Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Leistung vom Laptop stark vermindert

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 23.03.2015, 16:10   #16
Maryy
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Hallo. das habe ich hochgeladen.
lg Mary

Alt 23.03.2015, 16:14   #17
M-K-D-B
/// TB-Ausbilder
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Zitat:
Zitat von Maryy Beitrag anzeigen
Hallo. das habe ich hochgeladen.
lg Mary
Da ist nichts angekommen, bitte Anweisung nochmal genau lesen und wiederholen.
__________________


Alt 23.03.2015, 19:39   #18
Maryy
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



jetzt hab ichs nochmal versucht. hat es geklappt?
__________________

Alt 23.03.2015, 22:27   #19
M-K-D-B
/// TB-Ausbilder
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern.
Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg.




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
CloseProcesses:
C:\Users\Jochen_PC\Downloads\ReimageRepair.exe
C:\Users\Jochen_PC\Downloads\ReimageRepair(1).exe
C:\Users\Jochen_PC\AppData\LocalLow\FileConverter_1.3F4
C:\Users\Jochen_PC\AppData\Roaming\Mozilla\Firefox\Profiles\izie2psw.default\CT3241949
C:\Program Files\FileConverter_1.3F4
DeleteKey: HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
DeleteKey: HKEY_CURRENT_USER\Software\reimagerepair
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe
DeleteKey: HKEY_CURRENT_USER\Software\AppDataLow\Software\FileConverter_1.3F4
DeleteKey: HKEY_CURRENT_USER\Software\AppDataLow\Software\SmartBar
DeleteKey: HKEY_CURRENT_USER\Software\FileConverter_1.3F4
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\conduitapps.com
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{012BC931-73D0-4BED-B7B1-0953CA6D1F95}
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{294DFC01-4E5C-40F3-8485-E5A2ED70CB6C}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\FileConverter_1.3F4
File: C:\rei\reimage.qsr
EmptyTemp:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Schritt 2
Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
  • Starte die HitmanPro.exe
  • Klicke auf
  • Entferne den Haken bei
  • Klicke auf
    und
  • Akzeptiere die Lizenzbedingungen und klicke auf
  • Klicke auf

    und auf
  • Wenn der Scan beendet wurde, nichts löschen lassen etc. sondern wähle unten links auf der Button-Leiste
    und speichere die Logdatei auf Deinem Desktop.
  • Schließe HitmanPro und poste mir das Log.

 






Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset






Schritt 4
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei des FRST-Fix,
  • die Logdatei von HitmanPro,
  • die Logdatei von ESET,
  • die Logdatei von SecurityCheck.

Alt 28.03.2015, 13:12   #20
M-K-D-B
/// TB-Ausbilder
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!


Alt 05.04.2015, 15:14   #21
Maryy
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by Jochen_PC at 2015-04-05 15:43:04 Run:4
Running from C:\Users\Jochen_PC\Downloads
Loaded Profiles: Jochen_PC (Available profiles: Jochen_PC)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
start
CloseProcesses:
C:\Users\Jochen_PC\Downloads\ReimageRepair.exe
C:\Users\Jochen_PC\Downloads\ReimageRepair(1).exe
C:\Users\Jochen_PC\AppData\LocalLow\FileConverter_1.3F4
C:\Users\Jochen_PC\AppData\Roaming\Mozilla\Firefox\Profiles\izie2psw.default\CT3241949
C:\Program Files\FileConverter_1.3F4
DeleteKey: HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
DeleteKey: HKEY_CURRENT_USER\Software\reimagerepair
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe
DeleteKey: HKEY_CURRENT_USER\Software\AppDataLow\Software\FileConverter_1.3F4
DeleteKey: HKEY_CURRENT_USER\Software\AppDataLow\Software\SmartBar
DeleteKey: HKEY_CURRENT_USER\Software\FileConverter_1.3F4
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\conduitapps.com
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{012BC931-73D0-4BED-B7B1-0953CA6D1F95}
DeleteKey: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{294DFC01-4E5C-40F3-8485-E5A2ED70CB6C}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\FileConverter_1.3F4
File: C:\rei\reimage.qsr
EmptyTemp:
end
         
*****************

Processes closed successfully.
C:\Users\Jochen_PC\Downloads\ReimageRepair.exe => Moved successfully.
C:\Users\Jochen_PC\Downloads\ReimageRepair(1).exe => Moved successfully.
C:\Users\Jochen_PC\AppData\LocalLow\FileConverter_1.3F4 => Moved successfully.
C:\Users\Jochen_PC\AppData\Roaming\Mozilla\Firefox\Profiles\izie2psw.default\CT3241949 => Moved successfully.
C:\Program Files\FileConverter_1.3F4 => Moved successfully.
HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief. => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief. => Key Deleted Successfully.
HKEY_CURRENT_USER\Software\reimagerepair => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_CURRENT_USER\Software\reimagerepair => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36} => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36} => Key Deleted Successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Reimage.exe => Key Deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\Software\FileConverter_1.3F4 => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_CURRENT_USER\Software\AppDataLow\Software\FileConverter_1.3F4 => Key Deleted Successfully.
HKEY_CURRENT_USER\Software\AppDataLow\Software\SmartBar => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_CURRENT_USER\Software\AppDataLow\Software\SmartBar => Key Deleted Successfully.
HKEY_CURRENT_USER\Software\FileConverter_1.3F4 => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_CURRENT_USER\Software\FileConverter_1.3F4 => Key Deleted Successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\conduitapps.com => Key Deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{012BC931-73D0-4BED-B7B1-0953CA6D1F95} => Key Deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{294DFC01-4E5C-40F3-8485-E5A2ED70CB6C} => Key Deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FileConverter_1.3F4 => Failed to delete key at first attempt (Error: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\FileConverter_1.3F4 => Key Deleted Successfully.

========================= File: C:\rei\reimage.qsr ========================

MD5: 3D36F25BD9088420DE025961B8117559
Creation and modification date: 2014-12-17 12:38 - 2015-02-21 14:54
Size: 0002492
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product Name: 
Description: 
File Version: 
Product Version: 
Copyright: 

====== End Of File: ======

EmptyTemp: => Removed 402.9 MB temporary data.


The system needed a reboot. 

