|
Log-Analyse und Auswertung: Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestopptWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
23.09.2015, 19:29 | #1 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Hallo liebes TB-Team Da mir eure Seite wärmstens empfohlen wurde und ich ein wenig verzweifelt bin, habe ich mich hier angemeldet und hoffe, dass Ihr mir helfen könnt. Seitdem ich gestern von chip.de etwas runtergeladen und installiert habe, spinnt mein Laptop. Er ist extrem langsam geworden und der Akku hält nur wenige Minuten. Bei Letzterem weiss ich jedoch nicht, ob das nicht auch am Alter liegt (4 Jahre alt) und der Akku nun zufälligerweise kaputt gegangen ist. Ich habe daraufhin einen Suchlauf mit Malwarebytes und Avira gemacht. Beim Suchlauf mit Malwarebytes ist dann plötzlich Avira angesprungen und hat folgende Malware entdeckt: Code:
ATTFilter Exportierte Ereignisse: 23.09.2015 17:18 [System-Scanner] Malware gefunden Die Datei 'C:\Users\Cristina\Downloads\cnet2_setupIgor6_exe.exe' enthielt einen Virus oder unerwünschtes Programm 'PUA/InstallCore.Gen' [riskware]. Durchgeführte Aktion(en): Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '7f166c21.qua' verschoben! Nachfolgend das Logfile von Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 23.09.2015 Suchlaufzeit: 17:02 Protokolldatei: Scan 23.09.2015.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.09.23.03 Rootkit-Datenbank: v2015.09.22.01 Lizenz: Testversion Malware-Schutz: Aktiviert Schutz vor bösartigen Websites: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Cristina Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 371680 Abgelaufene Zeit: 25 Min., 9 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 19 PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\Toolbar.CT2528046, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Toolbar.CT2528046, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Toolbar.CT2528046, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}, , [0847f43fe1aafa3cc88ec1d0e91bf50b], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}, , [0847f43fe1aafa3cc88ec1d0e91bf50b], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD7DB970-2E61-457F-9D19-E13D175F7240}, , [c887191a7912c175292ff0a19b6910f0], PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}, , [103f8ba899f2ec4a2723b8d9df256898], PUP.Optional.PriceGong, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [143b6cc7107b42f44828f3c1a06431cf], PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}, , [56f93af96d1e7bbb89b42f62e91b8080], PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E08A9998-D98F-476F-8F5C-37C80FE0A4DA}, , [db7445eee6a59d991c21cec30ef6ce32], Registrierungswerte: 8 PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, ¾Â ü … A›kšB}ÞÌ4, , [93bccb68414a56e063f0c2e8ad58c13f] PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, jetztspielenob.de Toolbar, , [93bccb68414a56e063f0c2e8ad58c13f] PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD7DB970-2E61-457F-9D19-E13D175F7240}|AppPath, C:\Users\Cristina\AppData\Local\Conduit\CT2528046, , [c887191a7912c175292ff0a19b6910f0] PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046, , [103f8ba899f2ec4a2723b8d9df256898] PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046, , [56f93af96d1e7bbb89b42f62e91b8080] PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E08A9998-D98F-476f-8F5C-37C80FE0A4DA}|URL, hxxp://search.conduit.com/?SearchSource=10&ctid=CT2528046, , [db7445eee6a59d991c21cec30ef6ce32] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 25 PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit\Community Alerts, , [0847f43fe1aafa3cc88ec1d0e91bf50b], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit, , [0847f43fe1aafa3cc88ec1d0e91bf50b], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\397B5FD0E2674172BCA0ED089CC29E44, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\45C6E9FE0B5748D9B49A9C1FFA7EC684, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\8665B2031BB4494380751AC72D5B7E71, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\OpenCandy_397B5FD0E2674172BCA0ED089CC29E44, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\de, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\en, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\es, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\fr, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\it, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ja, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\nl, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pl, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pt, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ru, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_CN, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_TW, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data, , [054ad75ca4e796a0a9b93de723e041bf], Dateien: 76 PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\jetztspielenob.de\prxtbjet0.dll, , [93bccb68414a56e063f0c2e8ad58c13f], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\jetztspielenob.de\tbjet0.dll, , [e36c181b97f4f046e370fcae778eab55], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\jetztspielenob.de\tbjet1.dll, , [1c3359da1f6c3303c68df7b35ea751af], PUP.Optional.Conduit, C:\Users\Cristina\AppData\Local\Temp\ct2661025\ism.exe, , [ff50e84ba7e40d29d52c4f6c7e83f60a], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Local\Temp\is-GRMFS.tmp\OCSetupHlp.dll, , [afa052e1bfcc0b2b95a3a9f34abb59a7], PUP.Optional.APNToolBar, C:\Windows\Temp\avnwldrtemp\setup\Offercast_AVIRAV7_.exe, , [8dc2250ee2a9d85e5ea4b406fd04c937], PUP.Optional.Conduit, C:\Users\Cristina\Downloads\SpilgamesHeroesOfHellasDe(1).exe, , [c788a48f6a213afc5e2fa1b5768a1ee2], PUP.Optional.Conduit, C:\Users\Cristina\Downloads\SpilgamesHeroesOfHellasDe.exe, , [ec63e64d13785cda04f2e2d8e0213ec2], PUP.Optional.ConduitTB.Gen, C:\Users\Cristina\AppData\Local\Conduit\CT2528046\jetztspielenob.deAutoUpdaterHelper.exe, , [79d638fb385359dd13403f6b49bc718f], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll, , [0847f43fe1aafa3cc88ec1d0e91bf50b], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit\Community Alerts\Alert0.dll, , [0847f43fe1aafa3cc88ec1d0e91bf50b], PUP.Optional.DVDVideoSoft, C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi, , [3c13999a8308df57fc3ae8b1b94b7789], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\397B5FD0E2674172BCA0ED089CC29E44\TuneUpUtilities2012_de-DE_1002180.exe, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\45C6E9FE0B5748D9B49A9C1FFA7EC684\TuneUpUtilities2013_2200212_de-DE.exe, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\8665B2031BB4494380751AC72D5B7E71\TuneUpUtilities2013-2200214-p2v1.exe, , [84cb36fd078481b57b0a936a0bf71be5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\background.html, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\background.js, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_freeyoutubedownload.css, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_freeyoutubedownload.js, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo.ico, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo_128.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo_32.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo_48.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\errorRunProgramm.html, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\manifest.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\np_dvs_plugin.dll, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\options.html, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\options.js, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\page_action.html, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\backbar.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\download.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\fs.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\headphone.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\logo.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\manager.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\YoutubeDownloader.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\YoutubeToMp3.png, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\de\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\en\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\es\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\fr\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\it\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ja\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\nl\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pl\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pt\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ru\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_CN\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_TW\messages.json, , [70df31028902b581307529ed59aa4bb5], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\1.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\a.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\b.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\c.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\d.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\e.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\f.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\g.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\h.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\i.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\j.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\k.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\l.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\m.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\n.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\o.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\p.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\q.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\r.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\s.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\t.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\u.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\v.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\w.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\x.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\y.txt, , [054ad75ca4e796a0a9b93de723e041bf], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\z.txt, , [054ad75ca4e796a0a9b93de723e041bf], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Ich habe natürlich auch eure Seite für Hilfesuchende durchgearbeitet. Nachfolgend noch die entsprechenden Logfiles von FRST und GMER. Bei Defogger kam keine Fehlermeldung: FRST Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015 durchgeführt von Cristina (Administrator) auf CRISTINA-PC (23-09-2015 19:39:27) Gestartet von C:\Users\Cristina\Desktop Geladene Profile: Cristina (Verfügbare Profile: Cristina) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 9 (Standard-Browser: IE) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Dropbox, Inc.) C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (AVEO) C:\Program Files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AveoSTI.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-12] (Acer Incorporated) HKLM\...\Run: [XeroxEndeavorBackgroundTask] => rundll32.exe xrWCbgnd.dll,LaunchBgTask 1 HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-11] (CANON INC.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation) HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-26] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [AveoSTI.exe] => C:\Program Files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AveoSTI.exe [32768 2010-12-02] (AVEO) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [782008 2015-09-13] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-13] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [718720 2011-07-22] (Microsoft Corporation) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [GoogleChromeAutoLaunch_6250FBC1BFC59B5E9DE82D06B6BF04ED] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-08-28] (Google Inc.) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [Dropbox Update] => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-22] (Dropbox, Inc.) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\MountPoints2: {da12717c-fa9e-11e1-b4c1-1c7508a9c25f} - E:\Start.exe ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) ProxyServer: [S-1-5-21-1416606159-1160031757-1180804506-1000] => proxy.zhaw.ch:8080 Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{7E454ECC-55E1-487A-B353-85FC9C82C45F}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{E17B3D49-001E-469C-BF7F-2306104338C0}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.alawarspiele.de HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.alawarspiele.de HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com URLSearchHook: HKLM-x32 - jetztspielenob.de Toolbar - {fc01c2be-850b-4115-9b6b-9a427ddecc34} - C:\Program Files (x86)\jetztspielenob.de\prxtbjet0.dll (Conduit Ltd.) URLSearchHook: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 - jetztspielenob.de Toolbar - {fc01c2be-850b-4115-9b6b-9a427ddecc34} - C:\Program Files (x86)\jetztspielenob.de\prxtbjet0.dll (Conduit Ltd.) SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046 SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046 SearchScopes: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046 SearchScopes: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> {E08A9998-D98F-476f-8F5C-37C80FE0A4DA} URL = hxxp://search.conduit.com/?SearchSource=10&ctid=CT2528046 BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-06-12] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-06-12] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-27] (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-29] (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-27] (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: jetztspielenob.de Toolbar -> {fc01c2be-850b-4115-9b6b-9a427ddecc34} -> C:\Program Files (x86)\jetztspielenob.de\prxtbjet0.dll [2011-01-17] (Conduit Ltd.) Toolbar: HKLM-x32 - jetztspielenob.de Toolbar - {fc01c2be-850b-4115-9b6b-9a427ddecc34} - C:\Program Files (x86)\jetztspielenob.de\prxtbjet0.dll [2011-01-17] (Conduit Ltd.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> Kein Name - {FC01C2BE-850B-4115-9B6B-9A427DDECC34} - Keine Datei Toolbar: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> Kein Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Keine Datei DPF: HKLM-x32 {4A85DBE0-BFB2-4119-8401-186A7C6EB653} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/mjss/MJSS.cab109791.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll Keine Datei Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll Keine Datei Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-29] (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default FF Homepage: www.google.ch FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] () FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] () FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-06-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-06-27] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll [2012-01-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-22] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-22] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\user.js [2012-04-29] FF Extension: Avira Browser Safety - C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\Extensions\abs@avira.com [2015-09-22] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-20] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-09-22] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-25] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => Keine Datei CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\gcswf32.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Profile: C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browserschutz) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-02-07] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-18] CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-11-21] CHR Extension: (Google Wallet) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-24] CHR HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Cristina\AppData\Roaming\DVDVideoSoft\DVDVideoSoftBrowserExtension.crx [2012-11-21] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [887128 2015-09-13] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [461672 2015-09-13] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [461672 2015-09-13] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1213072 2015-09-13] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [228104 2015-08-13] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [346496 2012-02-08] (AVEO) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-09-13] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-09-13] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-31] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-04-05] (Avira Operations GmbH & Co. KG) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-23] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-23 19:39 - 2015-09-23 19:40 - 00027114 _____ C:\Users\Cristina\Desktop\FRST.txt 2015-09-23 19:39 - 2015-09-23 19:39 - 00000000 ____D C:\FRST 2015-09-23 19:38 - 2015-09-23 19:38 - 00000478 _____ C:\Users\Cristina\Desktop\defogger_disable.log 2015-09-23 19:38 - 2015-09-23 19:38 - 00000000 _____ C:\Users\Cristina\defogger_reenable 2015-09-23 18:34 - 2015-09-23 19:36 - 00024949 _____ C:\Users\Cristina\Desktop\TB Post.txt 2015-09-23 18:20 - 2015-09-23 18:20 - 02192384 _____ (Farbar) C:\Users\Cristina\Desktop\FRST64.exe 2015-09-23 18:20 - 2015-09-23 18:20 - 00380416 _____ C:\Users\Cristina\Desktop\Gmer-19357.exe 2015-09-23 18:19 - 2015-09-23 18:19 - 00050477 _____ C:\Users\Cristina\Desktop\Defogger.exe 2015-09-23 17:44 - 2015-09-23 17:44 - 00000770 _____ C:\Users\Cristina\Desktop\Ereignisse Avira.txt 2015-09-23 17:32 - 2015-09-23 17:32 - 00022924 _____ C:\Users\Cristina\Desktop\Scan 23.09.2015.txt 2015-09-23 17:01 - 2015-09-23 19:30 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-09-23 17:01 - 2015-09-23 17:01 - 00001110 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-09-23 17:01 - 2015-09-23 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-09-23 17:01 - 2015-09-23 17:01 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-09-23 17:01 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-09-23 17:01 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-09-22 15:55 - 2015-09-22 15:55 - 18819272 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-09-22 15:53 - 2015-09-22 15:54 - 00000000 ____D C:\Users\Cristina\AppData\Local\Lenovo 2015-09-22 15:51 - 2015-09-22 15:53 - 00000000 ____D C:\Program Files (x86)\Lenovo 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Opera Software 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Users\Cristina\AppData\Local\Opera Software 2015-09-22 15:49 - 2015-09-22 15:56 - 00000000 ____D C:\Program Files (x86)\Opera 2015-09-22 15:49 - 2015-09-22 15:49 - 00000000 ____D C:\Users\Cristina\AppData\Local\TuneUp Software 2015-09-22 15:47 - 2015-09-22 15:47 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\RPEng 2015-09-22 15:47 - 2015-09-22 15:47 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack 2015-09-22 15:45 - 2015-09-22 15:46 - 44183312 _____ (DVDVideoSoft Ltd. ) C:\Users\Cristina\Downloads\FreeYouTube914ToMP3Converter.exe 2015-09-22 15:33 - 2015-09-23 19:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-09-22 15:24 - 2015-09-22 15:24 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-09-22 15:23 - 2015-09-23 19:28 - 00001236 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA.job 2015-09-22 15:23 - 2015-09-23 16:54 - 00001184 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core.job 2015-09-22 15:23 - 2015-09-22 15:23 - 00004212 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA 2015-09-22 15:23 - 2015-09-22 15:23 - 00003816 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core 2015-09-22 15:23 - 2015-09-22 15:23 - 00000000 ____D C:\Users\Cristina\AppData\Local\Dropbox 2015-09-22 15:23 - 2015-09-22 15:23 - 00000000 ____D C:\ProgramData\Dropbox 2015-09-22 14:21 - 2015-09-22 14:26 - 00009482 _____ C:\Users\Cristina\Desktop\Menukarte.xlsx 2015-09-13 14:16 - 2015-09-13 14:16 - 00001142 _____ C:\Users\Public\Desktop\Avira Launcher.lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-23 19:38 - 2011-05-05 19:56 - 00000000 ____D C:\Users\Cristina 2015-09-23 19:38 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-09-23 19:38 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-09-23 19:36 - 2011-01-28 06:32 - 01321708 _____ C:\Windows\WindowsUpdate.log 2015-09-23 19:35 - 2012-04-25 20:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-09-23 19:33 - 2011-05-07 18:23 - 00000000 ____D C:\Users\Cristina\AppData\Local\Adobe 2015-09-23 19:29 - 2012-04-25 20:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-09-23 19:29 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-09-23 19:29 - 2009-07-14 06:51 - 00108011 _____ C:\Windows\setupact.log 2015-09-23 19:28 - 2012-05-03 19:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-09-23 19:28 - 2011-01-28 06:29 - 01891714 _____ C:\Windows\PFRO.log 2015-09-23 18:53 - 2012-10-16 08:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-09-23 17:01 - 2011-05-08 23:25 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Malwarebytes 2015-09-23 17:01 - 2011-05-08 23:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-09-23 16:58 - 2012-06-16 09:01 - 00001711 _____ C:\Windows\wininit.ini 2015-09-23 16:58 - 2011-09-12 21:58 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-09-23 16:53 - 2012-11-21 21:34 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2015-09-23 16:53 - 2011-08-07 12:44 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\DVDVideoSoft 2015-09-23 16:49 - 2012-10-28 14:42 - 00003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{14B239D9-506D-40CB-84F9-C01CAED49E02} 2015-09-22 15:56 - 2012-10-16 08:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-09-22 15:56 - 2011-05-05 20:00 - 00001451 _____ C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-09-22 15:56 - 2011-05-05 20:00 - 00001417 _____ C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2015-09-22 15:55 - 2012-10-16 08:27 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-09-22 15:55 - 2011-06-12 23:10 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-09-22 15:51 - 2010-11-17 15:28 - 00000000 ____D C:\Windows\Downloaded Installations 2015-09-22 15:49 - 2012-06-01 20:33 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\TuneUp Software 2015-09-22 15:48 - 2012-06-01 20:33 - 00000000 ____D C:\ProgramData\TuneUp Software 2015-09-22 15:25 - 2011-10-03 20:45 - 00000000 ___RD C:\Users\Cristina\Dropbox 2015-09-22 15:25 - 2011-10-03 20:44 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Dropbox 2015-09-22 14:40 - 2012-01-11 10:41 - 00000000 ____D C:\Users\Cristina\Desktop\Musik 2015-09-22 14:30 - 2012-04-25 20:40 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-09-22 14:30 - 2012-04-25 20:40 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-09-13 14:31 - 2011-07-03 16:31 - 00000000 ____D C:\Users\Cristina\Documents\My Games 2015-09-13 14:30 - 2011-10-25 20:15 - 00000000 ____D C:\ProgramData\AlawarWrapper 2015-09-13 14:21 - 2012-03-29 11:08 - 00000000 ____D C:\Users\Cristina\Desktop\Operation Handyfotos 2015-09-13 14:20 - 2013-11-24 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-09-13 14:17 - 2013-11-24 12:48 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-09-13 14:17 - 2013-11-24 12:48 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-09-13 14:16 - 2014-09-01 20:20 - 00000000 ____D C:\ProgramData\Package Cache ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2010-11-17 15:30 - 2010-03-03 01:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Einige Dateien in TEMP: ==================== C:\Users\Cristina\AppData\Local\Temp\avgnt.exe C:\Users\Cristina\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp45ukc1.dll C:\Users\Cristina\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Cristina\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Cristina\AppData\Local\Temp\dsHostCheckerSetup.exe C:\Users\Cristina\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Cristina\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\Cristina\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-09-22 16:19 ==================== Ende von FRST.txt ============================ Code:
