18 11:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-12-15 20:54 - 2011-10-16 05:43 - 01732220 _____ () C:\Windows\WindowsUpdate.log 2014-12-15 20:49 - 2008-01-21 03:47 - 00545204 _____ () C:\Windows\PFRO.log 2014-12-15 20:49 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-15 20:49 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-15 20:49 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-15 20:48 - 2006-11-02 14:01 - 00032540 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-12-15 12:09 - 2011-10-15 20:54 - 00000000 ____D () C:\Users\Martin 2014-12-15 12:03 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32 2014-12-15 00:49 - 2011-10-15 21:15 - 00092672 _____ () C:\Users\Martin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-12-14 17:56 - 2006-11-02 11:33 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-14 17:36 - 2012-07-26 00:54 - 00000000 ____D () C:\Users\Martin\AppData\Local\Downloaded Installations 2014-12-14 17:35 - 2011-10-15 22:47 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-12-14 17:32 - 2012-03-05 05:22 - 00001142 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000UA.job 2014-12-14 17:26 - 2012-10-03 13:31 - 00000000 ___RD () C:\Users\Martin\desk 2014-12-14 17:18 - 2013-07-17 18:06 - 00000000 ____D () C:\Program Files\Electronic Arts 2014-12-14 14:32 - 2012-03-05 05:22 - 00001120 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948944073-1962714127-1447560850-1000Core.job 2014-12-14 14:00 - 2011-10-16 15:07 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-12-14 10:35 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache 2014-12-14 03:21 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\de-DE 2014-12-14 02:44 - 2013-07-17 17:50 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-14 02:40 - 2006-11-02 11:24 - 109818608 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-12-14 02:35 - 2011-10-15 21:04 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-12-14 02:30 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-12-14 02:30 - 2012-04-11 17:38 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Skype 2014-12-14 02:29 - 2012-09-06 21:49 - 00000000 ____D () C:\Program Files\Steam 2014-12-14 01:51 - 2012-09-02 14:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\vlc 2014-12-13 16:21 - 2006-11-02 12:18 - 00000000 __RHD () C:\Users\Default 2014-12-13 16:21 - 2006-11-02 12:18 - 00000000 ___RD () C:\Users\Public 2014-12-13 16:14 - 2006-11-02 11:23 - 00000215 _____ () C:\Windows\system.ini 2014-12-13 01:34 - 2013-10-09 12:40 - 00000000 ___RD () C:\Users\Martin\Dropbox 2014-12-12 23:11 - 2013-10-09 12:31 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Dropbox 2014-12-12 22:43 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-12-12 16:24 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\L2Schemas 2014-12-12 16:05 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-12-12 15:45 - 2013-10-09 12:32 - 00000000 ____D () C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-12-12 15:21 - 2012-07-18 11:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-12-12 15:21 - 2011-10-15 22:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-12-12 15:05 - 2011-11-16 21:08 - 00000000 ____D () C:\Users\Martin\AppData\Local\Adobe 2014-12-12 14:16 - 2014-10-21 13:58 - 00000000 ____D () C:\ProgramData\Package Cache 2014-12-12 14:15 - 2013-04-12 02:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-12-12 14:15 - 2013-04-12 02:54 - 00000000 ____D () C:\Program Files\Avira 2014-12-12 14:10 - 2006-11-02 13:47 - 00240296 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-12-12 13:50 - 2013-11-04 22:35 - 00000000 ____D () C:\ProgramData\Oracle 2014-12-12 13:49 - 2011-10-15 22:26 - 00000000 ____D () C:\Program Files\Java 2014-12-12 13:31 - 2011-11-16 14:19 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-12-12 13:25 - 2014-11-05 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2014-12-12 13:25 - 2011-11-10 21:56 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-12-12 13:25 - 2011-11-10 21:28 - 00000000 ____D () C:\Program Files\DivX 2014-12-12 13:25 - 2011-11-10 21:27 - 00000000 ____D () C:\ProgramData\DivX 2014-11-24 14:04 - 2011-10-16 11:25 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ZeroAccess: C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22}\n ZeroAccess: C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\@ Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\temp\avgnt.exe C:\Users\Martin\AppData\Local\temp\Quarantine.exe C:\Users\Martin\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 21:04 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- also muss sagen jetzt läuft firefox wieder ohne mucken zu machen und schneller ist er selber auch wieder geworden der laptop hat sich denn jetzt alles erledigt oder ist da noch was zu sehen in den letzen beiden logs wünschte könnte das auch selber lesen aber ich verstehe da nur bahnhof |
16.12.2014, 21:57 | #13 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Satzzeichen!!!!! Das kann doch keine Sau lesen! Firefox deinstallieren entfernt nicht alles, deswegen anschliessend nochmal zurücksetzen. Das hat alles schon seinen Sinn
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.12.2014, 22:01 | #14 |
| Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Entschuldige, ja hatte ich gemacht hattest eben nix von download geschrieben sondern nur von deinstalieren und dann zurücksetzen und das war mir dann unschlüssig. Habe dann einen log ohne firefox gemach und einen nach instal. und zurücksetzen gemacht. War da dann nochwas zu finden? würde sowas gerne selber lesen können was in den logs steht aber da bverstehe ich nur bahnhof. So besser? |
17.12.2014, 20:08 | #15 |
/// the machine /// TB-Ausbilder | Bei nutzung von mozila firefox cpu nutzung bei 100 prozent Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ZeroAccess: C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Windows\Installer\{ab275791-70d8-56c6-f53a-376071dbad22}\n ZeroAccess: C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22} C:\Users\Martin\AppData\Local\{ab275791-70d8-56c6-f53a-376071dbad22}\@ Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. Bestehen noch Probleme mit dem System?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Bei nutzung von mozila firefox cpu nutzung bei 100 prozent |
fehlercode 0x5, fehlercode 28, fehlercode 31, fehlercode windows, gescannt, js/securitydisabler.a.gen, nicht mehr, spyhunter, spyhunter entfernen, this device cannot start. (code10), verdacht, win32/softonicdownloader.e, win32/softonicdownloader.f, win32/systweak.h, win32/toolbar.conduit.a, win32/toolbar.conduit.b, win32/toolbar.conduit.y, zusammen |