==== End of Fixlog 15:43:25 ====
         
Code:
ATTFilter
HitmanPro 3.7.9.240
www.hitmanpro.com

   Computer name . . . . : ACER-PC
   Windows . . . . . . . : 6.1.1.7601.X86/2
   User name . . . . . . : Acer-PC\Jochen_PC
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Trial (30 days left)

   Scan date . . . . . . : 2015-04-05 15:55:32
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 5m 9s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : Yes

   Threats . . . . . . . : 121
   Traces  . . . . . . . : 227

   Objects scanned . . . : 1.686.533
   Files scanned . . . . : 27.067
   Remnants scanned  . . : 449.633 files / 1.209.833 keys

Malware _____________________________________________________________________

   C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe -> Quarantined
      Size . . . . . . . : 2.135.552 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:46)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : C924C5E0CE37EC6BDB1704152E8F650736B4D18A68B4FC828177124BE8B40326
    > Bitdefender  . . . : Gen:Variant.Application.Kazy.579830
      Fuzzy  . . . . . . : 110.0
      Startup
         C:\Windows\system32\Tasks\avaavxvyex
      Forensic Cluster
         -40.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.6s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.6s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -9.5s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.3s C:\Program Files\SearchProtect\
         -8.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.1s C:\Program Files\SearchProtect\Main\rep\
         -7.1s C:\Program Files\SearchProtect\Main\
         -7.0s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -6.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.6s C:\Program Files\SearchProtect\Main\bin\
         -0.6s C:\Program Files\SearchProtect\EULA.txt
         -0.5s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.3s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.2s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.1s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
          0.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
          0.1s C:\Program Files\SearchProtect\SearchProtect\
          0.1s C:\Program Files\SearchProtect\SearchProtect\bin\
          0.1s C:\Program Files\SearchProtect\SearchProtect\rep\
          0.1s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          1.1s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          1.1s C:\Program Files\SearchProtect\UI\dialogs\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\libs\
          1.1s C:\Program Files\SearchProtect\UI\bin\
          1.1s C:\Program Files\SearchProtect\UI\rep\
          1.1s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Images\
          1.1s C:\Program Files\SearchProtect\UI\
          1.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.4s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.4s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.9s C:\Windows\AppPatch\nbin\
          1.9s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.4s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.7s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.8s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.8s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.9s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         13.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.3s C:\Windows\System32\Tasks\avaavxvyex
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Users\Jochen_PC\Downloads\SweetJava_TSA1XZORP.exe -> Quarantined
      Size . . . . . . . : 736.128 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:42:11)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 9F42552C52E47ECE3C9191306E6CC11E1B16C9020DAB0FDB52D4FC8EE979F741
      Product  . . . . . : Setup.exe
      Publisher  . . . . : ?? 2014 ClientConnect Ltd.
      Description  . . . : Setup.exe
      RSA Key Size . . . : 2048
      LanguageID . . . . : 0
      Authenticode . . . : Valid
    > Kaspersky  . . . . : not-a-virus:WebToolbar.Win32.Agent.avw
      Fuzzy  . . . . . . : 107.0

   C:\Users\Jochen_PC\Downloads\SweetJava_TSA29KJEI.exe -> Quarantined
      Size . . . . . . . : 736.128 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:44:38)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 9F42552C52E47ECE3C9191306E6CC11E1B16C9020DAB0FDB52D4FC8EE979F741
      Product  . . . . . : Setup.exe
      Publisher  . . . . : ?? 2014 ClientConnect Ltd.
      Description  . . . : Setup.exe
      RSA Key Size . . . : 2048
      LanguageID . . . . : 0
      Authenticode . . . : Valid
    > Kaspersky  . . . . : not-a-virus:WebToolbar.Win32.Agent.avw
      Fuzzy  . . . . . . : 107.0
      Forensic Cluster
         -0.8s C:\Users\Jochen_PC\AppData\Roaming\Mozilla\Firefox\Profiles\izie2psw.default\search-metadata.json
          0.0s C:\Users\Jochen_PC\Downloads\SweetJava_TSA29KJEI.exe


Suspicious files ____________________________________________________________

   C:\Program Files\Common Files\Siemens\SWS\plugins\scp\rslibw32.dll
      Size . . . . . . . : 163.840 bytes
      Age  . . . . . . . : 1260.2 days (2011-10-23 11:03:37)
      Entropy  . . . . . : 7.5
      SHA-256  . . . . . : 187C57570D19DCA8C7B3F910662D923F7AF106423C564830E9A7781C9345C927
      Product  . . . . . : RSLIBW32
      Publisher  . . . . : RSLIBW32
      Description  . . . : RSLIBW32
      Version  . . . . . : V1.0.3.20
      Copyright  . . . . : Copyright © 1999
      LanguageID . . . . : 1033
      Fuzzy  . . . . . . : 22.0
         The .reloc (relocation) section in this program contains code. This is an indication of malware infection.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Program is running but currently exposes no human-computer interface (GUI).
         The Entry Point of this file lies in a resource section. This is an indication of malware infection.
         Program contains PE structure anomalies. This is not typical for most programs.
         The file is in use by one or more active processes.
         The file appears to be part of an installation package or setup program. This is typical for most programs.

   C:\Users\Jochen_PC\Downloads\FRST.exe -> Deleted
      Size . . . . . . . : 1.135.104 bytes
      Age  . . . . . . . : 15.1 days (2015-03-21 13:54:13)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 27600BC2D6D1CBBD1FA5BB7A9157ACCCF3A068A6800ED4B6DC50D24A747F6CAB
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 23.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.