ATTFilter Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version:23-09-2015 durchgeführt von Cristina (2015-09-23 19:40:48) Gestartet von C:\Users\Cristina\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2011-05-05 17:56:24) Start-Modus: Normal ========================================================== ==================== Konten: ============================= Administrator (S-1-5-21-1416606159-1160031757-1180804506-500 - Administrator - Disabled) Cristina (S-1-5-21-1416606159-1160031757-1180804506-1000 - Administrator - Enabled) => C:\Users\Cristina Gast (S-1-5-21-1416606159-1160031757-1180804506-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1416606159-1160031757-1180804506-1002 - Limited - Enabled) ==================== Sicherheits-Center ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installierte Programme ====================== (Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.) Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.68 - NewTech Infosystems) Acer Crystal Eye webcam (HKLM-x32\...\{51F026FA-5146-4232-A8BA-1364740BD053}) (Version: 1.0.5.2 - Liteon) Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 5.00.3005 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3013 - Acer Incorporated) Acer GameZone Console (HKLM-x32\...\{58F4D244-314F-4D26-B5EF-C28AB32E22CB}_is1) (Version: 6.1.0.9 - Oberon Media, Inc.) Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.03.3003 - Acer Incorporated) Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0707.2010 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3001 - Acer Incorporated) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.1 - Adobe Systems) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe Creative Suite 6 Design Standard (HKLM-x32\...\{0327A4BF-62BF-48BB-8928-B971B749E9E1}) (Version: 6 - Adobe Systems Incorporated) Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.185 - Adobe Systems Incorporated) Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated) Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Reader 9.5.2 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.2 - Adobe Systems Incorporated) ArcSoft MediaImpression 2 (HKLM-x32\...\{81FC0476-9507-4CD3-95A7-2BE60E256D1D}) (Version: 2.0.27.846 - ArcSoft) ArcSoft PhotoStudio 5.5 (HKLM-x32\...\{85309D89-7BE9-4094-BB17-24999C6118FC}) (Version: - ArcSoft) ATI Catalyst Install Manager (HKLM\...\{BAF4695F-7867-D8B2-528A-A1EF2EE0A9EF}) (Version: 3.0.778.0 - ATI Technologies, Inc.) AVEO USB2.0 PC Camera(U2HGCV3P31048) (HKLM-x32\...\{3860C309-C642-49EE-B32D-8C4B462BC7BE}) (Version: 2.0.0.5 - USB2.0 PC Camera) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.12.420 - Avira Operations GmbH & Co. KG) Avira Launcher (HKLM-x32\...\{315dd168-0794-4cf1-8355-f195cde642fc}) (Version: 1.1.45.11819 - Avira Operations GmbH & Co. KG) Avira Launcher (x32 Version: 1.1.45.11819 - Avira Operations GmbH & Co. KG) Hidden Backup Manager Basic (x32 Version: 2.0.0.68 - NewTech Infosystems) Hidden Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.2.0.7 - ) BioProzessTrainer (HKLM-x32\...\{14C41094-39D5-4069-A270-686980A6DC99}) (Version: 5.12.1088 - IB-Schoop) BiotechSIM (HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\BiotechSIM) (Version: - CS FEE CTU) Broadcom Gigabit NetLink Controller (HKLM\...\{A84DB02B-9C2B-4272-9D2D-A80E00A56513}) (Version: 14.0.2.3 - Broadcom Corporation) Cake Mania (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}) (Version: - Oberon Media) Canon MP Navigator EX 2.0 (HKLM-x32\...\MP Navigator EX 2.0) (Version: - ) Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version: - ) CanoScan LiDE 200 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4807) (Version: - ) ccc-core-static (x32 Version: 2010.0825.2205.37769 - ATI) Hidden CyberLink PowerDVD 9 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.3216.50 - CyberLink Corp.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DigitalSimulatorV5.57 (remove only) (HKLM-x32\...\DigitalSimulatorV5.57) (Version: - ) Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media) Dropbox (HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Dropbox) (Version: 3.8.8 - Dropbox, Inc.) EndNote X4 (HKLM-x32\...\{86B3F2D6-AC2B-0014-8AE1-F2F77F781B0C}) (Version: 14.0.0.4845 - Thomson Reuters) eSobi v2 (HKLM-x32\...\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.) eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden EZ Vinyl/Tape Converter 10 by Ion Audio (HKLM-x32\...\EZ Vinyl/Tape Converter by Ion Audio_is1) (Version: - Ion Audio LLC) Farm Frenzy 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}) (Version: - Oberon Media) Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media) GetData Graph Digitizer 2.24 (HKLM-x32\...\GetData Graph Digitizer_is1) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.) Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden Heroes Of Hellas (HKLM-x32\...\Heroes Of Hellas) (Version: - Alawar Entertainment Inc.) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated) Igor Pro (HKLM-x32\...\Igor Pro) (Version: - ) ImageJ 1.44p (HKLM-x32\...\ImageJ_is1) (Version: - NIH) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.2.1001 - Intel Corporation) Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.186.6 - Intel) Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217060FF}) (Version: 7.0.600 - Oracle) Java(TM) 6 Update 26 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216026FF}) (Version: 6.0.260 - Oracle) Java(TM) SE Development Kit 6 Update 26 (HKLM-x32\...\{32A3A4F4-B792-11D6-A78A-00B0D0160260}) (Version: 1.6.0.260 - Oracle) jetztspielenob.de Toolbar (HKLM-x32\...\jetztspielenob.de Toolbar) (Version: 6.3.3.3 - ) Juniper Networks Host Checker (HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Neoteris_Host_Checker) (Version: 7.1.17.28099 - Juniper Networks) Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Juniper_Setup_Client) (Version: 7.1.17.41283 - Juniper Networks, Inc.) Juniper Networks, Inc. Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Launch Manager (HKLM-x32\...\LManager) (Version: 4.0.14 - Acer Inc.) Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation) Merriam Websters Spell Jam (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}) (Version: - Oberon Media) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Metric Collection SDK 35 (x32 Version: 1.2.0010.00 - Lenovo Group Limited) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version: - Microsoft) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.1.10111.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visio 2010 Service Pack 1 (SP1) (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{01D8AE4B-A04D-47E5-81BF-E3F98B81B8C3}) (Version: - Microsoft) Microsoft Visio Professional 2010 (HKLM-x32\...\Office14.VISIOR) (Version: 14.0.6029.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Might and Magic® VI (HKLM-x32\...\Might and Magic® VI) (Version: - ) Mozilla Firefox 40.0.3 (x86 de) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 de)) (Version: 40.0.3 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla) Myst: Masterpiece Edition (HKLM-x32\...\Steam App 63660) (Version: - ) MyWinLocker (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}) (Version: 3.1.212.0 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 3.1.212.0 - Egis Technology Inc.) Hidden Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8939 - NTI Corporation) NTI Media Maker 9 (x32 Version: 9.0.2.8939 - NTI Corporation) Hidden PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden Poker Pop (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111355427}) (Version: - Oberon Media) PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Realtek HDMI Audio Driver for ATI (HKLM-x32\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6034 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30124 - Realtek Semiconductor Corp.) ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version: - ) Riven (HKLM-x32\...\Steam App 63610) (Version: - ) Shredder (Version: 2.0.8.3 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.3 - Egis Technology Inc.) Hidden Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.8.8855 - Skype Technologies S.A.) Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.) Spin & Win (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110300453}) (Version: - Oberon Media) STAN 2.0.1703 (HKLM-x32\...\{C2ED3B35-5980-4496-B32B-1DE76D61DF63}) (Version: 2.0.1703 - inka software) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stronghold (HKLM-x32\...\{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}) (Version: - ) Stronghold Crusader Demo (HKLM-x32\...\{BDC96E64-A010-4341-A072-47EFDBD6CFBA}) (Version: - ) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated) TuneUp Utilities 2014 (de-DE) (x32 Version: 14.0.1000.353 - TuneUp Software) Hidden Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version: - ) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3007 - Acer Incorporated) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) WinFACT 8 (HKLM-x32\...\{0F00C986-561C-4536-B62B-0EDE3475312A}) (Version: 8.1.1 - Ingenieurbüro Dr. Kahlert) ==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.) ==================== Wiederherstellungspunkte ========================= 09-07-2015 21:12:51 Installed Stronghold Crusader Demo 22-09-2015 15:54:31 TuneUp Utilities 2014 wird entfernt 22-09-2015 15:56:17 TuneUp Utilities 2014 (de-DE) wird entfernt ==================== Hosts Inhalt: =============================== (Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) ============= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) Task: {74414BFD-5FD4-4704-9941-FDF87D5D450E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13] (Google Inc.) Task: {7B729215-85A3-4B25-A89D-40F4EA7C6DA6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-22] (Adobe Systems Incorporated) Task: {B8BF9182-8D7D-48DD-B094-E85106AF8465} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07] (Oracle Corporation) Task: {D06BF145-1F4B-4E40-9057-A84EF75D3FCF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-13] (Google Inc.) Task: {D973B400-74A4-4E40-8835-136A6CBC3549} - System32\Tasks\AdobeAAMUpdater-1.0-Cristina-PC-Cristina => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {DA19F808-74B2-4D6A-8326-44945096C04E} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-09-22] (Dropbox, Inc.) Task: {DE7BE347-BB9F-4221-BA06-2C26864E920A} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-11] (Adobe Systems Incorporated) Task: {DF29EDDD-043C-4960-A5E0-566A143EF8FE} - \SidebarExecute -> Keine Datei <==== ACHTUNG Task: {E173EF82-F58E-4BA7-8DED-B14927FB1211} - System32\Tasks\ArcSoft Connect Daemon => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27] (ArcSoft Inc.) Task: {FABCD8F4-3BDF-4044-90F8-9CA78CF806CF} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-09-22] (Dropbox, Inc.) Task: {FB84AFE9-6A49-4A93-B3AD-B88112C80510} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core.job => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA.job => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Geladene Module (Nicht auf der Ausnahmeliste) ============== 2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-08-27 01:45 - 2010-08-27 01:45 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-08-26 08:04 - 2010-08-26 08:04 - 00270336 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-06-29 01:20 - 2010-06-29 01:20 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll 2010-06-29 01:12 - 2010-06-29 01:12 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll 2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-11-17 14:47 - 2009-05-20 08:02 - 00072200 _____ () C:\Program Files (x86)\Launch Manager\CdDirIo.dll 2012-07-15 11:47 - 2010-10-25 15:38 - 00049152 _____ () C:\Program Files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AVEOCamSDK.dll 2011-09-05 19:05 - 2011-09-05 19:05 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\acrotray.deu 2012-02-15 18:52 - 2012-02-15 18:52 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\780c6c210a08fe7f4835bd252e0e4379\IsdiInterop.ni.dll 2010-11-17 15:18 - 2010-04-13 19:52 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll ==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) ========= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.) AlternateDataStreams: C:\ProgramData\Temp:0B9176C0 AlternateDataStreams: C:\ProgramData\Temp:2CB9631F AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F AlternateDataStreams: C:\ProgramData\Temp:798A3728 AlternateDataStreams: C:\ProgramData\Temp:93EB7685 AlternateDataStreams: C:\ProgramData\Temp:CDFF58FE AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D AlternateDataStreams: C:\ProgramData\Temp:E36F5B57 AlternateDataStreams: C:\ProgramData\Temp:E3C56885 AlternateDataStreams: C:\Users\Cristina\Desktop\Kantizeit mit Bettina:com.dropbox.attributes ==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.) ==================== EXE Verknüpfungen (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.) ==================== Internet Explorer Vertrauenswürdig/Eingeschränkt =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.) ==================== Andere Bereiche ============================ (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Cristina\AppData\Roaming\ArcSoft\PhotoViewer\1. 0. 0\PV_SetWallPaper.bmp DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall ist aktiviert. ==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge == (Aktuell gibt es keinen automatisierten Fix für diesen Bereich.) ==================== Firewall Regeln (Nicht auf der Ausnahmeliste) =============== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) FirewallRules: [{841DF0E5-1E8E-4A3F-A237-B1818741566F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD9\PowerDVD9.EXE FirewallRules: [{49DD8EF8-1C98-4E70-86A5-FEA4E85403A4}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{842C4585-04A3-4289-961D-773EBBBDE10C}] => (Allow) LPort=2869 FirewallRules: [{0D32A324-3747-4175-9018-2767F67BE975}] => (Allow) LPort=1900 FirewallRules: [{D2AE839D-3300-4DE1-8632-C0EE688198AB}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{061D46D2-C9ED-4F3F-AB27-FD2C74A0C79E}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe FirewallRules: [TCP Query User{39EECF7A-8161-402B-A2D5-E5F6EBACE91A}C:\program files (x86)\imagej\jre\bin\javaw.exe] => (Block) C:\program files (x86)\imagej\jre\bin\javaw.exe FirewallRules: [UDP Query User{4CC888F5-2CDF-484B-80D2-4114F37A4CA5}C:\program files (x86)\imagej\jre\bin\javaw.exe] => (Block) C:\program files (x86)\imagej\jre\bin\javaw.exe FirewallRules: [{DACCA5B4-7D31-4FE4-B34B-01DEABA5A961}] => (Allow) C:\Users\Cristina\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{0AD58F74-9756-4B99-A378-ABEC205A5E0E}] => (Allow) C:\Users\Cristina\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{F53A8CA1-3BE5-4087-AE5A-2A5366BE07F4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{FD8AA175-6607-4B6B-A986-FA37A38C0A07}C:\users\cristina\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\cristina\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [UDP Query User{FF0ABF66-27DC-4345-89B5-22E8E8A603B4}C:\users\cristina\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\cristina\appdata\roaming\dropbox\bin\dropbox.exe FirewallRules: [TCP Query User{2A87C458-8E79-4DF4-A100-82EEA4A43747}C:\users\cristina\desktop\ba\analyse\fcm\flowjo\jre\bin\javaw.exe] => (Allow) C:\users\cristina\desktop\ba\analyse\fcm\flowjo\jre\bin\javaw.exe FirewallRules: [UDP Query User{27B8A1EA-5015-4E68-AB6C-E1E04B90FBCD}C:\users\cristina\desktop\ba\analyse\fcm\flowjo\jre\bin\javaw.exe] => (Allow) C:\users\cristina\desktop\ba\analyse\fcm\flowjo\jre\bin\javaw.exe FirewallRules: [{630947EB-6751-4DC2-9054-8571552051C1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{E43408DB-4C1D-40CF-B97E-437A4D6858D1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1949BCC7-3E1F-4EF2-A46D-BB4BD1BFE0A6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Riven\Riven.exe FirewallRules: [{37D29F78-EF3F-40AF-B324-196E82A257D4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Riven\Riven.exe FirewallRules: [{713FB57F-9405-4386-8E45-B336019316DD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Myst Masterpiece\Myst.exe FirewallRules: [{D1295EC2-E348-4F4A-B2B8-622895E72950}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Myst Masterpiece\Myst.exe FirewallRules: [{666EB015-495E-44D4-83F6-859D104FEE24}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{E1BD742C-BF6A-40C3-A7C9-C53D32FED525}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{1AD21B18-DA04-4309-9472-9157B03F07FF}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{EA5CEBBE-50BD-49B5-9197-57792F74C97D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{01C370CC-326D-4E78-8E09-204A7DF23014}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1A576346-E4EE-4B4F-995E-C4BDAD14EA4E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{827D0551-6B56-40B4-9348-A00D84E844A1}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Fehlerhafte Geräte im Gerätemanager ============= ==================== Fehlereinträge in der Ereignisanzeige: ========================= Applikationsfehler: ================== Error: (09/22/2015 03:47:10 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FreeYouTubeToMP3Converter.exe, Version 3.11.35.1031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 51c Startzeit: 01d0f53333b509ee Endzeit: 6 Anwendungspfad: C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe Berichts-ID: Error: (09/22/2015 02:31:35 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wmplayer.exe, Version 12.0.7601.17514 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 384 Startzeit: 01d0f53275aefca0 Endzeit: 31 Anwendungspfad: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Berichts-ID: d85b0ae3-6125-11e5-897c-1c7508a9c25f Error: (09/13/2015 02:21:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: updrgui.exe, Version: 15.0.12.398, Zeitstempel: 0x559e22fe Name des fehlerhaften Moduls: MSVCR120.dll, Version: 12.0.21005.1, Zeitstempel: 0x524f7ce6 Ausnahmecode: 0xc0000417 Fehleroffset: 0x000a46bb ID des fehlerhaften Prozesses: 0x8e4 Startzeit der fehlerhaften Anwendung: 0xupdrgui.exe0 Pfad der fehlerhaften Anwendung: updrgui.exe1 Pfad des fehlerhaften Moduls: updrgui.exe2 Berichtskennung: updrgui.exe3 Error: (09/13/2015 02:21:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: update.exe_Avira Product Family, Version: 15.0.12.420, Zeitstempel: 0x55c3aa24 Name des fehlerhaften Moduls: MSVCR120.dll, Version: 12.0.21005.1, Zeitstempel: 0x524f7ce6 Ausnahmecode: 0xc0000417 Fehleroffset: 0x000a46bb ID des fehlerhaften Prozesses: 0x17e4 Startzeit der fehlerhaften Anwendung: 0xupdate.exe_Avira Product Family0 Pfad der fehlerhaften Anwendung: update.exe_Avira Product Family1 Pfad des fehlerhaften Moduls: update.exe_Avira Product Family2 Berichtskennung: update.exe_Avira Product Family3 Error: (05/18/2015 09:39:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (05/18/2015 09:39:58 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (05/18/2015 09:35:06 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (05/18/2015 09:30:08 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (04/05/2015 06:26:01 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (03/08/2015 10:38:33 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Systemfehler: ============= Error: (09/23/2015 07:24:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AntiVirSchedulerService erreicht. Error: (09/23/2015 07:24:23 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AntiVirSchedulerService erreicht. Error: (09/22/2015 02:32:30 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58} Error: (09/13/2015 02:46:44 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Error: (05/18/2015 10:54:04 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Error: (04/05/2015 06:29:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert. Error: (04/05/2015 06:29:15 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2015 06:28:39 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts. Error: (02/07/2015 08:27:09 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C} Error: (02/07/2015 06:40:18 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 ==================== Speicherinformationen =========================== Prozessor: Intel(R) Core(TM) i5 CPU M 480 @ 2.67GHz Prozentuale Nutzung des RAM: 79% Installierter physikalischer RAM: 3958.71 MB Verfügbarer physikalischer RAM: 808.98 MB Summe virtueller Speicher: 7915.61 MB Verfügbarer virtueller Speicher: 4285.5 MB ==================== Laufwerke ================================ Drive c: (Acer) (Fixed) (Total:451.66 GB) (Free:317.17 GB) NTFS ==================== MBR & Partitionstabelle ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 779C6EE7) Partition 1: (Not Active) - (Size=14 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=451.7 GB) - (Type=07 NTFS) ==================== Ende von Addition.txt ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-09-23 20:13:05 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB4O 465.76GB Running: Gmer-19357.exe; Driver: C:\Users\Cristina\AppData\Local\Temp\kgdyrkoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[3232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076871465 2 bytes [87, 76] .text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[3232] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768714bb 2 bytes [87, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe[3244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076871465 2 bytes [87, 76] .text C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe[3244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768714bb 2 bytes [87, 76] .text ... * 2 ? C:\Windows\system32\mssprxy.dll [3244] entry point in ".rdata" section 0000000066a271e6 .text C:\Program Files (x86)\Launch Manager\LManager.exe[5096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076871465 2 bytes [87, 76] .text C:\Program Files (x86)\Launch Manager\LManager.exe[5096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768714bb 2 bytes [87, 76] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5072] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076871465 2 bytes [87, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5072] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768714bb 2 bytes [87, 76] .text ... * 2 ---- EOF - GMER 2.1 ---- Ich habe übrigens sehr viele Dateien auf meinem Rechner (Musik, Fotos u.v.m.). Daher hoffe ich, dass ich das System nicht platt machen muss. Oder kann man diese Dateien vorher ohne Probleme sichern und das System dann neu aufsetzen? Habe Schiss, dass dies dann auch auf die externe Festplatte oder sogar mein Handy überspringt. Nochmals Danke, für die Hilfe und euer Forum! |
23.09.2015, 20:06 | #2 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt hi,
__________________Scan mit Combofix
__________________ |
23.09.2015, 21:38 | #3 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Hallo schrauber