Malware remnants ____________________________________________________________

   C:\Program Files\SearchProtect\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\EULA.txt (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\Main\bin\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe (SearchProtect) -> PendingDelete
      Size . . . . . . . : 3.251.472 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:46)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : A6DFA0B8EC49AF131F729969C71B5B1E54759C7B63D4125FB5BAEC6FA8429BA4
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      Service  . . . . . : CltMngSvc
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -10.0
      Startup
         HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\
      Forensic Cluster
         -39.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -38.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -38.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -8.9s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -8.8s C:\Program Files\SearchProtect\
         -7.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -7.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -7.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -6.5s C:\Program Files\SearchProtect\Main\rep\
         -6.5s C:\Program Files\SearchProtect\Main\
         -6.5s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -6.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -5.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -5.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -5.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -5.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.0s C:\Program Files\SearchProtect\Main\bin\
         -0.0s C:\Program Files\SearchProtect\EULA.txt
          0.0s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
          0.3s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
          0.3s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
          0.5s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
          0.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
          0.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
          0.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
          0.6s C:\Program Files\SearchProtect\SearchProtect\
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\
          0.6s C:\Program Files\SearchProtect\SearchProtect\rep\
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.9s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          1.1s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          1.1s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          1.1s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          1.2s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          1.6s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          1.7s C:\Program Files\SearchProtect\UI\dialogs\
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\
          1.7s C:\Program Files\SearchProtect\UI\bin\
          1.7s C:\Program Files\SearchProtect\UI\rep\
          1.7s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\
          1.7s C:\Program Files\SearchProtect\UI\
          1.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.9s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.9s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          2.0s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          2.0s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          2.0s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          2.1s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          2.2s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          2.2s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          2.2s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          2.2s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          2.2s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          2.2s C:\Program Files\SearchProtect\UI\dialogs\protection\
          2.2s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          2.2s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          2.2s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          2.2s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          2.3s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          2.3s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          2.3s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\settings\
          2.3s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          2.3s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          2.3s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          2.3s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          2.3s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          2.3s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          2.3s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          2.4s C:\Windows\AppPatch\nbin\
          2.4s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.9s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          6.3s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          6.3s C:\Program Files\SearchProtect\Main\rep\trn.bin
          6.3s C:\Program Files\SearchProtect\Main\rep\edk.bin
          6.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          6.4s C:\Program Files\SearchProtect\Main\rep\pni.bin
          9.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          9.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          9.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         13.6s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.8s C:\Windows\System32\Tasks\avaavxvyex
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         18.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\Main\bin\SPtool.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 3.016.464 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:46)
      Entropy  . . . . . : 6.8
      SHA-256  . . . . . : 7ECEC18E445D57E750773C1D525263E9B6D27F92CDFC187C19072E1D1AB7D5BE
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -39.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.3s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.3s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -9.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.1s C:\Program Files\SearchProtect\
         -7.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -7.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -7.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -6.8s C:\Program Files\SearchProtect\Main\rep\
         -6.8s C:\Program Files\SearchProtect\Main\
         -6.8s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -6.4s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.3s C:\Program Files\SearchProtect\Main\bin\
         -0.3s C:\Program Files\SearchProtect\EULA.txt
         -0.3s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
          0.0s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
          0.0s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
          0.2s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
          0.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
          0.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
          0.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
          0.3s C:\Program Files\SearchProtect\SearchProtect\
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\
          0.3s C:\Program Files\SearchProtect\SearchProtect\rep\
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.8s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.9s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.9s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.9s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          1.3s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          1.4s C:\Program Files\SearchProtect\UI\dialogs\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\libs\
          1.4s C:\Program Files\SearchProtect\UI\bin\
          1.4s C:\Program Files\SearchProtect\UI\rep\
          1.4s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\
          1.4s C:\Program Files\SearchProtect\UI\
          1.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.6s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.6s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          2.1s C:\Windows\AppPatch\nbin\
          2.1s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.6s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          6.0s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          6.0s C:\Program Files\SearchProtect\Main\rep\trn.bin
          6.0s C:\Program Files\SearchProtect\Main\rep\edk.bin
          6.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          6.2s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         13.3s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.6s C:\Windows\System32\Tasks\avaavxvyex
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\Main\bin\uninstall.exe (SearchProtect) -> PendingDelete
      Size . . . . . . . : 240.400 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:46)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : E9849AB279D2F2F7B75AE875F4A032F60040DFF0A23855ADCFD87E2A9685F18F
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -39.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.5s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.5s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -9.4s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.2s C:\Program Files\SearchProtect\
         -8.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.0s C:\Program Files\SearchProtect\Main\rep\
         -7.0s C:\Program Files\SearchProtect\Main\
         -7.0s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -6.6s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.5s C:\Program Files\SearchProtect\Main\bin\
         -0.5s C:\Program Files\SearchProtect\EULA.txt
         -0.5s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.2s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.2s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
          0.0s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
          0.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
          0.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
          0.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
          0.2s C:\Program Files\SearchProtect\SearchProtect\
          0.2s C:\Program Files\SearchProtect\SearchProtect\bin\
          0.2s C:\Program Files\SearchProtect\SearchProtect\rep\
          0.2s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.4s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.7s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.7s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.7s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.7s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          1.2s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          1.2s C:\Program Files\SearchProtect\UI\dialogs\
          1.2s C:\Program Files\SearchProtect\UI\dialogs\libs\
          1.2s C:\Program Files\SearchProtect\UI\bin\
          1.2s C:\Program Files\SearchProtect\UI\rep\
          1.2s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\
          1.2s C:\Program Files\SearchProtect\UI\
          1.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.5s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.5s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.8s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.8s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.8s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.9s C:\Windows\AppPatch\nbin\
          2.0s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.4s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.8s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.9s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.9s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          6.0s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.6s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.6s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.6s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         13.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.4s C:\Windows\System32\Tasks\avaavxvyex
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\Main\bin\uninstall.pun (SearchProtect) -> PendingDelete
      Size . . . . . . . : 1.294.320 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:46)
      Entropy  . . . . . : 7.9
      SHA-256  . . . . . : 4B9E5FFF2E7F739726549EF17AAFC4BB6E0B8CCFE0BF30A5204F3E83E33A242D
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect Uninstaller
      Version  . . . . . : 2.22.0.160
      RSA Key Size . . . : 2048
      LanguageID . . . . : 0
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -1.0
      Forensic Cluster
         -39.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.4s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.4s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -9.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.1s C:\Program Files\SearchProtect\
         -7.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -7.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -7.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -6.8s C:\Program Files\SearchProtect\Main\rep\
         -6.8s C:\Program Files\SearchProtect\Main\
         -6.8s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -6.4s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -5.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.3s C:\Program Files\SearchProtect\Main\bin\
         -0.3s C:\Program Files\SearchProtect\EULA.txt
         -0.3s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.0s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
          0.0s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
          0.2s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
          0.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
          0.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
          0.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
          0.3s C:\Program Files\SearchProtect\SearchProtect\
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\
          0.3s C:\Program Files\SearchProtect\SearchProtect\rep\
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.8s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.8s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.8s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.9s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          1.3s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          1.4s C:\Program Files\SearchProtect\UI\dialogs\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\libs\
          1.4s C:\Program Files\SearchProtect\UI\bin\
          1.4s C:\Program Files\SearchProtect\UI\rep\
          1.4s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\
          1.4s C:\Program Files\SearchProtect\UI\
          1.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.6s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.6s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.6s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          1.7s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.8s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.9s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          2.0s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          2.0s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          2.0s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          2.0s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          2.1s C:\Windows\AppPatch\nbin\
          2.1s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.6s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          6.0s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          6.0s C:\Program Files\SearchProtect\Main\rep\trn.bin
          6.0s C:\Program Files\SearchProtect\Main\rep\edk.bin
          6.1s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          6.1s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.8s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         13.3s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.5s C:\Windows\System32\Tasks\avaavxvyex
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         18.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\Main\rep\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\Main\rep\cfi.bin (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\Main\rep\edk.bin (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\Main\rep\pni.bin (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\Main\rep\trn.bin (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\SearchProtect\bin\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe (SearchProtect) -> PendingDelete
      Size . . . . . . . : 4.462.864 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:46)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : 20B34439D25B4131B0E1AFF4A285EEA4AC0DC4DF23132B7782FF5C32B4F761F0
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -17.0
      Forensic Cluster
         -40.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -9.6s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.4s C:\Program Files\SearchProtect\
         -8.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.1s C:\Program Files\SearchProtect\Main\rep\
         -7.1s C:\Program Files\SearchProtect\Main\
         -7.1s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -6.8s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.6s C:\Program Files\SearchProtect\Main\bin\
         -0.6s C:\Program Files\SearchProtect\EULA.txt
         -0.6s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.3s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.3s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.2s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -0.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
          0.0s C:\Program Files\SearchProtect\SearchProtect\
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\
          0.0s C:\Program Files\SearchProtect\SearchProtect\rep\
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.2s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          1.0s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          1.0s C:\Program Files\SearchProtect\UI\dialogs\
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\
          1.0s C:\Program Files\SearchProtect\UI\bin\
          1.0s C:\Program Files\SearchProtect\UI\rep\
          1.0s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\
          1.0s C:\Program Files\SearchProtect\UI\
          1.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          1.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.3s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.3s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.5s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.5s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.5s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.7s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.8s C:\Windows\AppPatch\nbin\
          1.8s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.3s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.7s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.7s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.7s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.8s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         13.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.2s C:\Windows\System32\Tasks\avaavxvyex
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 226.064 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : E324F0A0983D708FB3EA8BAB70F2C45B9497BC4D4ED84034110A8342DF03F32A
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -40.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -10.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.9s C:\Program Files\SearchProtect\
         -8.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.7s C:\Program Files\SearchProtect\Main\rep\
         -7.7s C:\Program Files\SearchProtect\Main\
         -7.6s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.3s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -1.2s C:\Program Files\SearchProtect\Main\bin\
         -1.2s C:\Program Files\SearchProtect\EULA.txt
         -1.1s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.9s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.8s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.7s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -0.5s C:\Program Files\SearchProtect\SearchProtect\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\rep\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
         -0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.5s C:\Program Files\SearchProtect\UI\dialogs\
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.5s C:\Program Files\SearchProtect\UI\bin\
          0.5s C:\Program Files\SearchProtect\UI\rep\
          0.5s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.5s C:\Program Files\SearchProtect\UI\
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.8s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\style.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.3s C:\Windows\AppPatch\nbin\
          1.3s C:\Windows\AppPatch\nbin\VC32Loader.dll
          1.8s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.1s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.3s C:\Program Files\SearchProtect\Main\rep\pni.bin
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         12.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         15.7s C:\Windows\System32\Tasks\avaavxvyex
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe (SearchProtect) -> PendingDelete
      Size . . . . . . . : 1.707.792 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 6.4
      SHA-256  . . . . . : 87FB855666CBF1E3DDB1682F199BCF8150FC6E9061C985F08E8D18E15E67B6CC
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -41.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -41.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -40.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -10.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -10.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -10.5s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -10.4s C:\Program Files\SearchProtect\
         -9.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -9.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -9.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -9.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.1s C:\Program Files\SearchProtect\Main\rep\
         -8.1s C:\Program Files\SearchProtect\Main\
         -8.1s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -1.6s C:\Program Files\SearchProtect\Main\bin\
         -1.6s C:\Program Files\SearchProtect\EULA.txt
         -1.6s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -1.3s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -1.3s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -1.2s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -1.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -1.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -1.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -1.0s C:\Program Files\SearchProtect\SearchProtect\
         -1.0s C:\Program Files\SearchProtect\SearchProtect\bin\
         -1.0s C:\Program Files\SearchProtect\SearchProtect\rep\
         -1.0s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -0.8s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.1s C:\Program Files\SearchProtect\UI\dialogs\
          0.1s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.1s C:\Program Files\SearchProtect\UI\bin\
          0.1s C:\Program Files\SearchProtect\UI\rep\
          0.1s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.1s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.1s C:\Program Files\SearchProtect\UI\
          0.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.3s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          0.3s C:\Program Files\SearchProtect\UI\dialogs\style.css
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          0.6s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          0.7s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          0.7s C:\Program Files\SearchProtect\UI\dialogs\settings\
          0.7s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          0.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          0.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          0.7s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          0.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          0.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          0.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          0.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          0.7s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          0.7s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          0.8s C:\Windows\AppPatch\nbin\
          0.8s C:\Windows\AppPatch\nbin\VC32Loader.dll
          1.3s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          4.7s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          4.7s C:\Program Files\SearchProtect\Main\rep\trn.bin
          4.7s C:\Program Files\SearchProtect\Main\rep\edk.bin
          4.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          4.8s C:\Program Files\SearchProtect\Main\rep\pni.bin
          7.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          7.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          7.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         12.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         15.2s C:\Windows\System32\Tasks\avaavxvyex
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         16.8s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 5.752.592 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : F195AC7EA3FEDF629B5F1C333539F575A2F4159F0C660E8CDC6DAD10B5AE8080
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -11.0
      Forensic Cluster
         -40.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -9.9s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -9.9s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -9.8s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.6s C:\Program Files\SearchProtect\
         -8.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData
         