__________________Danke für deine Zeit. Nachfolgend das Logfile von Combofix: Combofix Logfile: Code:
ATTFilter ComboFix 15-09-21.01 - Cristina 23.09.2015 21:54:59.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.41.1031.18.3959.2258 [GMT 2:00] ausgeführt von:: c:\users\Cristina\Desktop\ComboFix.exe AV: Avira Antivirus *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Antivirus *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\users\Cristina\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll c:\windows\IsUn0407.exe c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2015-08-23 bis 2015-09-23 )))))))))))))))))))))))))))))) . . 2015-09-23 20:05 . 2015-09-23 20:05 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-09-23 17:39 . 2015-09-23 17:41 -------- d-----w- C:\FRST 2015-09-23 15:01 . 2015-09-23 20:07 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-09-23 15:01 . 2015-09-23 15:01 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2015-09-23 15:01 . 2015-06-18 06:41 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2015-09-23 15:01 . 2015-06-18 06:41 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2015-09-23 14:49 . 2015-09-23 14:49 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{96D2EB13-965C-437E-A42B-348BF97B2B30}\offreg.dll 2015-09-22 13:55 . 2015-09-22 13:55 18819272 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2015-09-22 13:53 . 2015-09-22 13:54 -------- d-----w- c:\users\Cristina\AppData\Local\Lenovo 2015-09-22 13:51 . 2015-09-22 13:53 -------- d-----w- c:\program files (x86)\Lenovo 2015-09-22 13:51 . 2015-09-22 13:51 -------- d-----w- c:\users\Cristina\AppData\Local\Opera Software 2015-09-22 13:51 . 2015-09-22 13:51 -------- d-----w- c:\users\Cristina\AppData\Roaming\Opera Software 2015-09-22 13:49 . 2015-09-22 13:56 -------- d-----w- c:\program files (x86)\Opera 2015-09-22 13:49 . 2015-09-22 13:49 -------- d-----w- c:\users\Cristina\AppData\Local\TuneUp Software 2015-09-22 13:47 . 2015-09-22 13:47 -------- d-----w- c:\program files (x86)\FreeCodecPack 2015-09-22 13:47 . 2015-09-23 14:53 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft 2015-09-22 13:47 . 2015-09-22 13:47 -------- d-----w- c:\users\Cristina\AppData\Roaming\RPEng 2015-09-22 13:23 . 2015-09-22 13:23 -------- d-----w- c:\users\Cristina\AppData\Local\Dropbox 2015-09-22 13:23 . 2015-09-22 13:23 -------- d-----w- c:\programdata\Dropbox . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-09-22 13:55 . 2012-10-16 06:27 780488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-09-22 13:55 . 2011-06-12 21:10 142536 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-09-13 12:17 . 2013-11-24 10:48 162528 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2015-09-13 12:17 . 2013-11-24 10:48 141416 ----a-w- c:\windows\system32\drivers\avipbb.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{fc01c2be-850b-4115-9b6b-9a427ddecc34}"= "c:\program files (x86)\jetztspielenob.de\prxtbjet0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{fc01c2be-850b-4115-9b6b-9a427ddecc34}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fc01c2be-850b-4115-9b6b-9a427ddecc34}] 2011-01-17 14:54 175912 ----a-w- c:\program files (x86)\jetztspielenob.de\prxtbjet0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{fc01c2be-850b-4115-9b6b-9a427ddecc34}"= "c:\program files (x86)\jetztspielenob.de\prxtbjet0.dll" [2011-01-17 175912] . [HKEY_CLASSES_ROOT\clsid\{fc01c2be-850b-4115-9b6b-9a427ddecc34}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 189464 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 189464 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 189464 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 03:40 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "OfficeSyncProcess"="c:\program files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [2011-07-21 718720] "GoogleChromeAutoLaunch_6250FBC1BFC59B5E9DE82D06B6BF04ED"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2015-08-28 815944] "Dropbox Update"="c:\users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe" [2015-09-22 136048] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920] "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-06-28 265984] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-26 98304] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "AveoSTI.exe"="c:\program files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AveoSTI.exe" [2010-12-02 32768] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2015-09-13 782008] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-09-05 36760] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-09-05 2904984] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-05-07 256896] "Avira SystrayStartTrigger"="c:\program files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe" [2015-08-13 66936] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "ArcSoft Connection Service"=c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe . R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AVEO;USB2.0 PC Camera;c:\windows\system32\DRIVERS\AVEOdcnt.sys;c:\windows\SYSNATIVE\DRIVERS\AVEOdcnt.sys [x] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Avira.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe;c:\program files (x86)\Avira\Launcher\Avira.ServiceHost.exe [x] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x] S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x] S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - MBAMSWISSARMY *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-09-13 12:29 997704 ----a-w- c:\program files (x86)\Google\Chrome\Application\45.0.2454.85\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2015-09-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-16 13:55] . 2015-09-23 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core.job - c:\users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-09-22 13:23] . 2015-09-23 c:\windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA.job - c:\users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-09-22 13:23] . 2015-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-25 12:15] . 2015-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-25 12:15] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 226328 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 226328 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 226328 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2015-08-14 08:16 226328 ----a-w- c:\users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 03:42 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 861216] "XeroxEndeavorBackgroundTask"="xrWCbgnd.dll" [2009-07-14 58368] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392] . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.alawarspiele.de uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://acer.msn.com mStart Page = hxxp://www.alawarspiele.de mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyServer = proxy.zhaw.ch:8080 IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\ FF - prefs.js: browser.startup.homepage - www.google.ch FF - prefs.js: network.proxy.type - 0 FF - user.js: general.useragent.extra.brc - . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) Toolbar-Locked - (no file) WebBrowser-{FC01C2BE-850B-4115-9B6B-9A427DDECC34} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Might and Magic® VI - c:\windows\IsUn0407.exe AddRemove-Uninstall_is1 - c:\program files (x86)\Common Files\DVDVideoSoft\unins000.exe AddRemove-BiotechSIM - c:\windows\system32\javaws.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (S-1-5-21-1416606159-1160031757-1180804506-1000) @Denied: (2) (LocalSystem) "Progid"="Outlook.File.eml.14" . [HKEY_USERS\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (S-1-5-21-1416606159-1160031757-1180804506-1000) @Denied: (2) (LocalSystem) "Progid"="Outlook.File.vcf.14" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_185_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_19_0_0_185_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.19" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_19_0_0_185.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\ Malwarebytes Anti-Malware \mbam.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-09-23 22:21:17 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-09-23 20:21 . Vor Suchlauf: 10 Verzeichnis(se), 339'991'859'200 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 340'032'679'936 Bytes frei . - - End Of File - - 4ADE1A39C8172194ADDA37D54703C71A Nach dem Neustart ging Avira nicht mehr. Malwarebytes hingegen schon, welches sich auch mit einer Warnung meldete und etwas in die Quarantäne geschoben hat. Leider wusste ich jetzt nicht, wie ich hierfür ein Logfile rausziehen kann. Habe dann nochmal neugestartet, damit ich nicht ungeschützt ins Internet gehe. Ich hoffe, dass das ok war. |
24.09.2015, 20:38 | #4 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.09.2015, 22:07 | #5 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Hat etwas gedauert, aber nachfolgend die Logfiles. Aufgrund der Länge musste ich dies in zwei Posts machen. MBAM hat diesmal übrigens nur 123 Funde gehabt: MBAM: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlaufdatum: 24.09.2015 Suchlaufzeit: 21:47 Protokolldatei: mbam.txt Administrator: Ja Version: 2.1.8.1057 Malware-Datenbank: v2015.09.24.04 Rootkit-Datenbank: v2015.09.22.01 Lizenz: Testversion Malware-Schutz: Aktiviert Schutz vor bösartigen Websites: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Cristina Suchlauftyp: Bedrohungssuchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 397021 Abgelaufene Zeit: 21 Min., 56 Sek. Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (keine bösartigen Elemente erkannt) Module: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 19 PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\Toolbar.CT2528046, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Toolbar.CT2528046, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Toolbar.CT2528046, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{144F824B-2B24-4C90-8ACF-5A1C9864676D}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}, In Quarantäne, [f6be1023bccfb284c8ac8210aa5ac13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}, In Quarantäne, [f6be1023bccfb284c8ac8210aa5ac13f], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD7DB970-2E61-457F-9D19-E13D175F7240}, In Quarantäne, [9420ae85d9b2181e6610afe31fe535cb], PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}, In Quarantäne, [faba5bd8d0bb063042261e746a9a946c], PUP.Optional.PriceGong, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [07adef447f0cb28487078c29f50f8080], PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}, In Quarantäne, [6a4a6bc8d9b27abc045798faa85cad53], PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E08A9998-D98F-476F-8F5C-37C80FE0A4DA}, In Quarantäne, [3a7a8ba8d2b9c670b7a4355d758f45bb], Registrierungswerte: 8 PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, ¾Â ü … A›kšB}ÞÌ4, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719] PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, jetztspielenob.de Toolbar, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719] PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{FC01C2BE-850B-4115-9B6B-9A427DDECC34}, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{AD7DB970-2E61-457F-9D19-E13D175F7240}|AppPath, C:\Users\Cristina\AppData\Local\Conduit\CT2528046, In Quarantäne, [9420ae85d9b2181e6610afe31fe535cb] PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046, In Quarantäne, [faba5bd8d0bb063042261e746a9a946c] PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2528046, In Quarantäne, [6a4a6bc8d9b27abc045798faa85cad53] PUP.Optional.Conduit, HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E08A9998-D98F-476f-8F5C-37C80FE0A4DA}|URL, hxxp://search.conduit.com/?SearchSource=10&ctid=CT2528046, In Quarantäne, [3a7a8ba8d2b9c670b7a4355d758f45bb] Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Ordner: 25 PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit\Community Alerts, In Quarantäne, [f6be1023bccfb284c8ac8210aa5ac13f], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit, In Quarantäne, [f6be1023bccfb284c8ac8210aa5ac13f], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\397B5FD0E2674172BCA0ED089CC29E44, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\45C6E9FE0B5748D9B49A9C1FFA7EC684, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\8665B2031BB4494380751AC72D5B7E71, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\OpenCandy_397B5FD0E2674172BCA0ED089CC29E44, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\de, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\en, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\es, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\fr, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\it, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ja, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\nl, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pl, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pt, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ru, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_CN, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_TW, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], Dateien: 71 PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\jetztspielenob.de\prxtbjet0.dll, In Quarantäne, [5f558ba8602b40f6882bbcef0104e719], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\jetztspielenob.de\tbjet0.dll, In Quarantäne, [e9cb52e1bccf76c0c6ed1893ff06659b], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\jetztspielenob.de\tbjet1.dll, In Quarantäne, [4371e94a870493a35d56426913f2f808], PUP.Optional.Conduit, C:\Users\Cristina\Downloads\SpilgamesHeroesOfHellasDe(1).exe, In Quarantäne, [bbf96fc4008bae887c1461f5ed13cf31], PUP.Optional.Conduit, C:\Users\Cristina\Downloads\SpilgamesHeroesOfHellasDe.exe, In Quarantäne, [4371dc570c7fbe78b962b00bf8093ec2], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll, In Quarantäne, [f6be1023bccfb284c8ac8210aa5ac13f], PUP.Optional.ConduitTB.Gen, C:\Program Files (x86)\Conduit\Community Alerts\Alert0.dll, In Quarantäne, [f6be1023bccfb284c8ac8210aa5ac13f], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\397B5FD0E2674172BCA0ED089CC29E44\TuneUpUtilities2012_de-DE_1002180.exe, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\45C6E9FE0B5748D9B49A9C1FFA7EC684\TuneUpUtilities2013_2200212_de-DE.exe, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.OpenCandy, C:\Users\Cristina\AppData\Roaming\OpenCandy\8665B2031BB4494380751AC72D5B7E71\TuneUpUtilities2013-2200214-p2v1.exe, In Quarantäne, [6a4af83b8dfe3afc540f4eb09072bd43], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\background.html, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\background.js, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_freeyoutubedownload.css, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_freeyoutubedownload.js, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo.ico, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo_128.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo_32.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\dvs_logo_48.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\errorRunProgramm.html, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\manifest.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\np_dvs_plugin.dll, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\options.html, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\options.js, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\page_action.html, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\backbar.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\download.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\fs.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\headphone.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\logo.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\manager.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\YoutubeDownloader.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\images\YoutubeToMp3.png, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\de\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\en\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\es\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\fr\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\it\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ja\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\nl\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pl\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\pt\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\ru\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_CN\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.DVDVideoSoftTB, C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.0_0\_locales\zh_TW\messages.json, In Quarantäne, [d2e2cb68c4c742f4e89b0710b54e53ad], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\1.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\a.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\b.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\c.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\d.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\e.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\f.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\g.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\h.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\i.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\j.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\k.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\l.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\m.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\n.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\o.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\p.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\q.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\r.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\s.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\t.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\u.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\v.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\w.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\x.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\y.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], PUP.Optional.PriceGong, C:\Users\Cristina\AppData\LocalLow\PriceGong\Data\z.txt, In Quarantäne, [526290a32863082e9aa4d74e679c7d83], Physische Sektoren: 0 (keine bösartigen Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v5.008 - Bericht erstellt am 24/09/2015 um 22:30:45 # Aktualisiert am 18/09/2015 von Xplode # Datenbank : 2015-09-23.1 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : Cristina - CRISTINA-PC # Gestartet von : C:\Users\Cristina\Desktop\AdwCleaner_5.008.exe # Option : Löschen # Unterstützung : hxxp://toolslib.net/forum ***** [ Dienste ] ***** ***** [ Ordner ] ***** [-] Ordner Gelöscht : C:\ProgramData\Trymedia [-] Ordner Gelöscht : C:\ProgramData\Driver Mender [-] Ordner Gelöscht : C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936} [-] Ordner Gelöscht : C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [-] Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Mender [-] Ordner Gelöscht : C:\Users\Cristina\AppData\Local\PackageAware [-] Ordner Gelöscht : C:\Users\Cristina\AppData\LocalLow\Conduit [-] Ordner Gelöscht : C:\Users\Cristina\AppData\Roaming\dvdvideosoftiehelpers [-] Ordner Gelöscht : C:\Users\Cristina\AppData\Roaming\RPEng ***** [ Dateien ] ***** [-] Datei Gelöscht : C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Geplante Tasks ] ***** ***** [ Registrierungsdatenbank ] ***** [-] Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com [-] Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [-] Schlüssel Gelöscht : HKCU\Software\Softonic [-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar [-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit [-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Toolbar [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Trymedia Systems [-] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA} [!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\Softonic [!] Schlüssel Nicht Gelöscht : HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\AppDataLow\Software\Conduit [!] Schlüssel Nicht Gelöscht : HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\AppDataLow\Software\Toolbar ***** [ Internetbrowser ] ***** [-] [C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Gelöscht : nikpibnbobmbdbheedjfogjlikpgpnhp ************************* :: Proxy Einstellungen zurückgesetzt :: Winsock Einstellungen zurückgesetzt :: Internet Explorer Richtlinien gelöscht :: Chrome Richtlinien gelöscht ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2595 Bytes] ########## Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015 durchgeführt von Cristina (Administrator) auf CRISTINA-PC (24-09-2015 22:44:25) Gestartet von C:\Users\Cristina\Desktop Geladene Profile: Cristina (Verfügbare Profile: Cristina) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 9 (Standard-Browser: IE) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-12] (Acer Incorporated) HKLM\...\Run: [XeroxEndeavorBackgroundTask] => rundll32.exe xrWCbgnd.dll,LaunchBgTask 1 HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-11] (CANON INC.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation) HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-26] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [AveoSTI.exe] => C:\Program Files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AveoSTI.exe [32768 2010-12-02] (AVEO) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [782008 2015-09-13] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-13] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [718720 2011-07-22] (Microsoft Corporation) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [Dropbox Update] => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-22] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{7E454ECC-55E1-487A-B353-85FC9C82C45F}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{E17B3D49-001E-469C-BF7F-2306104338C0}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.alawarspiele.de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.alawarspiele.de HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = SearchScopes: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-06-12] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-06-12] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-27] (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-29] (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-27] (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> Kein Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Keine Datei DPF: HKLM-x32 {4A85DBE0-BFB2-4119-8401-186A7C6EB653} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/mjss/MJSS.cab109791.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll Keine Datei Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll Keine Datei Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-29] (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default FF Homepage: www.google.ch FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] () FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] () FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-06-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-06-27] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll [2012-01-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-22] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-22] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\Extensions\abs@avira.com [2015-09-22] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-09-22] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-25] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\ppGoogleNaClPluginChrome.dll => Keine Datei CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\pdf.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\gcswf32.