Alt 05.04.2015, 15:15   #22
Maryy
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Code:
ATTFilter
\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.4s C:\Program Files\SearchProtect\Main\rep\
         -7.4s C:\Program Files\SearchProtect\Main\
         -7.4s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.0s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -0.9s C:\Program Files\SearchProtect\Main\bin\
         -0.9s C:\Program Files\SearchProtect\EULA.txt
         -0.9s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.6s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.6s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.4s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.4s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -0.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -0.2s C:\Program Files\SearchProtect\SearchProtect\
         -0.2s C:\Program Files\SearchProtect\SearchProtect\bin\
         -0.2s C:\Program Files\SearchProtect\SearchProtect\rep\
         -0.2s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          0.8s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.8s C:\Program Files\SearchProtect\UI\dialogs\
          0.8s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.8s C:\Program Files\SearchProtect\UI\bin\
          0.8s C:\Program Files\SearchProtect\UI\rep\
          0.8s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.8s C:\Program Files\SearchProtect\UI\
          0.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\style.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          1.1s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.2s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.3s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.3s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.3s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.4s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.4s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.4s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.4s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.4s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.4s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.4s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.5s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.5s C:\Windows\AppPatch\nbin\
          1.6s C:\Windows\AppPatch\nbin\VC32Loader.dll
          2.0s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.4s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.5s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.5s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.6s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         12.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         16.0s C:\Windows\System32\Tasks\avaavxvyex
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.5s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 223.504 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : AFDFEC20AEFD3A0970B8FB4621AE7C838E08E25EC5F3F62F4F8F3639489249FF
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -40.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -10.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.9s C:\Program Files\SearchProtect\
         -8.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.6s C:\Program Files\SearchProtect\Main\rep\
         -7.6s C:\Program Files\SearchProtect\Main\
         -7.6s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.3s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -1.1s C:\Program Files\SearchProtect\Main\bin\
         -1.1s C:\Program Files\SearchProtect\EULA.txt
         -1.1s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.8s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.8s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.7s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -0.5s C:\Program Files\SearchProtect\SearchProtect\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\rep\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.6s C:\Program Files\SearchProtect\UI\dialogs\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.6s C:\Program Files\SearchProtect\UI\bin\
          0.6s C:\Program Files\SearchProtect\UI\rep\
          0.6s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.6s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.6s C:\Program Files\SearchProtect\UI\
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.8s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\style.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.3s C:\Windows\AppPatch\nbin\
          1.3s C:\Windows\AppPatch\nbin\VC32Loader.dll
          1.8s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.2s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.3s C:\Program Files\SearchProtect\Main\rep\pni.bin
          8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         12.5s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         15.7s C:\Windows\System32\Tasks\avaavxvyex
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 7.973.136 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 6.1
      SHA-256  . . . . . : F2D90F3441A46D3293800190D71BD2E31091B291EE0BCE0CEA956134137B5444
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -40.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -10.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.9s C:\Program Files\SearchProtect\
         -8.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.7s C:\Program Files\SearchProtect\Main\rep\
         -7.7s C:\Program Files\SearchProtect\Main\
         -7.7s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.3s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -1.2s C:\Program Files\SearchProtect\Main\bin\
         -1.2s C:\Program Files\SearchProtect\EULA.txt
         -1.2s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.9s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.9s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.7s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -0.5s C:\Program Files\SearchProtect\SearchProtect\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\rep\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
         -0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
         -0.0s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
         -0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.5s C:\Program Files\SearchProtect\UI\dialogs\
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.5s C:\Program Files\SearchProtect\UI\bin\
          0.5s C:\Program Files\SearchProtect\UI\rep\
          0.5s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.5s C:\Program Files\SearchProtect\UI\
          0.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.8s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\style.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.2s C:\Windows\AppPatch\nbin\
          1.3s C:\Windows\AppPatch\nbin\VC32Loader.dll
          1.7s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.1s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.3s C:\Program Files\SearchProtect\Main\rep\pni.bin
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         12.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         15.7s C:\Windows\System32\Tasks\avaavxvyex
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 263.952 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 6.1
      SHA-256  . . . . . : 8101A281DA7C479B9F113FA069ACCB417DEA74DAD4D66324B4D5F1500C1CFC7F
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -40.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.5s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -39.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -10.2s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -10.1s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -9.9s C:\Program Files\SearchProtect\
         -8.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -7.7s C:\Program Files\SearchProtect\Main\rep\
         -7.7s C:\Program Files\SearchProtect\Main\
         -7.6s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.3s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -1.2s C:\Program Files\SearchProtect\Main\bin\
         -1.2s C:\Program Files\SearchProtect\EULA.txt
         -1.1s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -0.9s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -0.8s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -0.7s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -0.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -0.6s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -0.5s C:\Program Files\SearchProtect\SearchProtect\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\rep\
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -0.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
         -0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
          0.0s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
          0.5s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.5s C:\Program Files\SearchProtect\UI\dialogs\
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.5s C:\Program Files\SearchProtect\UI\bin\
          0.5s C:\Program Files\SearchProtect\UI\rep\
          0.5s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.5s C:\Program Files\SearchProtect\UI\
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.8s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\style.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          0.9s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          1.0s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          1.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          1.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          1.2s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          1.2s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          1.3s C:\Windows\AppPatch\nbin\
          1.3s C:\Windows\AppPatch\nbin\VC32Loader.dll
          1.8s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          5.1s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\trn.bin
          5.2s C:\Program Files\SearchProtect\Main\rep\edk.bin
          5.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          5.3s C:\Program Files\SearchProtect\Main\rep\pni.bin
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          7.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         12.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         15.7s C:\Windows\System32\Tasks\avaavxvyex
         17.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         17.3s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\UI\bin\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\bin\cltmngui.exe (SearchProtect) -> PendingDelete
      Size . . . . . . . : 3.270.928 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:47)
      Entropy  . . . . . : 6.6
      SHA-256  . . . . . : 2C2DB1B680D86855268E2A506C9627E965A6CCDC60104E59107C37464E3A5D0B
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -13.0
      Forensic Cluster
         -41.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -41.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -40.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -40.4s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -10.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -10.7s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -10.6s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -10.4s C:\Program Files\SearchProtect\
         -9.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -9.3s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -9.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -9.2s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.2s C:\Program Files\SearchProtect\Main\rep\
         -8.2s C:\Program Files\SearchProtect\Main\
         -8.2s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -7.8s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -7.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -1.7s C:\Program Files\SearchProtect\Main\bin\
         -1.7s C:\Program Files\SearchProtect\EULA.txt
         -1.7s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -1.4s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -1.4s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -1.2s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -1.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -1.2s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -1.1s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -1.0s C:\Program Files\SearchProtect\SearchProtect\
         -1.0s C:\Program Files\SearchProtect\SearchProtect\bin\
         -1.0s C:\Program Files\SearchProtect\SearchProtect\rep\
         -1.0s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -0.8s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
         -0.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
         -0.5s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
         -0.1s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
          0.0s C:\Program Files\SearchProtect\UI\dialogs\
          0.0s C:\Program Files\SearchProtect\UI\dialogs\libs\
          0.0s C:\Program Files\SearchProtect\UI\bin\
          0.0s C:\Program Files\SearchProtect\UI\rep\
          0.0s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
          0.0s C:\Program Files\SearchProtect\UI\dialogs\Images\
          0.0s C:\Program Files\SearchProtect\UI\
          0.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.0s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
          0.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
          0.2s C:\Program Files\SearchProtect\UI\dialogs\settings.html
          0.2s C:\Program Files\SearchProtect\UI\dialogs\style.css
          0.2s C:\Program Files\SearchProtect\UI\dialogs\Consent\
          0.2s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
          0.2s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
          0.2s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
          0.2s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
          0.2s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
          0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
          0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
          0.5s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
          0.6s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\settings\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
          0.6s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
          0.6s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
          0.6s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
          0.6s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
          0.6s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
          0.6s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
          0.7s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
          0.7s C:\Windows\AppPatch\nbin\
          0.8s C:\Windows\AppPatch\nbin\VC32Loader.dll
          1.2s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          4.6s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          4.6s C:\Program Files\SearchProtect\Main\rep\trn.bin
          4.6s C:\Program Files\SearchProtect\Main\rep\edk.bin
          4.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          4.8s C:\Program Files\SearchProtect\Main\rep\pni.bin
          7.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          7.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          7.4s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         11.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         15.2s C:\Windows\System32\Tasks\avaavxvyex
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         16.7s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   C:\Program Files\SearchProtect\UI\dialogs\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\Consent\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\v.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\Images\x.png (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\libs\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\libs\main.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protection\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protectionDS\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\settings.html (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\settings\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\style.css (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\uninstall\ (SearchProtect) -> Deleted
   C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html (SearchProtect) -> PendingDelete
   C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js (SearchProtect) -> PendingDelete
   C:\Users\Jochen_PC\AppData\Local\SearchProtect\ (SearchProtect) -> Deleted
   C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\ (SearchProtect) -> Deleted
   C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat (SearchProtect) -> PendingDelete
   C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat (SearchProtect) -> PendingDelete
   C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\ (SearchProtect) -> Deleted
   C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat (SearchProtect) -> PendingDelete
   C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb (SearchProtect) -> PendingDelete
   C:\Windows\AppPatch\nbin\VC32Loader.dll (SearchProtect) -> PendingDelete
      Size . . . . . . . : 223.504 bytes
      Age  . . . . . . . : 4.8 days (2015-03-31 20:43:48)
      Entropy  . . . . . : 6.7
      SHA-256  . . . . . : AFDFEC20AEFD3A0970B8FB4621AE7C838E08E25EC5F3F62F4F8F3639489249FF
      Product  . . . . . : Search Protect
      Publisher  . . . . : Client Connect LTD
      Description  . . . : Search Protect
      Version  . . . . . : 2.22.0.160
      Copyright  . . . . : © 2014 ClientConnect Ltd.
      RSA Key Size . . . : 2048
      LanguageID . . . . : 1033
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -5.0
      Forensic Cluster
         -41.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -41.8s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\40E450F7CE13419A2CCC2A5445035A0A_F663F250E172D75637EE387588AB955D
         -41.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -41.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\887FDFEF9DC62EF73EB288690D5944B1_52ED19A9955293A8BAEB2095162FA825
         -11.5s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\
         -11.5s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\Data1.cab
         -11.4s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1.7.0_65.msi
         -11.2s C:\Program Files\SearchProtect\
         -10.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -10.1s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49514950C94E8026A2B06312597DFF49_33A0493B3756EC93EB52782457685E27
         -9.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -9.9s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05EC48341C277FE5110E7DFAA91377DC_49A0F7ED62B84361D2B23E89CDE34920
         -8.9s C:\Program Files\SearchProtect\Main\rep\
         -8.9s C:\Program Files\SearchProtect\Main\
         -8.9s C:\Program Files\SearchProtect\Main\rep\SystemRepository.dat
         -8.6s C:\Users\Jochen_PC\AppData\LocalLow\Sun\Java\jre1.7.0_65\jre1031.MST
         -8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\
         -8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\
         -8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat
         -8.0s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\
         -2.4s C:\Program Files\SearchProtect\Main\bin\
         -2.4s C:\Program Files\SearchProtect\EULA.txt
         -2.4s C:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe
         -2.1s C:\Program Files\SearchProtect\Main\bin\SPtool.dll
         -2.1s C:\Program Files\SearchProtect\Main\bin\uninstall.pun
         -2.0s C:\Program Files\SearchProtect\Main\bin\uninstall.exe
         -1.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\
         -1.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pbqrmvbub
         -1.9s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\avaavxvyex.exe
         -1.8s C:\Program Files\SearchProtect\SearchProtect\
         -1.8s C:\Program Files\SearchProtect\SearchProtect\bin\
         -1.8s C:\Program Files\SearchProtect\SearchProtect\rep\
         -1.8s C:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe
         -1.6s C:\Program Files\SearchProtect\SearchProtect\bin\VC32.dll
         -1.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll
         -1.3s C:\Program Files\SearchProtect\SearchProtect\bin\RN32.dll
         -1.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll
         -1.3s C:\Program Files\SearchProtect\SearchProtect\bin\VC64.dll
         -0.8s C:\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe
         -0.8s C:\Program Files\SearchProtect\UI\dialogs\
         -0.8s C:\Program Files\SearchProtect\UI\dialogs\libs\
         -0.8s C:\Program Files\SearchProtect\UI\bin\
         -0.8s C:\Program Files\SearchProtect\UI\rep\
         -0.8s C:\Program Files\SearchProtect\UI\bin\cltmngui.exe
         -0.8s C:\Program Files\SearchProtect\UI\dialogs\Images\
         -0.8s C:\Program Files\SearchProtect\UI\
         -0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
         -0.7s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C46E7B0F942663A1EDC8D9D6D7869173_D9B9F37ECE595B0B7B6AA12451D392CF
         -0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
         -0.6s C:\Users\Jochen_PC\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\705A76DE71EA2CAEBB8F0907449CE086_D17788D699A177293EF133C8B62DF94A
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\settings.html
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\style.css
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.css
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.html
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\consent.js
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Consent\defaults.js
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-Rollover.png
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-default.png
         -0.5s C:\Program Files\SearchProtect\UI\dialogs\Images\Apply-onclick.png
         -0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\SP_DialogBG.png
         -0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\Settings-icon.png
         -0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-dia.png
         -0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-uninstall.png
         -0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg-with-logo.png
         -0.4s C:\Program Files\SearchProtect\UI\dialogs\Images\bg.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\bgNotif.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettings.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\bgSettingsDS.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\bgUninstall.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\btnBlue.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\btnClose.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\btnSilver.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\button-bg.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_checked.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\checkbox_def.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-def.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\close-win-over-click.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\gray-bg.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def-grey.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-def.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez-selected.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\hez.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\icon-win.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\info-icon.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-rollover.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\menu-selected.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-def.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\libs\defaults.js
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\libs\dialogUtils.js
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button-selected.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\radio-button2.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\text-field.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\v.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\Images\x.png
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js
         -0.3s C:\Program Files\SearchProtect\UI\dialogs\libs\json2.min.js
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\libs\main.js
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protection\
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protection\defaults.js
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.css
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.html
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protection\protection.js
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\defaults.js
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.css
         -0.2s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.html
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\protectionDS\protectionDS.js
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\settings\
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\settings\defaults.js
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.css
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.html
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\settings\settings.js
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\defaults.js
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.css
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.html
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\uninstall\uninstall.js
         -0.1s C:\Program Files\SearchProtect\UI\dialogs\libs\DialogAPI.js
         -0.0s C:\Windows\AppPatch\nbin\
          0.0s C:\Windows\AppPatch\nbin\VC32Loader.dll
          0.5s C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
          3.9s C:\Program Files\SearchProtect\Main\rep\cfi.bin
          3.9s C:\Program Files\SearchProtect\Main\rep\trn.bin
          3.9s C:\Program Files\SearchProtect\Main\rep\edk.bin
          3.9s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\STG\
          4.0s C:\Program Files\SearchProtect\Main\rep\pni.bin
          6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\
          6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\
          6.7s C:\Users\Jochen_PC\AppData\Local\SearchProtect\UI\rep\UIRepository.dat
         11.2s C:\Users\Jochen_PC\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat
         14.4s C:\Windows\System32\Tasks\avaavxvyex
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\rfobmlpfqlovvawq
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\bahvxfk
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\ycfvxfk
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\qokvxfk
         16.0s C:\Users\Jochen_PC\AppData\Local\avaavxvyex\mkfvxfk