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Profile: C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browserschutz) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-02-07] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-18] CHR Extension: (Google Wallet) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-24] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [887128 2015-09-13] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [461672 2015-09-13] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [461672 2015-09-13] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1213072 2015-09-13] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [228104 2015-08-13] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.) S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [346496 2012-02-08] (AVEO) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [162528 2015-09-13] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-09-13] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-31] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-04-05] (Avira Operations GmbH & Co. KG) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-24] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-24 22:44 - 2015-09-24 22:44 - 00021706 _____ C:\Users\Cristina\Desktop\FRST.txt 2015-09-24 22:41 - 2015-09-24 22:41 - 00114894 _____ C:\Users\Cristina\Desktop\JRT.txt 2015-09-24 22:34 - 2015-09-24 22:34 - 00002678 _____ C:\Users\Cristina\Desktop\AdwCleaner[C1].txt 2015-09-24 22:26 - 2015-09-24 22:30 - 00000000 ____D C:\AdwCleaner 2015-09-24 22:24 - 2015-09-24 22:24 - 01798976 _____ (Malwarebytes) C:\Users\Cristina\Desktop\JRT.exe 2015-09-24 22:23 - 2015-09-24 22:23 - 01662976 _____ C:\Users\Cristina\Desktop\AdwCleaner_5.008.exe 2015-09-24 22:23 - 2015-09-24 22:23 - 00023786 _____ C:\Users\Cristina\Desktop\mbam.txt 2015-09-24 21:50 - 2015-09-24 21:50 - 00000000 ____D C:\Users\Cristina\Desktop\Logiles 2015-09-23 22:21 - 2015-09-23 22:21 - 00027138 _____ C:\ComboFix.txt 2015-09-23 21:53 - 2015-09-23 22:21 - 00000000 ____D C:\Qoobox 2015-09-23 21:53 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2015-09-23 21:53 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2015-09-23 21:53 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2015-09-23 21:52 - 2015-09-23 22:17 - 00000000 ____D C:\Windows\erdnt 2015-09-23 21:50 - 2015-09-23 21:50 - 05635484 ____R (Swearware) C:\Users\Cristina\Desktop\ComboFix.exe 2015-09-23 19:39 - 2015-09-24 22:44 - 00000000 ____D C:\FRST 2015-09-23 19:38 - 2015-09-23 19:38 - 00000000 _____ C:\Users\Cristina\defogger_reenable 2015-09-23 18:20 - 2015-09-23 18:20 - 02192384 _____ (Farbar) C:\Users\Cristina\Desktop\FRST64.exe 2015-09-23 18:20 - 2015-09-23 18:20 - 00380416 _____ C:\Users\Cristina\Desktop\Gmer-19357.exe 2015-09-23 18:19 - 2015-09-23 18:19 - 00050477 _____ C:\Users\Cristina\Desktop\Defogger.exe 2015-09-23 17:01 - 2015-09-24 22:43 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-09-23 17:01 - 2015-09-23 17:01 - 00001110 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-09-23 17:01 - 2015-09-23 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-09-23 17:01 - 2015-09-23 17:01 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-09-23 17:01 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-09-23 17:01 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-09-22 15:55 - 2015-09-22 15:55 - 18819272 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-09-22 15:53 - 2015-09-22 15:54 - 00000000 ____D C:\Users\Cristina\AppData\Local\Lenovo 2015-09-22 15:51 - 2015-09-22 15:53 - 00000000 ____D C:\Program Files (x86)\Lenovo 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Opera Software 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Users\Cristina\AppData\Local\Opera Software 2015-09-22 15:49 - 2015-09-22 15:56 - 00000000 ____D C:\Program Files (x86)\Opera 2015-09-22 15:49 - 2015-09-22 15:49 - 00000000 ____D C:\Users\Cristina\AppData\Local\TuneUp Software 2015-09-22 15:47 - 2015-09-22 15:47 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack 2015-09-22 15:45 - 2015-09-22 15:46 - 44183312 _____ (DVDVideoSoft Ltd. ) C:\Users\Cristina\Downloads\FreeYouTube914ToMP3Converter.exe 2015-09-22 15:33 - 2015-09-23 19:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-09-22 15:24 - 2015-09-22 15:24 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-09-22 15:23 - 2015-09-24 22:28 - 00001236 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA.job 2015-09-22 15:23 - 2015-09-23 16:54 - 00001184 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core.job 2015-09-22 15:23 - 2015-09-22 15:23 - 00004212 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA 2015-09-22 15:23 - 2015-09-22 15:23 - 00003816 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core 2015-09-22 15:23 - 2015-09-22 15:23 - 00000000 ____D C:\Users\Cristina\AppData\Local\Dropbox 2015-09-22 15:23 - 2015-09-22 15:23 - 00000000 ____D C:\ProgramData\Dropbox 2015-09-22 14:21 - 2015-09-22 14:26 - 00009482 _____ C:\Users\Cristina\Desktop\Menukarte.xlsx 2015-09-13 14:16 - 2015-09-13 14:16 - 00001142 _____ C:\Users\Public\Desktop\Avira Launcher.lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-24 22:44 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-09-24 22:44 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-09-24 22:39 - 2011-01-28 06:32 - 01576315 _____ C:\Windows\WindowsUpdate.log 2015-09-24 22:38 - 2011-10-25 20:15 - 00000000 ____D C:\ProgramData\AlawarWrapper 2015-09-24 22:35 - 2012-04-25 20:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-09-24 22:34 - 2011-09-12 21:58 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-09-24 22:32 - 2012-04-25 20:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-09-24 22:32 - 2011-01-28 06:29 - 01925290 _____ C:\Windows\PFRO.log 2015-09-24 22:32 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-09-24 22:32 - 2009-07-14 06:51 - 00108347 _____ C:\Windows\setupact.log 2015-09-24 22:14 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Performance 2015-09-24 22:12 - 2011-07-05 10:29 - 00000000 ____D C:\Program Files (x86)\jetztspielenob.de 2015-09-24 21:53 - 2012-10-16 08:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-09-24 19:42 - 2011-05-07 18:23 - 00000000 ____D C:\Users\Cristina\AppData\Local\Adobe 2015-09-24 19:36 - 2012-10-28 14:42 - 00003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{14B239D9-506D-40CB-84F9-C01CAED49E02} 2015-09-23 22:21 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2015-09-23 22:08 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2015-09-23 19:38 - 2011-05-05 19:56 - 00000000 ____D C:\Users\Cristina 2015-09-23 19:28 - 2012-05-03 19:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-09-23 17:01 - 2011-05-08 23:25 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Malwarebytes 2015-09-23 17:01 - 2011-05-08 23:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-09-23 16:53 - 2012-11-21 21:34 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2015-09-23 16:53 - 2011-08-07 12:44 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\DVDVideoSoft 2015-09-22 15:56 - 2012-10-16 08:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-09-22 15:56 - 2011-05-05 20:00 - 00001451 _____ C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-09-22 15:56 - 2011-05-05 20:00 - 00001417 _____ C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2015-09-22 15:55 - 2012-10-16 08:27 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-09-22 15:55 - 2011-06-12 23:10 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-09-22 15:51 - 2010-11-17 15:28 - 00000000 ____D C:\Windows\Downloaded Installations 2015-09-22 15:49 - 2012-06-01 20:33 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\TuneUp Software 2015-09-22 15:48 - 2012-06-01 20:33 - 00000000 ____D C:\ProgramData\TuneUp Software 2015-09-22 15:25 - 2011-10-03 20:45 - 00000000 ___RD C:\Users\Cristina\Dropbox 2015-09-22 15:25 - 2011-10-03 20:44 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Dropbox 2015-09-22 14:40 - 2012-01-11 10:41 - 00000000 ____D C:\Users\Cristina\Desktop\Musik 2015-09-22 14:30 - 2012-04-25 20:40 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-09-22 14:30 - 2012-04-25 20:40 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-09-13 14:31 - 2011-07-03 16:31 - 00000000 ____D C:\Users\Cristina\Documents\My Games 2015-09-13 14:21 - 2012-03-29 11:08 - 00000000 ____D C:\Users\Cristina\Desktop\Operation Handyfotos 2015-09-13 14:20 - 2013-11-24 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-09-13 14:17 - 2013-11-24 12:48 - 00162528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-09-13 14:17 - 2013-11-24 12:48 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-09-13 14:16 - 2014-09-01 20:20 - 00000000 ____D C:\ProgramData\Package Cache ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2010-11-17 15:30 - 2010-03-03 01:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Einige Dateien in TEMP: ==================== C:\Users\Cristina\AppData\Local\Temp\avgnt.exe C:\Users\Cristina\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-09-22 16:19 ==================== Ende von FRST.txt ============================ |
24.09.2015, 22:08 | #6 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Und hier noch JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.6.2 (09.14.2015:1) OS: Windows 7 Home Premium x64 Ran by Cristina on 24.09.2015 at 22:36:02.66 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_6250FBC1BFC59B5E9DE82D06B6BF04ED ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer ~~~ Files ~~~ Folders Failed to delete: [Folder] C:\ProgramData\alawarwrapper Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{004D0F1B-0AD6-48CA-9894-4C6B8B32F37B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0057DE6A-46C7-4476-BAF5-CA05771E779D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0079E933-2A36-4129-BF51-9AB0D491D366} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{018E5A3C-A408-4BBF-9B12-438568F2FC23} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{01E54C26-DFD4-4A43-AE16-6496364B4B9A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{01F52932-C6E5-4F79-B3DC-658C53AACB38} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{02B51859-1D03-41A7-B18C-5E06F4C08604} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0348EA0D-9E21-46E9-9409-F5E972ACE9CB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0357ACF8-6A52-462D-8492-2D46EFB960EF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0367102D-CE17-4A6C-9777-9FDBF48BD1F3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{03F7A9AD-F61B-4BBF-9A42-BCCAA3B4672F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{04C5EFD4-246E-4E5A-A583-154CB1BBBE56} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{04F754DB-C57E-44C4-A849-10E8A350A64A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{056AEBDF-B6BD-464D-A27F-73332FEC8106} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{059301E0-2BFA-44E0-9541-9F57A80CA520} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{05987B95-EFF5-48B8-A238-5A54744DA2B4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{05BFF62B-5F50-4785-8D3C-971C696D8ADF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{05F35293-5C79-42F0-83DC-F3C1150635DF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{063C39C2-A437-44D4-9924-7EFAEEC80510} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0641F201-224C-41F7-87D7-B8095B505D56} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{066A5559-0DD3-4A4F-A806-51B187A76385} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{06ACCB58-A02C-4219-A391-C4F18AFAA60F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0752E861-1D5C-4AA4-AEB0-D56E244BDE8E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{076D5B8A-18CC-44FA-B91B-04C8368F0B88} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{07C1CEF3-1A85-4FF2-9A8B-E6E0B5AAED43} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{07FC0AE8-4738-4A57-AC15-FC0978518172} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{08141CE6-3AB1-4336-9F5D-9FE50DEF9AF5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{088AB45A-CED7-40AD-BA16-A9A9355AC6AD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{08D5A20A-8B6F-4A04-A40C-50691D57E264} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{08E4CB18-0474-4587-9EEA-222A3044847D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0904F006-6DA6-48B2-BCC1-EF321E384F3B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{09B0E8E2-59B5-44B0-9BDF-ADFE7CC5225A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0A0F2009-1677-487D-B2BA-611FE8B08332} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0A8C5EE9-B8CE-40F5-9AF2-DF2365FDF278} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0AA8CD53-FFA0-4735-A2D9-EFC5A4612CD3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0AF7A033-77E4-4BF3-8FE2-35F8F6C2853C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0B12D371-C3B6-42E9-B9AA-E63ACAA4C6C7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0B363370-5624-49E3-9C10-29309784C5B4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0B4F1671-6359-4752-9C46-C937C22675DB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0BBB152B-BFDC-4CF9-8CF3-5D06269C0C80} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0BBC149C-DAE6-47DE-9E11-768DA8CB184D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0BBF7F11-6D66-435F-B54E-A62A4E218640} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0BF1D8A1-6CA4-4B6D-A124-D3C3757CC187} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0C7CB186-2A15-4AEE-A050-88D5C1ED2E01} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0C8D3649-EF21-4665-9878-C0BB166118A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0CE45B3E-E638-49E0-99C9-AB83B6F9D017} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0E22F166-3B86-4B21-9280-2F3E2A7C5D5E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0E42108B-F0CC-4090-806F-D444841E537E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0E4F6853-7B68-438D-8456-8E32F0F2F4BE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0E7C1DCD-1C61-4B74-B8A1-F7868B1ADFEA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0EA9DEF1-B969-46FE-A3B6-5B0B11E6755B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0EBE17B3-20A4-44C6-8CA3-0D4E3FC37B3F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0ECE3A8E-DC79-4419-8125-28F13A40ABDE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0ECFED2E-C3B1-4562-A8F0-65DD7F7FBEE2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0EDFA3E4-BD7C-44C5-8CFD-D6E3A4805B50} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0F05A0CB-9BD1-49F6-BF3C-40FF6ACABFE6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0FA63E08-E6E0-4C7E-80BA-99218667AE59} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0FB17DFB-E31E-4761-A7FF-8CD0E32F50E3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{0FDC221A-C6F5-4916-A73E-8820C389DED0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{10356AB1-7F13-4F85-BCC5-325BE3D6E219} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1055D5CD-D53C-4A3E-BFCF-805BD7E0FD7D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1079E2BC-DD31-414A-99E9-D4E35AAC8F22} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1098100C-5D32-4DD0-9C04-73746EAEBCC0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{10ABB137-CED3-49E0-9583-4CDEC46E8AEA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{10E1BB92-541E-45A3-AC23-F42334270550} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{10F6D65E-066C-41BF-9E3E-D1A9A7027C17} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1105102B-A7BF-437C-8538-DC4688EF19C1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{110777F0-B431-4AC1-99AB-4298D5722C22} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1213B645-6688-405E-B169-9C2F5060583E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1213C380-66C2-4439-B8AF-A9DEABF658A3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{127F4C88-B36C-486B-BCA9-AF8B33B40009} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{12E1C1BC-B6FB-44BC-9327-96CAB368049C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1301460D-57DD-40C8-9C87-0BE2D4E330A5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1347E3AC-0045-42AD-B38E-72EF050E9481} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{137BDDAC-4F1C-419A-9185-2764D2E849C3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{139B0498-B720-4D76-A77F-59AC55C3BBDD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{13EE55F2-E67D-4527-B2FE-07BC86EC1AB5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1432EFCF-A0EB-45BB-A2E9-3C64FAF0CD80} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{14B550BB-F0D4-41B2-B05A-80BD8348429E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{14E2FFEC-7AEE-418D-BD4A-21D0C0F00D3F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{15264C18-8ADF-412E-95E7-A14EF19F523A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{152A41CF-71EB-42BA-BB68-11F1BBCD443A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{154CF888-EA74-4BD8-B623-56FFACC18079} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{15E4B8FA-2E66-43FB-BBAF-0D425E132ED7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{15FE886D-1D62-4C6B-985D-4CEE5C9E8026} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{165D08A7-54E7-49BC-9837-E3E413EE7AF0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{168CF4B8-08A3-4718-B3AC-828E7186ED82} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{16E7E318-C17C-4135-8345-3C15B88869F4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{16FFF638-2634-4E6A-A000-2B8DE7ABC49C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{17FF5E2E-3530-49E0-9012-FC795920EF3A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{186E934A-DD4E-43B3-AB3B-DD33C904224B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{18AF7CA2-5CE7-443F-8923-2921BE9FB603} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{18DB58DB-99AC-4891-8B2C-3A8A7B123BA4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1923E546-D574-4CA2-B73B-6346DFB19DC2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{19D18EA3-73C7-431C-ACF1-A5C5D1DC025A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{19D99B20-BA69-4C4E-BE68-D4C9AED12DC1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1A0F81A3-7C5C-4F2B-97C1-34FB140205F8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1A113A8D-19F2-4614-8407-FC185B1D4414} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1AD840EA-F4D8-4F0F-9B1E-92303B8EBB97} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1AE678D6-8A2E-4133-914B-C16AE0698D73} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1AFBD953-18CE-4AB1-9620-70FD3C8A879A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1B005D76-8C5E-45FF-8456-9044B34A9338} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1B366EB5-2C8F-4A1B-8249-84F3DF70B598} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1B60AD04-6529-4C57-A718-608AE15885DA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1BA9088D-C385-480F-968E-80F4EB631F74} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1BCBEA3A-A04F-4EF3-9D4C-0BD3A6072F7C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1C0ABC84-1AA1-4413-B3DF-ACB31B99AE26} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1C46E676-83EC-4995-B0DD-B93105A1B0CF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1C4A4684-5491-4826-BD94-29D0664BB7FB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1C723878-9937-4055-81FB-5557D90B48F8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1D9714CD-5CAC-4EF2-B911-B5C6EEAF211A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1DC78F86-E6CD-492A-B380-06DBE05A09D0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1E2C445A-A0B3-4141-BAA4-FC0A04EC930A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1E7DC318-C1B1-49D1-B903-99DD0930BF4A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1E892BA5-7BFA-4746-B193-CE444CD48349} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1EECC808-7F0A-4904-B11E-E671FC92C016} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1F0936AE-21EF-4944-8C5A-1CA236408655} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1F2217B4-600A-4639-B9B9-7C340EB0751F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1F5C1BDE-D027-4BAC-A8CE-E1211A6D70B4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{1F86041A-2E15-4D6D-A3EC-627712F0740D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2001A351-9AF8-4BD4-80C3-8F6904D542B1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2016079B-E132-4911-BAD6-CCC91852867D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2058FF96-495D-4507-B88C-D63A122D2F5E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{20747FC7-C44E-4AF2-B87B-94C5719650F0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{209488FE-CA25-4454-9796-36779CD5F2F3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{20E9C059-98C1-411F-9DB8-D0AB7FEC3DF1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{213A6055-82D6-47E3-9E43-13998D2CA0A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2156C582-87BE-4DCC-9A95-09EF1BF01566} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{216C789E-6A3D-4BF5-A46F-806BB0D2B2EA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{21838497-1B31-43D8-8152-D43BAAAD6D46} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{220EDD69-D804-4BA6-B6CA-FB153ABCC365} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2287BBEC-4164-4B75-AAF7-AF02459F8172} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{22A6CC0D-AACD-4607-86E3-D7705985C299} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{22DF9091-F4C1-4B0C-A891-1BBAA2A134B9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{22E54F25-5DDD-4B29-B716-5F1B6837178B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2324533A-8336-43BA-B2A0-20ADE2A9FAFE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{23312103-C60F-4B0F-B580-506E33282097} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2351072F-BD1D-4253-B2AE-78B6595566AA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{235B6743-7842-42B8-8568-704D9BF7E257} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{23BFE7C6-6377-4DF3-816F-F096A6BC57AA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{23C9E4F2-E1D8-41FF-A43F-04B452A7211A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{23CC0087-F679-4BFB-B6FC-9B9BC8EFBD6C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2401216C-D25B-4F1B-A887-9419683E4855} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{24CAD630-BBEB-42A6-94F8-91CB7B6CD4B6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{24E4D65F-8CCC-468E-BE34-2516F81E7190} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{24F22644-B914-4873-A7F4-7A6B520E01FC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{253D0A06-10BC-477C-80E2-B95EB0E1E610} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{25889C10-15F2-4F55-BA37-59CFDD14A6F9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{25BAD767-F485-40DA-8EC8-C529E00D82D4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{26B641BA-F7BA-4FF9-AE48-4461E2B345E6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{26B7FC40-08A7-4302-9EEC-0F810CE4594C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{26BED897-8928-486A-B8B7-12131C4136EB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{26F5151A-0BF1-4D93-A68B-F0030329FE99} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{27129E7F-5215-433F-9F96-DAB4AB6B55CB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2751B373-5283-41EF-961B-16CDC267D984} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{27A318E2-ADE2-42C4-935A-B80D79B6D4E2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{284D7B06-7EFE-4C3C-9DE3-B33B1E47D734} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{28919A78-8CC3-4DC0-A572-88FD6292C498} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2899DC1D-57B9-4797-BA04-83E3158C97CB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{28AD9661-3D42-4C90-991B-C04E6124818A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{28C7676F-984C-4C0F-873A-A0143E7B7A95} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{28D0A4DC-4DE4-43BE-97CA-0F1C1A650052} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{28E77010-D5DA-4EC8-A9F5-9431F5F725F0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{28FAC6F2-2675-4B0B-87E0-477251951881} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2B674951-D0C5-43C7-93A6-9957EC05B245} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2B920D5E-F62F-469C-BD01-7EBACE15AC91} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2C64D7AF-FEB5-4441-891C-6B3CBB450F26} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2C918F22-6061-45FB-A3EB-3C64225FFCC9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2CD30C60-33A8-4876-9BF9-94FDABA61EA5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2CD956A6-4E6A-42E5-91C9-C8606D0CA936} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2D21A613-A566-4C1F-B3F1-466E81DF2107} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2D2C5364-1EE9-4879-8527-A044DBB3EE71} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2D3ADF39-E129-461F-83A3-A9B47EC463EF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2DAA79F9-A0E0-44FE-9D42-7E34DB7E7B7D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2DB9FDA0-FEFE-4377-8BF9-A2E5ED12D6AC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2DDEC1AF-707A-47AB-9F6E-3EC00ECB0601} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2E240248-1C55-43BE-B69E-796A03C19EF8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2E907B67-298D-4FA3-A584-9A3D6D1C63A5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2EB87AA0-B05C-40C9-8D30-1DCEE18143C6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2F0B4CFF-0CAE-4736-8D3F-54E75DBE1E88} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2F14963F-9FD1-4501-BBA9-22B2409CA77D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2F6C32F3-3114-44A2-BED9-C24BFA5FD116} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2F7DC9DF-ED24-498C-B506-4F830A6DFC9D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2FAE00C6-C0A0-4A41-BB70-F2D46E6577C4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2FAE21CD-ADC9-4C40-9AD3-62A460E22DE7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2FB9620D-395F-4EC6-A91D-460B51872376} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{2FF4CD5A-2869-4339-A333-504972F7D0FD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{30E90769-63AA-448C-B3D8-D3DB647699BD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{31376D9B-7DC0-4C3A-BFE7-875C837C1C20} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{31AA980B-46C4-4E3B-920F-19F3C89E9BA2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{31CEFD41-D020-463F-B213-0C1B00D32356} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{321B2D25-C308-408F-A370-CF2BE95976BA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3237B56A-C1C4-4A43-BDEC-6082598047C3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{32707A6F-4D54-4EB3-B455-7287BB7C8A99} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{32830316-7F88-4BD2-91A0-2B5E13934E2B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{32E624DF-AC74-4B12-AFC8-DBA76A64EE7C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3349DFB4-B8A3-421A-A942-ECF8F1124280} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{33DAA5F1-5708-4AA6-AA2D-CF1ACEB3049F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{33EFDE41-8F5E-47CB-BCE7-624861F34425} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{348EEC89-F813-4FFB-9203-B017A5AE7C9A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{34B1F887-BDE3-4300-A4EE-FC79C26018E2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{34D917AA-6B31-4838-A8F1-4235E008E4EB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{34F104AC-0DAF-4163-ACD2-7F40CA250D24} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{35711AF0-1CB2-47B8-81D3-5922D4AA576E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{359B68E8-201B-4AA7-885B-0FB9724C156A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{35CCCE64-9F6C-450A-B024-221592D6E9F3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3619DED4-8D11-43E8-81C9-088F10BBC540} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{37B96331-23E8-4327-BABC-D47C6FE4C77E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{381132D0-408E-4165-B32D-A964D07A737C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{38187672-610D-45BB-958A-1538043BA49F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{384F986D-E7C8-497E-8ABA-FC48014ABA7C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{387D48CE-9610-465F-84C2-ECA1A0AF345F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{38A60421-46A0-4ABE-A594-8140085B4914} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{38DFB769-3240-4BBE-8CB2-29CD078C7BE8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{392FCA2F-BDE9-4290-AFA3-6C9EC6467467} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3966FBC0-8A21-4CDD-BA65-AFFFE53998BF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{399F0EC0-FCA9-474B-ACB6-CB33AD26D23A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{39A563E4-9721-491A-B151-F54572D74319} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{39A65A26-A6F7-4484-A646-129ADE7B8440} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{39B7589C-CD2C-4257-87D2-59319FAB29A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{39FCCB2B-2916-4A5A-A752-0D39331D3129} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3A0385C1-E4DC-40D3-990C-0CC45F6E3843} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3A254E63-A6A7-4E3C-9A01-C9C59FA5318D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3AEF846E-B14A-4BFF-A45F-2410A215A711} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3AEFC470-B971-443F-B185-2BAE2529DFCB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3AFE0A72-5499-49FD-AE96-6F00FC877878} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3B07DFE6-09C3-4341-B9D6-FA4754866AE5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3B129185-1533-4F2E-B795-16CC7F419D90} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3BC70161-BF1C-4871-A2C7-DC022502CA42} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3BF95B38-CD8F-47BF-BADD-5C0AFED3D10A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3C16D837-126E-46B4-B2A5-1264F91032DA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3C8178CD-7348-4855-9A01-9F11B4F231A2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3D010974-F394-46B8-B775-253264AFADFC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3D342F10-4181-4E10-8E46-60DF031A137F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3D407DA3-C2F3-4BF7-AA41-8927A26D8110} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3D502F82-B5B0-45B8-B5B2-A9763791188D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3DA4E353-C611-4CB0-BAB2-30F78B281154} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3DB897F3-E4E0-4F94-93A6-5753103F960B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3DE43893-BFB7-4A0C-AA03-0109DA0003EE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3DEF5103-F4D4-406A-8121-D26641764828} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3E5481C2-8AE9-4497-81C2-96D793807AA3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3E673504-41F4-41B2-8FBE-47905BF4A345} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3E7D7712-5A5F-4DB4-B756-D6AC4CE44567} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3EB1874B-8D77-4373-BF02-DA5EC9E7C46C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3ECDC709-5A87-421B-A0E0-F46DAA0A68E6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3ECE2D7C-253A-4DEB-BEFD-FCEC24975087} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3F8684D1-F7AE-41C5-B940-6D2CB080DFF5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3FB396FF-CC3C-4904-B882-E2E109695DA2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{3FE1878D-1155-43B7-9A2E-BAC2E04EB32A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{40138C1C-3295-40E5-BDE8-26FCD72756B3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4037D329-E76A-465B-92F6-A94374C7ED82} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{404379A7-F89A-40E3-803E-3A357F5A422E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4044F4FF-165C-48C9-A60D-D829061D6651} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{419563B1-721E-419E-8D79-63398AEDABC0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{41DCE69B-83AC-4107-915A-A838B7B19A46} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{425CF520-D53A-48ED-9773-75DC922FF65A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{427D868A-A252-46AD-B34B-E79D371DA023} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{42C906FC-8E81-44A7-8C9B-5B4FB519D1AD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{42CBB7C7-519F-4EFD-8B15-539D7A156C31} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{432B044B-201E-4920-937F-86D0CAEC6406} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{432C0EF6-9C9C-4D1B-B230-45800ED32771} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{432CF0AF-34C3-4884-BEEA-4A44F7286BDE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{436D699C-F975-41B2-A2C5-935FFBD89772} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{43A550C7-076B-4216-9AD0-597A4991D860} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{43B3A093-AE28-4C3D-A843-C774E4A879D2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{43C464B0-56EF-441D-8790-011FFB236925} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4419DD61-7B19-4617-8AC7-DFA9BB0FAD99} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{44421D60-A07B-48A3-A97D-462E17AE7B94} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4443CC99-8733-414E-917B-5C3A398B1848} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{44DDA6AB-BF9A-492B-8612-825080F36C6A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{44F2F84F-E5F2-4DD7-AA0F-3280C5B3C0F3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{45B1C265-E721-4837-BFFB-B5E736EDDF26} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{45C854D3-4B4B-4226-9C23-7F2F803E2E8B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{45D0AC3E-F437-4A7E-A0EC-A580DAF34673} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{462AB649-4FD8-49D2-A443-78D8A4313623} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{46427693-B59E-4F68-88BB-229AA91DF50D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{46CF9410-0FCA-402D-80B8-3C1C9AC6B41A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{473AFCBB-6931-4F47-B946-A4C197D24D4D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{475D940A-F908-40B7-B71D-F1307BBCCDF3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{47C154B3-5BBA-4E8D-A98C-5E174BB427C8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{47CF55AE-A359-4F09-A7AC-4760E368CD43} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{485766B8-3265-4454-8B98-9B7057104994} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{48D758A5-FA16-4B44-A4A4-4B0033CCB707} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{49443B6E-03EF-4310-95D7-93326BFC11D9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{49786EF6-D015-4C1C-A0D2-C6AF182BD39F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{49AC4DBF-6A7E-4B4D-9E6D-63844169BC01} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{49F66A1B-3873-417F-AAF0-F719E049A60E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4A0B5460-EAF1-4597-8E43-A3FC431C8A46} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4A51AA99-8B1A-481D-BD41-19A6ABF6235F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4B09A18E-51A3-451E-897F-23346831771C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4B0A35B4-FC85-4FAC-BA7B-BB4662EB2BB8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4BD43A9B-B886-4DA1-A646-196A084E4B20} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4BE90461-0D89-4D89-BB40-EA8656828099} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4C88CA5E-151D-48A7-B836-45BEE3A2E331} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4C8DEFCE-3E0B-493A-8474-57FDD7751494} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4CD79F11-B92A-4E3D-A84C-1C23CF44E293} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4CEDF10E-38FF-4CD6-8787-553D06B34D98} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4D28E699-6194-4AD9-BD74-264C9708DA6B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4DBF2FCE-C165-4818-88AF-A790D93D7BAC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4DE31062-3847-442A-BF58-98D48524D541} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E190359-65C0-4C3F-8457-143D2CD110CD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E2ABEF6-6190-4055-BE56-D9A8FB64DF51} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E3086C6-AF08-43F3-91C6-BA9D12720266} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E4D7AEC-11B8-4B77-8A2C-BDD99FDED02C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E529D00-E2B0-4DE7-8CF2-11AA628689E3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E94DE33-870F-45B8-B5EB-E75200AEFEDC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4E951410-437A-4DF4-BC72-ED2896DC20D2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4EB90D6E-2E0F-471E-849D-43BF96168F1A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4EBCBF53-831E-4920-963E-6C098A735DA0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4EFEEBFC-C7CF-4FD9-A6D7-C51D3585C54B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4F11A9EF-E7D1-4CCC-89F2-DB23451C2EF1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4F7235C4-94C7-4936-90BE-F9FBB2F3870B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4F7FE284-A029-415B-B02F-6AF6D8804DEE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4FA04A05-C4EA-4D8E-B7DF-BA4EB593F03B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4FBBEB30-B4C0-4139-B3E3-9CA5592BE43A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{4FD5B825-3DB3-4205-A289-E6EBEC4CBC0F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{50032E7A-313F-4AAF-A4EA-2193FAD827F2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{503E4AFE-4E77-428E-A8B4-713789B2CFD1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{50515ECE-C762-49A4-8C4B-2B7FC97AC8BE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5095D3F9-8FDF-46A2-BFF3-8E02F2D3C724} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{50F28467-AB53-45AF-A5B9-9FCBB6B5D116} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5101FA4A-2647-4D6A-B8C1-031703160829} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5106F030-BB3E-49BB-82C6-1C85F33B6295} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{511A501E-B868-468A-966E-648B13F144F8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5125CC10-22CC-4612-B86D-8B648738C281} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5129A708-1167-43D9-A44A-51441E64EB2D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5296FC5E-ED9E-4C08-9899-53312AACD76A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{52976B7B-52EF-442F-99E2-FDB8EF510A4B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{52A5C47E-DE55-4E81-A3B7-ABB5E543F873} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{52AEBEEE-2F11-437E-8EAE-12C6DCAF199C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{52E54D97-9738-4CC7-ADD0-8C7A822A4EDE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{537BAC2D-85B4-41F6-BBE1-561A75FF4C3F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5383CACD-F142-4CA8-A3A5-4D302A67AC6B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{53B6F6C4-1590-4ADB-BB70-A4B2D3BB3553} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5523CBF4-36BD-477F-BF4B-2EA5758A91B0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{555662AE-7378-4570-ABDA-7F1CF64A027B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{55B93490-F014-4C0F-A01B-A9216F1AF942} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{55DACC80-72F3-4B2B-AA4E-F3EA520D7754} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{55EEAE1F-A4BB-4254-B2B9-889DE0E4A8E2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{56EA48DA-73C9-4167-86D2-AB425B0FFEA1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5777AB10-63EC-402D-9D45-A969EE657FE1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{57D41DD3-66B4-4A13-AF5C-CD1403EB43B4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{582B3A49-1C17-4520-AEE4-0E709E4D8104} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{58331F8D-D487-4C47-AC59-2DC411580735} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{583B4F8F-9FC7-45D1-903D-2EDA776C20F7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{583D2925-873D-44BC-9C28-8BD6B1EB1127} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{58411C21-B5BB-4290-97FC-B4E52ED05A9A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{58777DAB-25E2-4638-8ACA-B3520D99459A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{58A8258F-D5CD-468D-847F-FC7BF89B0972} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5934F40E-6449-49FE-B13F-E43D0C73E0EE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{59B7927A-6F4D-4818-B282-792161BFED45} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{59F2B8C6-4CED-4F4F-8385-8E6F1D9743BA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{59F55828-146F-4099-B253-26E54364ACDC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5A153B97-6B27-4141-8A13-51F179876B92} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5A3B40B6-6808-4CB7-9200-3A1A8780AED6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5A894E21-9E12-4E5E-A251-B07282DA4073} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5B90D05E-D98E-48D5-AE3D-B41B870AFA68} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5C18613A-AEDD-4D5B-B63E-5094DBCC4CE2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5CD625F6-43B9-4A62-B5B6-23DDE1505AB8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5D3D5D7F-7199-4A95-8269-52786E893562} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5D8D449C-F09E-4B8A-9FFD-5EBB8BE4F807} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5D95E8BC-3492-4079-8AAB-9727B9535723} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5D9CF259-852D-41EA-890E-15DFD3E51E8D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5DCA4437-3C67-4435-BCFF-B782DB53CE30} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5DD3E185-C703-4FAD-B8EA-16E6C14631DA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5DED99CD-8D90-4A24-8970-C1494BAC5928} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5E749F78-4403-4353-9619-8AE4B8C858F5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5EDF2FFE-DD00-444B-8BD7-2C5627F467C8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5F307602-6F14-482E-9452-91172F23FC2C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5F7F5725-62D7-456A-96DE-2642771E2FF5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{5FF19144-A7CA-456E-B54F-CEA2A97DC53B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{604EE2E7-BD34-4FD4-8ADA-99B4B5772BF2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6075967D-DE73-451E-9DAC-E045E999958D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{607A4D28-C2A4-4A91-A8B4-B0917AB98C95} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{60849035-5EE7-4F29-861E-7E00306BFFBB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6095FE71-2A90-4498-8955-1B1002EFC8AF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{61242115-41C6-4633-B95D-9807A36B6772} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6167B60E-1A3E-44F2-8E2E-8AD5D885FF5D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{61A9BB3E-0C73-4269-AD3C-B43D9C5790A8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{61FC4204-0806-40A2-AD43-9DA342A7F201} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6240C1A9-67D0-408C-BB3C-1265B84772E1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6255767B-422D-4F77-81D6-C3A46A084287} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{629C64B1-7340-485C-9723-0EEBF4CEE547} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{638C33E0-0CF2-4EE9-9CC6-564E26D6313B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{63DC8447-DA65-46A5-97BB-5C6E4A461DDB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{64299A35-6E0C-4093-8058-99E43DF5D89F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{645C8E7A-555E-448D-97D8-241FAD82323B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{645E7B9F-5511-4E07-8374-0AB0F0E9030D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6482F1BE-73EE-4743-BC1C-9BB51163448B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{64BFBDFF-7B3B-44EE-9FA6-F570667EF0C2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{654E6224-AE16-49B8-91BD-98798C4CB3A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6567536A-51DB-46BA-BC67-B33F895B0DCC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{65D45E91-7B30-47F8-B00F-195DA704FA7F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{65F33A2A-9987-4AAD-AE33-D5D1BA9114A4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{66268BAE-89B4-40CE-92A3-104E09EDAEF8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{665DD0FE-8345-44C5-9E90-C77E394289F4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{668F916A-7D08-493C-80F6-689D56293599} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6721EF37-5A09-4C90-A5B8-D1DB91FD908B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{678AC4A6-B431-475E-9E03-A8CA952ECA45} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{67B7BD2D-1A73-4232-B6CA-FBE8E7C7C24C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{67D51F11-9793-427F-A1A7-999C9B44C227} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{681F6D67-2D17-4DEA-966C-F0EE6A8D9E17} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{686F64FD-9AD1-410B-AF4C-52ECE8302FBA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{690E02E2-3ADA-4B21-84CB-265C92AA46F0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6911F201-4172-4A17-A0B3-D8FB0F8CC577} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{696C7D93-D3CD-4463-B470-6F43B16342DE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{69C37B32-731C-4BF4-BD83-69FCFA1499E6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{69FE4553-96BA-41E7-857F-DB5FF8260425} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6A91976C-AEC2-4A53-A30B-8B52BCDA4CD5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6A9370FB-94BE-4E78-A03B-F02DB4ACD4DA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6AA4E22D-6232-457D-905C-6966F655C233} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6ABF39CA-6849-4E49-A09D-BCC91611CC02} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6AE70BA2-C9B7-4992-AA5A-6338ED7C7099} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6B22F685-9DBD-4297-BBA1-686CCE6FC80D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6B6DC1A6-0DE3-4F2C-BEAC-EC759F01EAF6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6B8D7D3A-0DC9-4D43-A438-75F6E80BCE25} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6BDBFA30-F371-4C04-8479-6F29A8F3ECC6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6C700FF4-1AEC-4E87-8CC0-990C8A8AA203} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6C9B1D1F-3B1C-48D9-BEBC-40E2A35ED984} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6CAA85F9-005A-430F-9DF5-866373294F00} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6CF8D9EB-45B0-4D8B-8512-7271CD571924} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6D138B12-63BE-47A9-AC7A-5718BD17099C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6D7CBB4E-8AAB-46D3-B648-624962969E0E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6E3C27D7-204D-40CA-B88D-A296280ADAD4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6E5496AD-2E04-4AEA-89BD-1B59C89B19A4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6E718749-1EBC-4C12-89E8-982CD701EEF5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6EBF4AD8-F16B-445D-9BB3-FFEDD71C388C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6ED57023-4CF2-4A70-A49C-0A9946C15A5C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6EF5F451-5688-424C-B436-74C0D11E329D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6F36AF68-9C46-4912-9B34-36BA11405B2D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{6FA2A43A-D508-427C-9B2B-446A56722292} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{701F6BC9-F0D2-481A-AE8F-21947F5CB34C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7048DC33-3C5E-40A8-A40F-FD528D56C080} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{70FE0923-4094-4D15-A97B-5F98FA7D94E9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{711DA4EB-8034-483B-875E-27161A0D8470} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{71584C7F-97FD-41E2-8938-D85372E8FDAA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{71F083A8-1321-41F7-A99F-B5038D3EA95C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{71F318DD-401E-4BDC-B9EB-62416B9CE034} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7219DF5C-A0E9-4352-80BE-E806F7507FE6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7232E628-E770-4841-B170-0F082F987679} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{728C22DB-B805-4CF8-A746-2578C3791433} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7323E505-99E6-4E73-B5F7-F70ADF7A19FF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{74187902-E51C-4BA8-AFCE-908ED1832F00} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{743CDE5F-FF2E-46F6-A9D6-9E310C88270E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{745B185D-EBCF-4D76-B893-F81BC0524456} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7484F39B-F339-4254-AE4E-D20657AFC0D9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7524DB89-1804-49B7-8A1F-1DE2599C81BC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{75C58FF6-A93A-4388-AF42-A050F306F21D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7623DD01-D10C-4E20-9D32-0BEDAFB081FA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7652EAFF-3524-4394-AF34-82DA5AE29B32} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