   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}\ (SearchProtect) -> Deleted
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect\ (SearchProtect) -> Deleted
   HKLM\SOFTWARE\SearchProtect\ (SearchProtect) -> Deleted
   HKLM\SOFTWARE\SPPDCOM\ (SearchProtect) -> Deleted
   HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SPPD\ (SearchProtect) -> PendingDelete
   HKLM\SYSTEM\ControlSet001\services\CltMngSvc\ (SearchProtect) -> PendingDelete
   HKLM\SYSTEM\ControlSet001\services\SPPD\ (SearchProtect)
   HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SPPD\ (SearchProtect) -> Deleted
   HKLM\SYSTEM\ControlSet002\services\CltMngSvc\ (SearchProtect) -> PendingDelete
   HKLM\SYSTEM\ControlSet002\services\SPPD\ (SearchProtect)
   HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPPD\ (SearchProtect) -> PendingDelete
   HKLM\SYSTEM\CurrentControlSet\services\CltMngSvc\ (SearchProtect) -> PendingDelete
   HKLM\SYSTEM\CurrentControlSet\services\SPPD\ (SearchProtect)

Potential Unwanted Programs _________________________________________________

   C:\ProgramData\Registry Helper\ (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Registry Helper Log.txt (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Service\ (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Service\Service Log.txt (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\ (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\BackupOptions.efs (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\Ignored.efs (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\Options.efs (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\RegistryHelper.ini (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\Results.efs (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\Settings.efs (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Settings\StatusInfo.efs (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Startup Manager\ (RegistryHelper) -> Deleted
   C:\ProgramData\Registry Helper\Startup Manager\StartupPrograms.ini (RegistryHelper) -> Deleted
   C:\rei\ (ReimageRepair) -> Deleted
   C:\rei\AV\ (ReimageRepair) -> Deleted
   C:\rei\AV\avupdate.conf (ReimageRepair) -> Deleted
   C:\rei\AV\avupdate.exe (ReimageRepair) -> Deleted
      Size . . . . . . . : 2.234.568 bytes
      Age  . . . . . . . : 104.2 days (2014-12-22 09:55:04)
      Entropy  . . . . . : 6.0
      SHA-256  . . . . . : 60B6AB6ED206CE0F6A61065A645BFF51E92FA5FD132757F8D437A8FA60DABC02
      Product  . . . . . : Avira
      Publisher  . . . . : Avira Operations GmbH & Co. KG
      Description  . . . : Updater
      Version  . . . . . : 2.0.2.13
      RSA Key Size . . . : 2048
      LanguageID . . . . : 0
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -7.0

   C:\rei\AV\avupdate_msg.avr (ReimageRepair) -> Deleted
   C:\rei\AV\HBEDV.KEY (ReimageRepair) -> Deleted
   C:\rei\AV\Microsoft.VC90.CRT\ (ReimageRepair) -> Deleted
   C:\rei\AV\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest (ReimageRepair) -> Deleted
   C:\rei\AV\savapi3_restart.exe (ReimageRepair) -> Deleted
      Size . . . . . . . : 55.648 bytes
      Age  . . . . . . . : 104.2 days (2014-12-22 09:55:02)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : 1EA3D28E5A7DB5CBAE67094344151FB8AC791CE3F40F0AA636DE7CC9CB48AAA9
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -1.0

   C:\rei\AV\savapi3_start.exe (ReimageRepair) -> Deleted
      Size . . . . . . . : 55.648 bytes
      Age  . . . . . . . : 104.2 days (2014-12-22 09:55:02)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : BD3EDF49010EB06E4C705C128DDC38AC951A0506A080C067B3A9951454EC2598
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -1.0

   C:\rei\AV\savapi3_stop.exe (ReimageRepair) -> Deleted
      Size . . . . . . . : 55.648 bytes
      Age  . . . . . . . : 104.2 days (2014-12-22 09:55:02)
      Entropy  . . . . . : 5.9
      SHA-256  . . . . . : BD3EDF49010EB06E4C705C128DDC38AC951A0506A080C067B3A9951454EC2598
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : -1.0

   C:\rei\cfl.rei (ReimageRepair) -> Deleted
   C:\rei\cpuidsdk.dll (ReimageRepair) -> Deleted
      Size . . . . . . . : 1.048.576 bytes
      Age  . . . . . . . : 104.2 days (2014-12-22 09:54:56)
      Entropy  . . . . . : 6.4
      SHA-256  . . . . . : B3BAD26EC5D885A2883C577943C49E98994FC5F877698A4F3D8DB6B03795CC5C
      Product  . . . . . : CPUID SDK Dynamic Link Library
      Publisher  . . . . : CPUID
      Description  . . . : CPUID DLL SDK
      Version  . . . . . : 1.0.8.3
      LanguageID . . . . : 1036
      Fuzzy  . . . . . . : 0.0

   C:\rei\rei1801.ini (ReimageRepair) -> Deleted
   C:\rei\rei1805.ini (ReimageRepair) -> Deleted
   C:\rei\rei1808.ini (ReimageRepair) -> Deleted
   C:\rei\reimage.qsr (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.1\RUN20141217_1138\ (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.1\RUN20141217_1138\debug-repair-2.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.1\RUN20141217_1138\debug-repair.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.1\RUN20141217_1138\Info_EnvironmentVars.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.1\RUN20141217_1138\Info_Installed.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.1\RUN20141217_1138\out.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\ (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\Compress.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\debug-repair-2.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\debug-repair.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\Info_EnvironmentVars.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\Info_Installed.rec (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150206_1838\out.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\ (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\Compress.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\debug-repair-2.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\debug-repair.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\Info_EnvironmentVars.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\Info_Installed.rec (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.5\RUN20150208_1107\out.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\ (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\Compress.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\debug-repair-2.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\debug-repair.log (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\Info_EnvironmentVars.res (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\Info_Installed.rec (ReimageRepair) -> Deleted
   C:\rei\Results\EXE1.8.0.8\RUN20150221_1334\out.log (ReimageRepair) -> Deleted
   C:\rei\SupportInfoTool.ini (ReimageRepair) -> Deleted
   C:\rei\Temp\20141217_1138\ (ReimageRepair) -> Deleted
   C:\rei\Temp\20141217_1138\ApplicationList.ini (ReimageRepair) -> Deleted
   C:\rei\Temp\20150206_1838\ (ReimageRepair) -> Deleted
   C:\rei\Temp\20150206_1838\ApplicationList.ini (ReimageRepair) -> Deleted
   C:\rei\Temp\20150208_1107\ (ReimageRepair) -> Deleted
   C:\rei\Temp\20150208_1107\ApplicationList.ini (ReimageRepair) -> Deleted
   C:\rei\Temp\20150221_1334\ (ReimageRepair) -> Deleted
   C:\rei\Temp\20150221_1334\ApplicationList.ini (ReimageRepair) -> Deleted
   browser.newtab.url
   C:\Users\Jochen_PC\AppData\Roaming\Mozilla\Firefox\Profiles\izie2psw.default\prefs.js

   browser.startup.homepage
   C:\Users\Jochen_PC\AppData\Roaming\Mozilla\Firefox\Profiles\izie2psw.default\prefs.js