{76B50EF0-247D-4124-BF36-B25D29C685B5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{773749A9-6AB0-4A66-8EA2-873D9301B33B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{774D085C-8A55-41F6-A05D-6A8620C14F91} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{777ACD97-095A-4284-9D57-0FA5855591A0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{77A0D7B1-4967-4DE2-A4D5-125B3CB2165B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{77C858F5-DCAC-4473-B067-7C1C217339F2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{77FF1DA4-F945-48F2-8214-9297EF000789} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{785473E4-C072-4D1E-A46E-223FF6451D26} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{78A92FC7-4E33-466B-9610-CA1B9ADEE25D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{793A566B-0E20-4F99-9C37-FB27C52FFDD6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7954C131-BA9E-40A5-97A6-4A344129512A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{79BB0AB8-6EB2-4672-9FFB-C736D2957255} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7A3E7C91-54BA-4E02-8662-7A4239A442F0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7A7F7E05-6CFA-4A56-83BD-48DAF6479F87} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7AEF7E7B-5CEB-4295-8DD7-1FB87992E1D9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7B052180-328C-47E6-AD04-267286BE25CF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7B108C12-0DAE-4836-B2F4-5C8D5AA19043} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7BCBE7A2-2E68-43AC-BEEA-52ECBBD3F1A5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7BECE69A-F1F1-43A3-9A99-CDE626E28B4D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7C131FEE-B4D5-422C-BFC4-FA679E6EC876} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7C2C9F5D-BBEF-42F7-A186-3BBC9D52BC82} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7C51B416-D18F-4910-9A1F-3A807E297030} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7D235335-99D2-46D9-9A65-6999D76E2B41} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7DB4A0B7-CD4B-454A-8E3B-53FE5EBBD8A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7DDBA963-D01B-4CD6-81C2-CE0C576EA984} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7F71596B-A724-48D7-B20B-3605000CB19F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7F8AD3EE-F09F-41F1-9EA5-0904D423745F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{7FEAF6B7-4711-4B9A-9558-3C2CD8148EB1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8065A450-0706-4766-8E00-4E96C15A0D89} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{80D36650-2E5F-4780-AA5D-F69C6EDADE10} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{80F696DF-DE07-495E-9E63-E953F80D27F8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8118EA00-B0A6-4D50-A212-2A1FE848BE71} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{815AC06F-B843-4261-A4FE-370A7A977FFE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{819CB30C-EBD1-4C47-90C9-B027DDDE8317} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{81D08D71-8135-4472-AA4A-5FF0C54293A1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{824C66FF-6943-48D0-B655-30544D740AA7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{825D4F38-623D-46EE-9898-EC4087B4A31F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{82646578-EE24-46EF-9290-4D24D5EFC355} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{82690497-6DD2-456F-9931-179E6FB37B2A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{82B69F81-C686-403F-94DD-B8F64DFAF7A5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{82C2A3D4-23AA-4320-83BE-2DFE80498658} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{82C79476-B30A-417F-973C-8C38CA957421} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{834B4CAD-6C17-40F7-8667-41CF012501DC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8363A7B4-2BAF-43FF-8CAD-7420A378BAC4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{836C02CB-2880-4065-8D7B-89CF67231257} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{837457CA-CA82-41C6-84A2-65BD975E719D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{838F3EFC-DD5A-428E-A435-427320E8289C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{83BA23ED-8146-43D0-935E-35CF971FBEFF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{83C24D7B-425F-45BC-8E0C-D4CCDDF37EA4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{83D22A02-B9F1-46BF-ABFE-9406AB418A77} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{83F322E6-88C7-4170-9DBB-A80B38C60209} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{83FCC2E5-C977-473F-AD2F-DA86D9620DB5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8406EDE3-CC7B-474E-B4F1-FE4C5BF82507} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{840F07BF-CEC1-4917-B438-F9AC30621C79} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{843ED841-F95F-4464-A8A8-B7BB8200697C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{848F360D-0B59-43D7-BC74-FDEE0204DF9C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{848F673B-3716-4D9F-A60B-7D48596C9CB7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8512FAD6-2A64-4E61-99DA-891A8A29EB73} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8523E857-6CA6-42A7-9AF3-4B2D13CB3943} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8537FC82-A1A3-4C52-ACD3-5582F27A40DC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8565A6B4-45DA-46B4-B8BE-7558B6756887} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{85879709-7CE0-4260-AC17-FD6B012259AE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8598AB4C-55BE-4533-9DE4-47D3E1B31B4C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{85BCF35A-C217-4A84-9BC2-1FD2716144AB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{85E2D5A0-B447-4B9F-88C2-F79D3BF442D8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8606CDF7-356A-4277-AC9C-70D026972426} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{86209D88-D4B1-4690-B156-A8C5D316C7A2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8627B7B1-927F-4408-9649-9545F152B02F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{862CEEC5-9860-44C1-B0F9-B73E8254F7F0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8648ED7B-34A6-4718-B582-9BBE12B39FC9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{86717CBB-734A-401A-9840-B7D567F8D453} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{86980E41-57D4-4FEF-9AF9-6FFC7625EC9E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8726C7EF-23B2-4E4E-B53A-8827636782B3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{873F1509-F9BB-4DF4-9784-C0B307489739} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{87B83E7D-7A2F-4C7D-AAF3-1858EA332ACC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{87D0551F-6C86-44BA-9507-3D60DC7BA034} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{880D9A75-80C3-4D8B-BEBD-77D33A105817} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8849F687-EB96-4486-9E20-D74BA2C3EE6A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{886BFDA1-DBFC-4813-AD33-2E4B8C1C7E79} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{88AEFA70-693B-4078-BF8C-7A852CA150FC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{88F86169-D189-4B4A-B85E-EAA610885D3A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{890BC701-E527-4699-802B-BC60392B4F05} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8918E9F1-93C8-4723-8529-1C57E7556878} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{892D0809-B226-4E90-B78A-D615132BD7B2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8988FF84-75DF-456A-83A0-205F55AE827F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{89ECBB73-1528-4002-88F0-1AFB4D4D3B0F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8A05C27D-264E-4613-9D66-5F931A03A98E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8A417F1C-00DE-40AD-9333-B251F5CD2612} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8AD9310B-F285-4DF4-AA48-8B0A20A4A66E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8B045FFF-981D-40B7-88CA-6898ABACF39F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8BBE73B8-B98D-49F7-85EE-2F6C66D0D2E9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8C6AFC74-D990-429C-8877-1262713CF288} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8C7C1761-1485-4F9C-B8F6-95F7D89C20CF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8CC1B08B-2345-49AF-90BA-FE6BC3F63B7C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8D7E750B-0DF0-4130-AE74-F05ADB090044} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8D9BA7CD-91A8-47E2-8C73-FE10C429ABDE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8DA1DF0B-0DDE-43F5-8105-44D7F4FE65E5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8DBDAAC8-4F50-45C5-A1CF-EFAE5962F008} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8DC014B7-6C3F-432D-83A9-37D8F2669E04} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8E1CBE98-F224-4F09-8E29-55C7DDFCDA9F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8E4F7690-C639-4B8B-8C5B-A9F48611ECBB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8E656514-9EEA-41FB-963A-8A3492ECB1B4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8E6CA4D2-018E-487B-8A49-131E265321CF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8F82B27A-139E-4870-A887-85026FD4D134} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8FE87C37-C33F-4CBA-B12B-86F75A8A7BAB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{8FEE70FE-5938-4026-B283-C02137595DDC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9047215C-4115-47EC-9E01-E2E4D1DA0007} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{90731183-8334-4B6E-9D90-A5A25DEB847F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{90AD3BEE-35D9-4A62-AAA9-F7355078FB0F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{90F3139D-270F-4246-9133-95200E3E7DA9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9101F875-1896-44B9-A5C0-85AF8717FDBE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{91D71F5A-5DC0-4DEE-951C-B82F059A15C8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{91D8AF25-4BDA-4FAC-8AB0-1C6B822A9FB9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{91FEC1FB-D26D-4F50-B518-A4C0BB9E8A5E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9219BD44-C89E-4716-B352-48D018D9EF30} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{92DFA738-17D9-44A3-9B46-2470F03A29A3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{92ED27E7-D54B-4385-BC2C-8E1B2295C56D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9360BD11-6325-4FDA-8E02-F7B1A528F406} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{93BBFBCA-070C-4EC4-AE54-5750DE90AE88} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{93C8D459-4E11-4B6A-A934-C4EB3BF45414} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{94159734-ECB8-4C10-8600-E506F89B1B94} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{942A626F-D192-4FD9-98D8-F9166A5BA3DA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9434595F-22B7-47F1-8E8E-983735BBE0D4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{944A9868-1AAF-47EE-A2A6-50F98E97C618} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{945F1F17-D3E1-4574-BC49-3CA09417DF32} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9470A69B-6FF5-4869-8FCC-A3D4202B30E8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{949E77D1-65A2-4AB8-901E-12EAEA7D644D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{94C8F62A-1AB6-43BF-84EB-EB8700120C51} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9560D719-07B1-42AE-BA87-5AADA7E3EA9B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9589E144-26BC-45E2-B98B-FFB33ABEF257} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{958DC8AC-E721-49D7-9D8C-9B7AF1DC9BEE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{95AD3315-0295-480F-9052-A3B88C11F3CB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{95C1D0B8-D2D2-4515-BCB9-9321A44E00F4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{95F2A54E-C40E-4086-A2DE-BB88152F470F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9699D5AC-08C0-4915-BD59-21F1FDE71BF8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{978C11D2-431D-479B-A1D3-5FF1928CECAC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{97CA3200-A1B4-428B-B438-9C7FD6AF3FF5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{97D7B560-84DA-47B5-BB69-C82718DB5BC0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{97E37D4C-21D7-43F9-8E87-B49D851C9C47} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{980892D6-C819-4BB2-BFD2-0012CCE8CCA0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{984AFE27-669C-4D5E-85A5-BD265C6FED96} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9863757C-933A-48B2-8E81-A11B14307267} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9869EC95-B817-4106-BF76-65B7F2489A3D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{986F4C95-2F81-4C04-B5D1-FA1436C39063} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{991AF583-40F8-4393-9371-C41BDC2CFD63} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9931B32E-C043-4C79-852C-83FBC4384337} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{99755D99-CE14-431E-B8EB-E48B8161008B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{99D02F22-2553-450C-947D-790056A66AE1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{99DD9A8C-D3FD-49A9-AC7C-022A22F714DF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{99DEB36A-0A18-4429-BEC1-3902DDB4A2D4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9A23B7CE-FCE7-4B33-B934-3BF931B46D00} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9A79F449-5955-4255-8AF4-B8E8A115AAB8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9A9F6722-209E-472F-B091-5D9E0E3A6585} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9A9FEA4A-E576-4007-88C3-E24A99B98645} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9AC66729-3ECE-4001-9E17-1C80541977C9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9AF39B7E-2E3E-4F68-8CA3-9D6177F1748D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9B5E6206-3BDC-41F5-B015-EED5B3C1EA26} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9B860304-30BF-40BD-9CEB-93EBF4AF600A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9B9CB287-5BCD-4D1A-9305-C4869D9FA56B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9BBDD311-8474-4EBC-8DCA-F2C383F1D05E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9BF8F162-68DB-4BC7-9D25-1BE1063AFF62} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9C6490E0-722F-48B7-8F3C-078075D93B15} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9C846954-BD37-429A-82E2-E04B4D12B17C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9C993654-6424-4616-866C-6653E21B40C2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9CA1E730-FCFF-4294-AF57-77CCEB51150B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9CBC70EC-7535-400A-9FF6-7C819B621F53} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9D36C4F9-1578-448D-8038-AFF714EED160} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9D75C01A-4724-4367-B4A1-42AE848CAF59} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9D90E91D-46CA-4390-BAC1-97FE32E5A599} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9DDAAFDA-D506-47A1-A5F2-C93A8302341C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9DEF4B94-8022-42C8-B126-CAD6F7B70AD0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9E2E4B04-6599-4C5D-A79A-5B298F86314A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9E399DE8-9106-45C1-9D86-DFE417840F95} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9E703285-90C4-42E0-96E6-6ED3F3F462AF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9EC862A7-FDDB-4CB0-9647-19DDC4748CAD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9EEDFF1B-5BE1-48BC-99B1-7624DA3B47A3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9F30F5ED-B8F6-4309-917F-E0D365E3E374} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9F3557FF-051F-4F17-BB95-75D50868723D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{9FD7FFA7-84A4-4A73-A590-C17781184D7D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A0281A58-9081-44AA-A125-E4EAA9B9F529} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A0A1E0E4-20CB-4A6F-BE9A-41A17FFD8D45} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A0A3F5C6-DC9C-4956-97A0-57927256AA6E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A0C39AE0-C481-4AAD-9F61-1D0E1C128537} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A0CE8BFF-3E4B-4FA3-8EA6-0B60B7F34DC4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A0EB132F-6FE9-4128-A671-ED18F2264456} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A125D6F6-C7B9-4E37-97C6-62CE004FACBA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A1BFB10A-FCC8-4408-97AD-FA7E0237230B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A1DF9F64-F9F7-4965-9B4A-63C1752F4430} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A255DE59-AAA0-45B9-8713-439816CF1855} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A267F565-F51B-403B-9AC0-F2320421417B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A31C98E9-151F-42F5-A018-D1BA72488840} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A323E478-BE6D-4FBD-9FD4-D37BE9993F48} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A37BB893-A26D-4E23-93E0-2E5A04147A49} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A3E6A6C1-A716-4F8B-9FEE-2D8387170165} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A42BAE8D-0828-4405-8E3F-EFE352457A32} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A466AEBB-A70C-45BC-9E79-D8C325DE67D0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A4B26C7F-A5C1-49FC-AB8C-433884C30523} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A4D8475B-7DB7-4B22-A289-72EDA48DF7AC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A50A8872-C1E7-4668-A238-98FC43D0BAD6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A5376EF7-7764-4F58-8E4E-A51C06A69321} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A5487728-8157-4A8D-A068-E3A43DD0F1EE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A55A40F2-FB38-432B-82C7-ADDBD8C830ED} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A5BDCE69-3F8C-4837-AD56-05BDFE02D550} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A5C905B9-F12C-488E-B26C-F0571665DF02} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A601FC60-ED2F-4503-8DBF-F494A51A4DF5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A612B331-F90F-497E-96C2-FFD88F817D5C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A61F2E7D-4DCC-4070-8F43-2A78BAAD5B79} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A61F44D7-19BC-452A-AA87-FD19DBA9B22D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A69E6356-08DF-4BC3-A402-7CF0B8F48F92} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A6EA7BA1-6B9D-4523-B403-EC98B656FD95} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A6EBA9B9-429A-4AFB-9650-CD200ACE857F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A6ED4387-F3C7-4076-962E-3EFBBE6BEBA8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A70C44C0-3C4B-445F-BC38-B325AED4A548} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A79230D9-04B8-4669-BD23-56DD73C8AC78} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A7E733A5-DF69-46FB-97D4-30215D508B77} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A8577D6B-9E65-456F-B11B-D9E4D1160DF8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A873AD6A-CD32-4F78-BFA9-AE69C3EC913D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A8AA9814-3DC0-4C4E-98BF-60DEF0813D83} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A8F6A957-E6A5-4B27-A317-234D3C690CD8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A942B27E-1CB3-46D4-9DAC-CB38F4215649} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A9782664-B7C4-413C-8037-A047310EFF4A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{A9814286-65FF-44D9-AF5A-A516D41C7A05} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AA04704B-4E8B-4825-813B-AB1262C71356} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AA5467BE-C75A-48BA-9AC1-972F2DB73610} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AA8BBF56-BEE7-4FEC-9CF3-D4E9DBEC59DE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AA8BC720-2C9E-47D9-A74E-9F0583CFFDDC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AAF93BB2-D558-40B2-BC3B-0B78DADD3864} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AB1E17B6-34AF-460F-A369-93227174D723} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AB6658DE-080C-4F4A-A52D-9FF636300582} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ABAE0129-DEF8-4C55-86AD-F6C98ADF3B2E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ABBD75FA-5ABC-4C2E-AC43-41AD31B55A67} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ABD31FAA-B354-4B40-8020-84C932579F67} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ABDD4821-7E9F-43F7-8226-913A1EC8FB48} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AC6B507A-0D22-4E49-9060-370F9E0CE54D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ACA79EEA-CA6A-45D4-BDC1-B35241894DB9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AD08D5B2-C3F0-49F4-AC50-116E71852C85} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AD87746F-C0D0-4AC3-BBAB-E34D745F9777} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ADB2DD05-0D7F-4145-A690-AC2387E196BB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ADEAC9E1-014F-4FC1-B7F4-88B6D4AC1AE8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AE24681A-D875-4B2D-8F07-6FD05B7DD25F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AE4D2D49-68CE-482C-8DCD-E4D30812E4D7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AE9E321A-A84C-4779-AEB1-DEAACE83AFDE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AEA2C79F-4E02-41A5-9434-807A278ACB7D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AEF5C843-AB62-4EE7-99A3-620170ED1890} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AF613FA8-0A5F-4E56-A216-0319222539F5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{AF6E4BAF-90EF-46C1-82F7-45CB9014C2DD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B0070AC7-67F7-477E-9E02-7E24A226BA24} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B1380C72-831C-425F-9DF5-C7F0DCF0CF5D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B17EE924-ED95-4295-834F-2368A3D4084D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B181305B-6523-44F8-91F5-C55C5D66631B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B19A72B4-352A-4699-A06A-168F6AE9F75F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B1D79E38-B068-45FE-BD85-A18639C34CAD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B296B0F1-C26F-4C4B-A282-118DC33E13D4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B2E3AEEC-8BEA-466D-83AC-1AEF7E9627D2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B2F384B5-E0C3-44FB-A96A-4DA02C841318} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B3073F89-FE5F-4BF5-9E07-9BEDFD6A36DF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B3240353-D936-4F48-8A24-F244377419B9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B33F7695-1632-42C4-97BF-D5DA48D8E56A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B34DABF8-BD5D-4C4F-A39C-D5CE577093B2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B3C7B3D6-13E3-4762-8624-3E01BBAFC419} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B3D72A21-8274-482D-B50F-7E77441F271C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B3EAC0DA-968D-40BC-B8FD-8CFFD4FF16AB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B44542F9-FB5F-4126-8FF6-4FD1B1A8744D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B464BD45-9996-40E5-8988-6FDD057CBFCE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B4A8EA0F-CB28-41D6-8E4F-8EF9D3EF997D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B4D77C16-A130-4332-AE76-6C1013971310} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B5052817-26B4-4327-9F09-5206DAB7B069} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B51A2573-E643-4EB5-81A9-8AC6F4293FDE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B54A4DD1-6AAE-408C-980B-67CA202CF647} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B5709ACC-4CF1-4B1E-8C0B-6EF286014C54} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B59217F6-1629-47F0-86CA-6CDDDFC9577D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B5B68861-4839-42B5-BEE9-B9B273D4A24E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B617757F-388D-4DA1-B4E6-73CF0B2E7EDA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B621CC92-677C-4514-B079-AD33C35ADE27} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B6C233CE-4823-440B-A1CE-90035B6DDD9C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B6C3F39A-9E87-4CAB-BB22-46EA4A76262A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B6C8F4A5-331F-4116-ACA4-C09102153434} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B734A922-14EB-41CD-B730-B34EEE5F25BE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B79FF1FA-DF7E-425A-862B-773F03EB4F4B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B7DC9005-3BA0-4BB9-A765-F8C74E582958} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B7E333DB-464D-454B-BFA0-BE675C1D4F87} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B7EEDD70-AE20-437E-9932-539F70568979} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B7FBA846-D4DE-4007-B310-FFAE38B83FE0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B813E001-B912-4EED-B92A-0B40EBFDF51E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B890501C-3128-4982-9A4D-FC2A79F7EE89} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B8A4F001-D85C-40E4-A2AF-FBA9475E7757} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B8D22E90-8507-447E-9710-4D5A39738EAB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B8DD6686-3ABF-42E9-831F-98911AB7FE7D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B8EA2B87-B257-4358-9A93-16EB63424D7C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B8ED32B1-6AC6-4526-A990-E45379FAE9B8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B97CBF87-0C95-4732-ABF8-9A77029D2404} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B9C2BCB9-F6BD-4718-B57F-7C4415063FB8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{B9F75FA3-DBAD-42C1-8274-222275B33D8E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BA510221-3EEA-4353-9762-BBF54A260521} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BA7818CF-73CB-40EF-B035-6607DFEC0DB3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BA8EDC31-A98B-4CE8-A14F-DAFC24EDD155} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BA96255C-1173-4AC4-B502-11486911C53D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BA98FC8F-96D7-4087-8B66-61448D459683} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BA9B5177-685E-4589-B1C2-ECF5FF2CFEC1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BAB140E5-AE98-438B-BCA8-D459AD8E98AB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BABA77E4-F36A-4E4C-B475-FD5E9D1851E5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BAD3D4CD-F0F1-495E-AF14-BA4E44F3BDC2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BADAD5DD-C403-4882-9148-6A48CB89AEF9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BAE27D30-56FF-47A7-8E73-AA64B4D88DFA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BB06EAA8-D095-46BE-87B0-1E10C6E984D1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BB0AFA8C-7457-4822-9DE3-BDF24FFBAEE2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BB36D855-3189-4951-B90D-5E60207B2D52} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BBEC0962-1838-4718-8C3F-E119B41DDF02} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BC21BAEF-0CA7-4F59-83BC-ABA4A747ED79} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BC6063B2-94F3-4142-98EF-A24E2C756A0C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BC9746B0-ABDE-4328-9E4C-BCA53E7B7DEF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BCA52A19-2CC6-4B7C-9322-2BE31E19AA80} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BCA80716-9B43-4FD0-AA3C-C51C17049555} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BD28076D-6AA6-4372-86D7-CECADDB332B0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BD9E2DE7-7466-41BB-88A8-B230BA16083E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BDB9DF92-C4F8-432E-9F05-080765E9DDCC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BDD6162A-CEF1-4420-8599-FD7F51885353} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BE2995F7-1A3C-4F75-9B14-EA54E0CF2F12} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BE96F4D9-2CEA-474D-8D92-ED206720A14D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BEA12786-8838-4A1B-9178-851F24120452} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BEA6C71F-7CA3-4869-86DD-89F0E04EB33D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BEC53D2A-9035-4E45-BCD8-E88187230D80} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BEDBE0EB-5441-45DC-A92A-EA011F2CAA7F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BEE93F41-7F13-4AA2-941D-ABAC71AB6711} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BF0ABD5D-8825-44EC-8A4C-CD13B84A7D77} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BF0AF1BA-0403-4188-9873-37C61ED0B91E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BF2C78A4-0F49-4F89-8DE1-19309EA76E2A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BF579CB0-B159-4B1A-A2D4-9E511720BB26} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BF5C2982-DFE5-49F9-995C-6BC8D1CD72CE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BF9E9F08-96A0-438E-AD9B-54B7E275259A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{BFEF3556-5236-4390-B0DA-B98FB30A868A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C020A5E5-2239-47C0-A0B0-DEE08A2D100C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C0960183-DAAF-4DB9-B916-5E607F215BE6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C0E71A4F-7ECA-43EF-9DCE-AB7FFD71D297} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C0EB0B95-F000-48B0-BF26-8E5B5D82A445} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C11F88F8-9839-433A-B9C4-0CE9D0C1AFC2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C139ECE1-6562-4784-9C07-FCFA71ED9592} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C15EF437-475D-4F1F-9477-DD88EDE5E6D0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C1D354FB-86A5-4E52-86E8-1B265AF89F4F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C1DB0542-15B7-40AE-8B13-C5B635B1229C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C1E985DD-D979-45C2-902E-33753B38B4C2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C27A0FC7-A61B-43A8-87C6-EC173F9C0A88} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C297FA1C-0024-4889-8EA4-48ADF0B40D60} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C2FADE58-E8D8-4244-9E49-CE16BA28EBEC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C30506CA-686F-4B92-A089-649B60B2EAF4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C310DA48-7A9C-4E13-BCCE-AF0239C9823B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C336ECDE-1DE0-48B0-A38F-44DBCBAD2A50} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C342CA01-E650-42F9-980A-6DAD357B5C86} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C3AE8D8F-A516-4FA9-A292-F986F224CEC2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C4004369-16DC-4C1B-8DE8-2D5098D71E2E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C40CDE1C-94D9-4989-B1D6-A6E63AE57F8A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C413EE35-7CC1-4755-BA8F-17FF7AD34BB3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C464FDE9-9399-48FA-951A-7F257690BC73} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C471B6DF-CBDB-4239-BEFD-BBD49A5AC378} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C47891E6-BC48-46ED-8ACE-8AADB29AACE6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C4D62E64-D069-4136-BA1B-D370F1C85EC6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C57A3FF0-1528-4458-B63F-D7B325FFCBBE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C57AC60F-F01F-4B69-9DD5-B7943FC11455} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C5C0E825-9C6B-43F8-8369-57B9FB251251} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C60E60C0-75B5-4535-9B42-EAD67B3D6EE3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C64E6691-396D-4E99-BB12-B6A35CD46E88} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C67F46AA-35EB-450D-9D0C-C5694AECD390} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C6AEF815-ECAF-4E2C-B573-DC6033464278} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C71C45C7-2072-43B4-A1F6-3FC1FCD0B857} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C7625AFB-A3CF-4613-965B-220509FDBB17} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C7902E5E-5041-43CA-8379-C202D17A3403} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C8112846-35D2-4DBA-8A9A-9B0D42627FE6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C8EC6ACE-AB77-4D98-B6ED-B543B89B0806} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C90B0D12-D2CA-4F47-9B8A-72660B47983B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C967D82B-73BB-401E-9684-B81B3B70C90A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C996CAC5-EC6B-4293-9EB1-A012D693DD3C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C9A51119-862C-4EA4-9B6E-86154B9DEC13} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C9AD5A84-B22F-4686-8854-FD3DAA14714C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{C9C193B3-30BE-4720-8077-ECAD8FAF002F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CA6C96B6-E767-4B0C-9F7B-9DD5E50D6E71} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CA822CDA-C8F5-4A86-B412-09AEEF32578C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CAB10816-6F13-4D2F-A9B8-89F37CE1433E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CAF7CDDD-2361-43FD-9323-FD1E4C134F43} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CB73795F-46EB-4438-9D50-E57D8E1B73DB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CBA699FC-3509-4797-8B78-48CD9E7BFB04} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CC4D8814-017C-4371-81C1-8895774CBC74} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CC8129DA-F2FC-43BC-9944-A690BB68C82B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CCB099B9-8746-4B6D-A0ED-955E4011CA50} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CD662E80-1E53-46F1-ADC3-72F166A75C72} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CD81E9AA-427D-4AF4-A82A-0FD1CF378824} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CD8D462B-8393-42E7-9C61-661C58B746B5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CE299812-6AAD-49B4-9C5C-1153F17F1001} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CE8A616C-0B9A-4657-9E16-BF6336CED79F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CEACE0A2-6D63-4913-BEAA-E3CABDE4B001} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CF104347-2729-48E3-90EC-7AC925999CB8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CF270A81-B770-4949-92DA-670AE860C60D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CF49A4BE-F2B2-416B-A79D-2F942C0D442A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{CF9988F3-FC08-4BFF-8D66-92CAD053871B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D034F56D-FC9E-4409-ACCE-2C1AA33603D7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D03C8EF9-ED89-4080-BFB9-0DB2CD69147B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D053D968-B6C2-474D-AEBD-29978B95F4F9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D05990A2-DE85-4DE5-8E66-6333ECE9F6E2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D09A52D2-D119-4D81-905B-EFFBCDD574D5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D10CC428-FB82-4DE8-9F25-C02AB7B9B2E0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D1276FD2-106A-4856-88F4-23B3251C132D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D1292377-D335-4B31-AFE5-6A71E08069D0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D159FE22-26F9-4B67-BC74-CFA9EB2CB9F2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D167C577-A784-424B-98A2-34151C79F6DE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D17859D0-A0B6-4756-BD1B-2CAC96521E9B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D2068528-82C7-44E0-8DD9-E3A013B9EC9D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D233A648-F763-4D10-9912-F58D83F96ED3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D23798B1-1026-426B-A6DE-739663F4972E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D244FAA5-9377-4087-B8DE-116ED7483CC9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D3200863-BE02-4996-95D6-9CB5BFAC7E17} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D32854DF-537F-4659-AA3A-3CA70071154E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D3358A24-CE7F-425B-8AA1-A08BD4B143C0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D37CB75C-F49C-4518-A84E-F76CA3FA648B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D381152C-444F-45A2-91C4-702E63BF8691} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D38585AB-16F4-44F2-918C-447D7CA48629} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D40DAECA-AC7F-4BA2-AB96-35FBD02EF7A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D424C912-BF7C-4370-B939-239C6E34DD57} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D429DC40-BCD9-466D-B6A2-79ED7B750F22} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D43B8807-08AA-4761-8ABA-3FF96F31CE22} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D44A0A80-C366-4FDF-86CB-93AA25EDCD23} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D48E0531-0776-4586-A730-A835E5E13DE8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D491D617-358D-4FE5-8449-F27782D7A432} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D52295C0-D014-459E-A597-F7343D55BC51} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D5396850-FF80-411C-8E96-D681A9A86D10} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D545BB37-2D83-4A01-9F24-93FCF72828E4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D58A36B5-1A2A-4C29-AFCB-6DEF0E3A5719} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D5A40BD2-F2A4-4A10-A290-A3F8464DD91B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D5AA0836-97FE-4B85-BD8B-537DCB6C62DF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D5AEBF60-E2B2-4C43-941D-B83113AF5C18} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D5E5D6AC-FA1D-4A67-B78E-60C87B760A67} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D636116C-8EA9-4C26-AD55-B88DAE807845} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D69B2087-6E00-4119-BF46-D231F7160FA3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D69CB3D6-88D4-4E1A-A939-3C2E0F53313C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D6A21368-2B18-4C92-BC91-1975FD1B62C2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D7311A1E-A7B9-4077-8735-2CB12EBF9B5B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D80E5842-E32C-4F27-97D5-28CD3D387270} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D81B5E8D-F370-48DE-9F3F-4D7026657D80} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D822AADB-1CD0-4C10-A950-285AF0DBE656} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D86766A7-39F0-4783-9CE5-3C36C9921CC7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D8C566FC-D43F-4740-BBD4-20F85AA6493D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D915C94A-F605-47BC-9DEC-E1ABF01A6333} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D9C6097C-E90C-4588-9BBE-4BA2F6BB19B4} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{D9FF478E-FB3F-44D2-B64B-7AF7055B2376} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DA44FEFF-D924-42BA-9DA4-B691311A151A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DAB60BE8-0D19-4718-8516-FFB409E2D8AF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DB00E28C-DE7B-4266-9751-CDF65BDE17EB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DB654ADD-4471-44EE-9401-E982BAD940A5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DB68C5F2-9CEA-420B-AEF0-04F61F142227} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DB8FE342-00C7-4FDA-B7C6-BDF8A51A5A9D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DBB87EFB-98EE-4B47-9A8F-6673501EA6DD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DBBAEFDA-53B8-4CB0-9DCB-FA4E7E3D9247} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DC158C47-C0B0-41FB-A252-16F7CB7D785B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DC631C68-A7CF-4235-93CD-5E4EDD28F439} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DC75E436-7439-47AE-9354-33C95405E4E7} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DD01D8F3-5B3B-4287-BC74-28BAF790FB0D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DD4292A2-5F1F-4D59-A75F-EE6162C66CA8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DD643BE8-B07C-4A3A-A4C5-9466DD2D7312} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DD895814-49DA-4018-A862-FD79EFCEAF70} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DE17F113-62F6-43BE-84D5-E55B14307B8A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DE4B778B-F0AA-40D8-B549-389BE9D666E2} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DE51ACB8-8433-43E3-87BC-BDDC6C0ECAC6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DE5F6405-EE7F-4541-8AC4-A21A6DCD28FF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DECBE7CC-3F3F-477D-A5F6-4166E41AB059} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DF20282E-6952-4EB2-B22D-1F43C4D5F72C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DF76B182-A267-4787-87C4-189A4BDF203E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{DF77964A-8847-4B6D-B9FB-D3EE92165596} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E01C0DA3-D14C-4088-8F79-E779BE1B81C1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E023172A-8122-4A13-A51C-41BF866F3DD1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E0683B9C-EB06-4413-AAD7-7906A034444D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E0955F7D-6655-4ECA-8F9F-0706C0D615E5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E0F3247C-840D-428B-B5D6-1BA9CB274710} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E126C488-01B9-465F-9A20-D448A8B4882F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E133C7E1-5F1C-4DA2-9650-758AACD96232} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E207BA9D-B6CF-4313-ACC1-5B07D6D01CC0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E208E0CF-3C57-4042-BF76-51B93F086BCD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E2A7EAFE-070E-4095-91AD-39DB82499636} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E39B33E2-DCF1-47C9-9759-231F3AAFC0D3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E3BB9CBD-5D0D-427A-A339-9941903A2D21} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E3C254FE-828B-4B89-B5F5-DB77401821DC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E490DD67-24F5-4164-AD41-3D9B3C31F109} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E4FBB551-2DCF-4078-BBEA-18D680FBE3D0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E5A86C4E-92C6-456F-B162-D87EE1886958} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E63833EC-B6C1-46D9-BECB-9A8B1E27A9A9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E6482C0B-90D9-45CB-9EF1-29F7A85E3B04} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E6523710-8BA4-4F68-84B2-155C63BC5853} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E6793FA2-8AD6-4F68-A898-E12E378D6B2C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E6868940-B536-4ACE-8791-57380F92CAFE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E68DEA1B-CAE2-4216-BCBA-0017217FA541} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E722C15E-2CE1-43F9-B261-410C86D34798} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E78E5804-EE3C-4F8D-B6EE-E9026399C83F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E7B2B7F1-36F3-4B19-A98A-000334E73BFB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E7EC1BE1-2D92-4368-8C79-E8464A03212B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E7EFAF7C-603E-4D07-8689-C04957743579} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E8080D8C-5178-4532-B804-E4D07F3A186D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E90F660E-0228-4C1E-80A6-B9C11CA3F547} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E913D2F1-9D97-424B-ABC7-F45BD6291FC6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E95EDEEF-71C1-4BF7-9C36-046D399DCE4B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{E98DAA59-50A9-4ADC-A838-2DA6CCAB9191} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EA3CD8D0-0856-4AD8-B308-63A0EEA990F0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EA5F6B7C-225C-44FD-B311-CC95B496B10D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EA7F2391-2E90-400C-AD32-E713D9F7F6E5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EAE26DC4-50A8-43A2-8E49-4925FECD1E55} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EB171861-7B9F-4E64-A7C1-418C951ED713} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EB28382E-B9F0-4C38-B4C1-2628C9A2A0C5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EB367DA5-5D33-4630-8EAF-375585A20AA1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EB657E1D-544C-4A91-AB3C-2A74C1B8392D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EBAF458C-8A33-4255-A766-683E5E76617B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EC04E27F-3F09-44A2-BB0B-3039CD109D49} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EC130D32-FE79-45D0-9214-A185A07DFC65} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ECC47B52-918E-465E-8808-47256F249202} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ED32FAC2-B496-45BC-B0E3-C275C4CCE538} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ED519308-B8D5-4EF2-8257-716389D1016C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{ED83F100-3DBF-45C1-B213-0D853D4F43B5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EDA827A3-74F9-44BA-842E-F8DEC22EE039} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EDF3674D-6C9B-496A-8122-5D003A3033D6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EE14DE17-2C10-48BF-87B5-331A0ADE7FCD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EE7D15C2-3706-46AE-8F44-FC5FA58DD23B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EE815D4A-846F-4A9C-B9FF-30907EBE530D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EEC14DD1-5853-45C8-967C-133B22757BE9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EEEC57C4-FCD8-48B7-8C12-D5E574A9F870} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EF2306A3-55B0-4130-9B02-C3CCEC69F023} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EF3031BA-3CD2-429E-B9FE-18D5F7F34FF9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EF60D88B-65E8-4272-B21A-F7C39E0A4DB0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EF88C436-8CAA-4DDA-912C-61CE7D926E27} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{EF8D70CD-A3AA-4EAE-94EE-30E6EEF357C9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F0318D63-F9E9-4ED6-AD2D-7B2FC2C6A310} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F07A7C87-4C5C-495F-BEC0-D63CCB6E4DD1} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F0BB9A6C-92EA-4A3F-A508-B732CA338302} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F0E6DE17-105C-4A1B-BDCE-42F6115E6E31} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F0F4B44B-B16B-4507-BACB-5D3CFFEBB492} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F0FD5499-1744-4BCD-8FB9-B093ED504ECA} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F117FF5C-B80F-40CC-A53F-DB13A075EA70} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F1F68270-25DE-4408-BFD4-918C55DA1AB0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F20016D1-D675-465E-AE5A-F79CD1237294} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F218D70D-9B07-471E-8CFB-00E0098F979A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F2487C42-7D68-4140-A093-A1AA42BC79A0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F2627774-5E44-4C25-A608-4316DED95C47} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F2AE2138-4FEE-483F-A4BE-833675DD35D5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F2B61D95-7A6E-4971-8ADC-894C9A3A7585} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F2EB10AD-9B92-4947-9AE6-6223B23684EE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F3403E5A-DD6B-44DD-9933-D6FF79BBAFEF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F461EFC3-D5E1-4085-9D72-0A07B089A443} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F468AC56-208D-49B7-991E-1A9EA0EB0439} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F4773723-3971-4757-B290-F632B4EAB98D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F48292D0-3535-48C6-BAB1-F1ACEC5EBEE3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F4CC70B5-9CAC-4A43-9562-AA4C47F88F6F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F4E2426F-E444-4E8B-B114-03BCC8866DE0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F510701C-9AE4-4993-9DA6-B25ADC8672CB} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F5316D51-522A-4538-A8B5-832C46FA5CEF} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F5A025A2-2E1B-4167-919E-0C47355ABBEC} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F5BAF911-AE21-45F3-B7B0-EF9203196750} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F5F82B99-626D-46CC-831B-BFFB9533B687} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F603B02B-6522-440D-927B-1941096FD645} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F61A3446-0056-41DA-B00B-1998B5E018F6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F61D004F-EE29-45B8-A2A8-A3B7584D5D64} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F64D295E-5A93-4CCC-8BD1-C6EE92F10503} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F6540329-3052-413E-A29E-AEE99207CB1E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F6616B89-2337-4A21-B1F0-4207949B54BD} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F6650E34-4862-420C-A2BD-17DF443071BE} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F71F7D65-8B9B-4D8D-ABE9-D3C10D791DA0} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F74E1201-9F12-4FB8-9182-9CB239E3D7D8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F7779D0E-AB1B-45EC-BFA8-69213B37F1A3} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F7A6A3D3-2F44-40EC-8905-31C8DFF2D7C6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F7E87E58-D0EB-420F-BC1F-ED0B3B14098D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F80117C5-7669-4FF6-BB73-821FB9D41FA5} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F81C80CC-F349-48D2-91E7-6119E068D40C} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F8CDC9C3-2505-4C5D-9490-28D1C90D238B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F903E3F7-989B-4F31-A45F-79E63B2CEA1E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F90981DA-5270-475F-9581-7E519976411E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F936874E-146C-4C89-9AE0-E5BD200A73E6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F96E9790-F87D-462A-AA4B-4F699D3FB322} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{F9B40303-C221-4B58-8950-B65C0588335E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FA326849-AFC9-47F5-8E54-D111A34FA50E} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FA4C1773-527E-4F12-9B8D-8A786F93E48B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FA64D4FD-EA20-4B01-ACBA-B254DAB0593D} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FACDFB34-7159-4352-BE31-4E69A95A0504} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FAD359FE-B2F2-4502-9E3B-2FDF64AFF932} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FB67DD3A-8C41-4BEF-95DE-71C96CB42F91} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FB8AF8BB-F267-4087-B724-668117823553} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FBBB8019-91F6-4D68-9007-2EF696DD8EE8} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FBDDE37D-F7CB-4976-9DF5-6DCFF11AF20B} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FC2A32D1-F32D-4DAF-847D-4DC721AEADE9} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FC922FFC-C312-4784-A5A6-B96454FEAB0A} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FD2F85A2-4ED1-477F-A403-CB1E5E8F72A6} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FE7962D9-25A6-4F43-B89E-4A182B6FFC15} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FE925A48-EAF4-40BF-9776-82C22ED82F21} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FEA40305-C737-48DE-9B4F-57266E1EA60F} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FF48187B-CAFD-4ECB-AD24-9B51AD32A611} Successfully