   HKLM\SOFTWARE\Classes\62c9ccffad834deab5e0fd5cd3afeb390064969.BHO.1\ (MediaPlayer+) -> Deleted
   HKLM\SOFTWARE\Classes\62c9ccffad834deab5e0fd5cd3afeb390064969.BHO\ (MediaPlayer+) -> Deleted
   HKLM\SOFTWARE\Classes\62c9ccffad834deab5e0fd5cd3afeb390064969.Sandbox.1\ (MediaPlayer+) -> Deleted
   HKLM\SOFTWARE\Classes\62c9ccffad834deab5e0fd5cd3afeb390064969.Sandbox\ (MediaPlayer+) -> Deleted
   HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL\ (ReimageRepair) -> Deleted
   HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}\ (ReimageRepair) -> Deleted
   HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}\ (RegistryHelper) -> Deleted
   HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}\ (ReimageRepair) -> Deleted
   HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}\ (ReimageRepair) -> Deleted
   HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}\ (FLV Player) -> Deleted
   HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}\ (FLV Player) -> Deleted
   HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}\ (FLV Player) -> Deleted
   HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}\ (FLV Player) -> Deleted
   HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1\ (ReimageRepair) -> Deleted
   HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine\ (ReimageRepair) -> Deleted
   HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}\ (MyStart) -> Deleted
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\ (DomalQ) -> Deleted
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\ (DomalQ) -> Deleted
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110611491169} (MediaPlayer+) -> Deleted
   HKLM\SOFTWARE\Registry Helper\ (RegistryHelper) -> Deleted
   HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dghncoeocefmhkhiphdgikkamjeglbfh\ (MyStart) -> Deleted
   HKLM\SYSTEM\ControlSet001\services\eventlog\Application\Registry Helper Service\ (RegistryHelper) -> Deleted
   HKLM\SYSTEM\ControlSet002\services\eventlog\Application\Registry Helper Service\ (RegistryHelper) -> Deleted
   HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Registry Helper Service\ (RegistryHelper) -> PendingDelete
   HKU\.DEFAULT\Software\AskPartnerNetwork\ (AskBar) -> Deleted
   HKU\.DEFAULT\Software\VNT\ (AskBar) -> Deleted
   HKU\S-1-5-18\Software\AskPartnerNetwork\ (AskBar) -> PendingDelete
   HKU\S-1-5-18\Software\VNT\ (AskBar) -> PendingDelete
   HKU\S-1-5-21-4120694069-413394052-4141004193-1004\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{AE07101B-46D4-4A98-AF68-0333EA26E113} (FLV Player) -> Deleted
   HKU\S-1-5-21-4120694069-413394052-4141004193-1004\Software\Microsoft\Internet Explorer\MAIN\Start Page (Trovigo) -> Deleted
   HKU\S-1-5-21-4120694069-413394052-4141004193-1004\Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\ (Trovigo) -> Deleted
   HKU\S-1-5-21-4120694069-413394052-4141004193-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}\ (ReimageRepair) -> Deleted
   HKU\S-1-5-21-4120694069-413394052-4141004193-1004\Software\Smartbar\ (Conduit) -> Deleted
         

Alt 06.04.2015, 08:33   #23
M-K-D-B
/// TB-Ausbilder
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Servus,


es fehlt noch die Logdatei von ESET und SecurityCheck.

Alt 12.04.2015, 09:51   #24
M-K-D-B
/// TB-Ausbilder
 
Leistung vom Laptop stark vermindert - Standard

Leistung vom Laptop stark vermindert



Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!

Antwort

Themen zu Leistung vom Laptop stark vermindert
conduitsearch, conduitsearch entfernen, fehlercode 0x40000015, fehlercode 0x80000003, fehlercode 0xc0000005, fehlercode 24, fehlercode windows, pup.optional.babylon.a, pup.optional.conduit, pup.optional.conduit.a, pup.optional.crossrider, pup.optional.crossrider.a, pup.optional.fastplayer.a, pup.optional.hdquality.a, pup.optional.mysafeproxy.a, pup.optional.mystarttb.a, pup.optional.searchprotect.a, pup.optional.softonic.a, pup.optional.valueapps.a, pup.optional.videosmediaplayers.a, reimage repair entfernen, remote desktop access entfernen, this device cannot start. (code10), value="2.0"/>




Ähnliche Themen: Leistung vom Laptop stark vermindert


  1. Windows 8 & Windows 7 Laptop beide stark Adware verseucht
    Log-Analyse und Auswertung - 17.07.2015 (31)
  2. Windows 8: Datenträger 0 (C:) ständig auf 100% Leistung und Laptop sehr langsam.
    Log-Analyse und Auswertung - 30.05.2015 (5)
  3. Windows Vista: Seiten laden nicht richtig, Leistung stark vermindert, System sehr langsam
    Plagegeister aller Art und deren Bekämpfung - 26.04.2015 (5)
  4. Win7-Laptop von ASUS reagiert stark verzögert und hängt immer wieder
    Plagegeister aller Art und deren Bekämpfung - 14.04.2015 (11)
  5. Laptop Leistung stark beeinträchtigt + diverse andere Probleme
    Plagegeister aller Art und deren Bekämpfung - 21.03.2015 (28)
  6. Wie stark infiziert ist der Laptop?
    Log-Analyse und Auswertung - 25.04.2014 (9)
  7. Beeindruckende Leistung! Hut ab
    Lob, Kritik und Wünsche - 21.02.2014 (0)
  8. CPU leistung permanent auf 100!
    Plagegeister aller Art und deren Bekämpfung - 11.01.2014 (13)
  9. Windows 7: Laptop langsam, läuft auf voller leistung bis er überheitzt und aus geht
    Log-Analyse und Auswertung - 20.12.2013 (7)
  10. Super Leistung
    Lob, Kritik und Wünsche - 30.10.2013 (0)
  11. Starker Schädlingsbefall und stark verminderte Leistung.
    Log-Analyse und Auswertung - 28.08.2013 (27)
  12. PC Leistung stark ausgebremst
    Log-Analyse und Auswertung - 18.04.2013 (9)
  13. Max Leistung vom Pc
    Überwachung, Datenschutz und Spam - 24.04.2012 (7)
  14. leistung verbessern
    Log-Analyse und Auswertung - 22.03.2011 (3)
  15. Trojaner? PC Leistung stark vermindert. HIJACKTHIS
    Log-Analyse und Auswertung - 10.03.2010 (1)
  16. PC Leistung
    Log-Analyse und Auswertung - 03.12.2009 (1)
  17. mehr Leistung?
    Alles rund um Windows - 20.10.2007 (11)

Zum Thema Leistung vom Laptop stark vermindert - Hallo. das habe ich hochgeladen. lg Mary - Leistung vom Laptop stark vermindert...
Archiv
Du betrachtest: Leistung vom Laptop stark vermindert auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.