deleted: [Empty Folder] C:\Users\Cristina\Appdata\Local\{FFE45521-9E23-4A9C-B1BF-352751CC7B6B} Successfully deleted: [Folder] C:\Program Files (x86)\alawar Successfully deleted: [Folder] C:\Users\Cristina\Appdata\Local\alawarwrapper Successfully deleted: [Folder] C:\users\Public\Documents\alawarwrapper ~~~ FireFox Emptied folder: C:\Users\Cristina\AppData\Roaming\mozilla\firefox\profiles\mntty8d8.default\minidumps [166 files] ~~~ Chrome [C:\Users\Cristina\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\Cristina\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\Cristina\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\Cristina\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.09.2015 at 22:41:44.09 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
25.09.2015, 18:13 | #7 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestopptESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.09.2015, 22:22 | #8 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Hey Schrauber Hab leider keine guten Nachrichten. Erstmal vorweg: Laptop ist immer noch brutal langsam. Der ESET-Scan hat 2 Stunden gedauert (mit mehreren Warnungen). Ich habe wie gewünscht externe Datenträger angeschlossen. Die Festplatte ist nun defekt, was ich mir gar nicht erklären kann. Nachfolgend die Logs: ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=77d0de5152bf3f4abbabaa0f3f5b090a # end=init # utc_time=2015-09-25 06:34:37 # local_time=2015-09-25 08:34:37 (+0100, Mitteleuropäische Sommerzeit) # country="Switzerland" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 25946 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=77d0de5152bf3f4abbabaa0f3f5b090a # end=updated # utc_time=2015-09-25 06:50:39 # local_time=2015-09-25 08:50:39 (+0100, Mitteleuropäische Sommerzeit) # country="Switzerland" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=77d0de5152bf3f4abbabaa0f3f5b090a # engine=25946 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-09-25 08:45:12 # local_time=2015-09-25 10:45:12 (+0100, Mitteleuropäische Sommerzeit) # country="Switzerland" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 194138 194843762 0 0 # scanned=249403 # found=12 # cleaned=0 # scan_time=6872 sh=C222504FFFB49640198DBF15252D8E7186A4E781 ft=1 fh=1f7c71d448f9cfcd vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\gry.exe" sh=3E37507BBD4C0287689634B2CDD77E59679681AF ft=1 fh=cbd9e88b633aff58 vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\mism.exe" sh=4FCC97779D94929758888A954E0806CE5F71AFBD ft=1 fh=e46affbb5110ef8c vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\jetztspielenob.de\tbjetz.dll" sh=57CD8DEAF43DF3A2F4703E5219A69935B119D0DB ft=1 fh=311781f1ea21501f vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\tbjet0.dll" sh=B5C93DA0C608B26C9487ABC49CCB643C9A15ED33 ft=1 fh=75f1c65aa8a331ed vn="Variante von Win32/PriceGong.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll" sh=07CF040FEFA25DFDA4287BAB632EAB806E294695 ft=1 fh=0db8f293d4a19d8f vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (1).exe" sh=EF476640E69604879C540915C4BCBA9CF9F6A332 ft=1 fh=f1da0bf17500491a vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (2).exe" sh=AA190194CD322F27B81B57B66F0E48B16DDF09FC ft=1 fh=7a1e2a1eaadddca3 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (3).exe" sh=07CF040FEFA25DFDA4287BAB632EAB806E294695 ft=1 fh=0db8f293d4a19d8f vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter.exe" sh=67EC07E0F34F86396F3364EA40709185BA49A74B ft=1 fh=73b55ea706fa42a9 vn="Variante von Win32/Toolbar.Conduit.AI evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter3.10.6.727.exe" sh=AD731ACD65AB0DC1CE44047E3925181D8B97571D ft=1 fh=4209451a1b42476c vn="Win32/Toolbar.SearchSuite.Y evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\LphantV7de.exe" sh=C9DBCC50CAB672AE7952A2B07BFDA9A79BACEDFD ft=1 fh=cf50ee1b35fa30d0 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Cristina\Downloads\SpilgamesHeroesofHellas2OlympiaDe.exe" Code:
ATTFilter Results of screen317's Security Check version 1.008 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2014 (de-DE) Java 7 Update 60 Java(TM) 6 Update 26 Java(TM) SE Development Kit 6 Update 26 Java version 32-bit out of Date! Adobe Flash Player 19.0.0.185 Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (40.0.3) Google Chrome (45.0.2454.101) Google Chrome (45.0.2454.99) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe Symantec Norton Online Backup NOBuAgent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015 durchgeführt von Cristina (Administrator) auf CRISTINA-PC (25-09-2015 23:11:27) Gestartet von C:\Users\Cristina\Desktop Geladene Profile: Cristina (Verfügbare Profile: Cristina) Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland) Internet Explorer Version 9 (Standard-Browser: IE) Start-Modus: Normal Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Prozesse (Nicht auf der Ausnahmeliste) ================= (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (AVEO) C:\Program Files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AveoSTI.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Dropbox, Inc.) C:\Users\Cristina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Nicht auf der Ausnahmeliste) =========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.) HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-05-27] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-12] (Acer Incorporated) HKLM\...\Run: [XeroxEndeavorBackgroundTask] => rundll32.exe xrWCbgnd.dll,LaunchBgTask 1 HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-11] (CANON INC.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation) HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-05-27] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-03-11] (Egis Technology Inc.) HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation) HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-26] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [AveoSTI.exe] => C:\Program Files (x86)\AVEO USB2.0 PC Camera(U2HGCV3P31048)\AveoSTI.exe [32768 2010-12-02] (AVEO) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [782520 2015-09-25] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [66936 2015-08-13] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [718720 2011-07-22] (Microsoft Corporation) HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\...\Run: [Dropbox Update] => C:\Users\Cristina\AppData\Local\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-22] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Cristina\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec MyWinLocker\x86\psdprotect.dll [2010-05-27] (Egis Technology Inc.) ==================== Internet (Nicht auf der Ausnahmeliste) ==================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{7E454ECC-55E1-487A-B353-85FC9C82C45F}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{E17B3D49-001E-469C-BF7F-2306104338C0}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.alawarspiele.de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.alawarspiele.de HKU\S-1-5-21-1416606159-1160031757-1180804506-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = SearchScopes: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-06-12] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-06-12] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-27] (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-29] (Skype Technologies S.A.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-27] (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-1416606159-1160031757-1180804506-1000 -> Kein Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Keine Datei DPF: HKLM-x32 {4A85DBE0-BFB2-4119-8401-186A7C6EB653} hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/de/mjss/MJSS.cab109791.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll Keine Datei Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll Keine Datei Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-11-29] (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default FF Homepage: www.google.ch FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] () FF Plugin: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] () FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-06-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-06-27] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Keine Datei] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll [2012-01-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-22] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-22] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-07-30] (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Cristina\AppData\Roaming\Mozilla\Firefox\Profiles\mntty8d8.default\Extensions\abs@avira.com [2015-09-22] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-09-22] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-12-25] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\ppGoogleNaClPluginChrome.dll => Keine Datei CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\pdf.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.99\gcswf32.dll => Keine Datei CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll => Keine Datei CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll => Keine Datei CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Profile: C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Avira Browserschutz) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-02-07] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-18] CHR Extension: (Google Wallet) - C:\Users\Cristina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-24] CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx ==================== Dienste (Nicht auf der Ausnahmeliste) ======================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [932912 2015-09-25] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [461672 2015-09-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [461672 2015-09-25] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1148688 2015-09-25] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [228104 2015-08-13] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-05-27] (Egis Technology Inc.) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Datei ist nicht signiert] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) ===================== Treiber (Nicht auf der Ausnahmeliste) ========================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 AVEO; C:\Windows\System32\DRIVERS\AVEOdcnt.sys [346496 2012-02-08] (AVEO) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [163544 2015-09-25] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [141416 2015-09-13] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-31] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [74952 2015-09-25] (Avira Operations GmbH & Co. KG) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-25] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Nicht auf der Ausnahmeliste) =================== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.) ==================== Ein Monat: Erstellte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-25 23:11 - 2015-09-25 23:11 - 00024876 _____ C:\Users\Cristina\Desktop\FRST.txt 2015-09-25 23:11 - 2015-09-25 23:11 - 00001184 _____ C:\Users\Cristina\Desktop\checkup.txt 2015-09-25 20:25 - 2015-09-25 20:25 - 00852704 _____ C:\Users\Cristina\Desktop\SecurityCheck.exe 2015-09-25 20:23 - 2015-09-25 20:24 - 02870984 _____ (ESET) C:\Users\Cristina\Desktop\esetsmartinstaller_deu.exe 2015-09-25 13:13 - 2015-09-25 16:13 - 00013445 _____ C:\Users\Cristina\Desktop\Mappe1.xlsx 2015-09-25 13:03 - 2015-09-25 13:03 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\71895B1E.sys 2015-09-24 22:26 - 2015-09-24 22:30 - 00000000 ____D C:\AdwCleaner 2015-09-24 22:24 - 2015-09-24 22:24 - 01798976 _____ (Malwarebytes) C:\Users\Cristina\Desktop\JRT.exe 2015-09-24 22:23 - 2015-09-24 22:23 - 01662976 _____ C:\Users\Cristina\Desktop\AdwCleaner_5.008.exe 2015-09-24 21:50 - 2015-09-25 20:26 - 00000000 ____D C:\Users\Cristina\Desktop\Logiles 2015-09-23 22:21 - 2015-09-23 22:21 - 00027138 _____ C:\ComboFix.txt 2015-09-23 21:53 - 2015-09-23 22:21 - 00000000 ____D C:\Qoobox 2015-09-23 21:53 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2015-09-23 21:53 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2015-09-23 21:53 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2015-09-23 21:53 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2015-09-23 21:52 - 2015-09-23 22:17 - 00000000 ____D C:\Windows\erdnt 2015-09-23 21:50 - 2015-09-23 21:50 - 05635484 ____R (Swearware) C:\Users\Cristina\Desktop\ComboFix.exe 2015-09-23 19:39 - 2015-09-25 23:11 - 00000000 ____D C:\FRST 2015-09-23 19:38 - 2015-09-23 19:38 - 00000000 _____ C:\Users\Cristina\defogger_reenable 2015-09-23 18:20 - 2015-09-23 18:20 - 02192384 _____ (Farbar) C:\Users\Cristina\Desktop\FRST64.exe 2015-09-23 18:20 - 2015-09-23 18:20 - 00380416 _____ C:\Users\Cristina\Desktop\Gmer-19357.exe 2015-09-23 18:19 - 2015-09-23 18:19 - 00050477 _____ C:\Users\Cristina\Desktop\Defogger.exe 2015-09-23 17:01 - 2015-09-25 23:06 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-09-23 17:01 - 2015-09-23 17:01 - 00001110 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-09-23 17:01 - 2015-09-23 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-09-23 17:01 - 2015-09-23 17:01 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-09-23 17:01 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-09-23 17:01 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-09-22 15:55 - 2015-09-22 15:55 - 18819272 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-09-22 15:53 - 2015-09-22 15:54 - 00000000 ____D C:\Users\Cristina\AppData\Local\Lenovo 2015-09-22 15:51 - 2015-09-22 15:53 - 00000000 ____D C:\Program Files (x86)\Lenovo 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Windows\System32\Tasks\Lenovo 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Opera Software 2015-09-22 15:51 - 2015-09-22 15:51 - 00000000 ____D C:\Users\Cristina\AppData\Local\Opera Software 2015-09-22 15:49 - 2015-09-22 15:56 - 00000000 ____D C:\Program Files (x86)\Opera 2015-09-22 15:49 - 2015-09-22 15:49 - 00000000 ____D C:\Users\Cristina\AppData\Local\TuneUp Software 2015-09-22 15:47 - 2015-09-22 15:47 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack 2015-09-22 15:33 - 2015-09-23 19:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-09-22 15:24 - 2015-09-22 15:24 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-09-22 15:23 - 2015-09-25 22:28 - 00001236 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA.job 2015-09-22 15:23 - 2015-09-25 15:28 - 00001184 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core.job 2015-09-22 15:23 - 2015-09-22 15:23 - 00004212 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000UA 2015-09-22 15:23 - 2015-09-22 15:23 - 00003816 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1416606159-1160031757-1180804506-1000Core 2015-09-22 15:23 - 2015-09-22 15:23 - 00000000 ____D C:\Users\Cristina\AppData\Local\Dropbox 2015-09-22 15:23 - 2015-09-22 15:23 - 00000000 ____D C:\ProgramData\Dropbox 2015-09-22 14:21 - 2015-09-22 14:26 - 00009482 _____ C:\Users\Cristina\Desktop\Menukarte.xlsx 2015-09-13 14:16 - 2015-09-13 14:16 - 00001142 _____ C:\Users\Public\Desktop\Avira Launcher.lnk ==================== Ein Monat: Geänderte Dateien und Ordner ======== (Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.) 2015-09-25 22:53 - 2012-10-16 08:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-09-25 22:35 - 2012-04-25 20:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-09-25 20:44 - 2011-01-28 06:32 - 01811402 _____ C:\Windows\WindowsUpdate.log 2015-09-25 20:30 - 2011-01-28 06:12 - 00654852 _____ C:\Windows\system32\perfh007.dat 2015-09-25 20:30 - 2011-01-28 06:12 - 00130434 _____ C:\Windows\system32\perfc007.dat 2015-09-25 20:30 - 2009-07-14 07:13 - 01500294 _____ C:\Windows\system32\PerfStringBackup.INI 2015-09-25 20:28 - 2009-07-14 06:51 - 00110133 _____ C:\Windows\setupact.log 2015-09-25 20:27 - 2012-10-28 14:42 - 00003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{14B239D9-506D-40CB-84F9-C01CAED49E02} 2015-09-25 20:27 - 2011-10-03 20:45 - 00000000 ___RD C:\Users\Cristina\Dropbox 2015-09-25 20:27 - 2011-10-03 20:44 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Dropbox 2015-09-25 20:26 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-09-25 20:26 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-09-25 20:18 - 2012-04-25 20:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-09-25 20:18 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-09-25 13:17 - 2013-11-24 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-09-25 13:13 - 2013-11-24 12:48 - 00163544 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2015-09-25 13:13 - 2013-11-24 12:48 - 00074952 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2015-09-25 13:13 - 2011-05-07 18:23 - 00000000 ____D C:\Users\Cristina\AppData\Local\Adobe 2015-09-24 22:53 - 2011-09-12 21:58 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-09-24 22:49 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2015-09-24 22:38 - 2011-10-25 20:15 - 00000000 ____D C:\ProgramData\AlawarWrapper 2015-09-24 22:32 - 2011-01-28 06:29 - 01925290 _____ C:\Windows\PFRO.log 2015-09-24 22:14 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Performance 2015-09-24 22:12 - 2011-07-05 10:29 - 00000000 ____D C:\Program Files (x86)\jetztspielenob.de 2015-09-23 22:21 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2015-09-23 22:08 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2015-09-23 19:38 - 2011-05-05 19:56 - 00000000 ____D C:\Users\Cristina 2015-09-23 19:28 - 2012-05-03 19:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-09-23 17:01 - 2011-05-08 23:25 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\Malwarebytes 2015-09-23 17:01 - 2011-05-08 23:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-09-23 16:53 - 2012-11-21 21:34 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2015-09-23 16:53 - 2011-08-07 12:44 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\DVDVideoSoft 2015-09-22 15:56 - 2012-10-16 08:27 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-09-22 15:56 - 2011-05-05 20:00 - 00001451 _____ C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-09-22 15:56 - 2011-05-05 20:00 - 00001417 _____ C:\Users\Cristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2015-09-22 15:55 - 2012-10-16 08:27 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-09-22 15:55 - 2011-06-12 23:10 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-09-22 15:51 - 2010-11-17 15:28 - 00000000 ____D C:\Windows\Downloaded Installations 2015-09-22 15:49 - 2012-06-01 20:33 - 00000000 ____D C:\Users\Cristina\AppData\Roaming\TuneUp Software 2015-09-22 15:48 - 2012-06-01 20:33 - 00000000 ____D C:\ProgramData\TuneUp Software 2015-09-22 14:40 - 2012-01-11 10:41 - 00000000 ____D C:\Users\Cristina\Desktop\Musik 2015-09-22 14:30 - 2012-04-25 20:40 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-09-22 14:30 - 2012-04-25 20:40 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-09-13 14:31 - 2011-07-03 16:31 - 00000000 ____D C:\Users\Cristina\Documents\My Games 2015-09-13 14:21 - 2012-03-29 11:08 - 00000000 ____D C:\Users\Cristina\Desktop\Operation Handyfotos 2015-09-13 14:17 - 2013-11-24 12:48 - 00141416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2015-09-13 14:16 - 2014-09-01 20:20 - 00000000 ____D C:\ProgramData\Package Cache ==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse ======= 2010-11-17 15:30 - 2010-03-03 01:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Einige Dateien in TEMP: ==================== C:\Users\Cristina\AppData\Local\Temp\avgnt.exe C:\Users\Cristina\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmph0nxg_.dll C:\Users\Cristina\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.) C:\Windows\system32\winlogon.exe => Datei ist digital signiert C:\Windows\system32\wininit.exe => Datei ist digital signiert C:\Windows\SysWOW64\wininit.exe => Datei ist digital signiert C:\Windows\explorer.exe => Datei ist digital signiert C:\Windows\SysWOW64\explorer.exe => Datei ist digital signiert C:\Windows\system32\svchost.exe => Datei ist digital signiert C:\Windows\SysWOW64\svchost.exe => Datei ist digital signiert C:\Windows\system32\services.exe => Datei ist digital signiert C:\Windows\system32\User32.dll => Datei ist digital signiert C:\Windows\SysWOW64\User32.dll => Datei ist digital signiert C:\Windows\system32\userinit.exe => Datei ist digital signiert C:\Windows\SysWOW64\userinit.exe => Datei ist digital signiert C:\Windows\system32\rpcss.dll => Datei ist digital signiert C:\Windows\system32\dnsapi.dll => Datei ist digital signiert C:\Windows\SysWOW64\dnsapi.dll => Datei ist digital signiert C:\Windows\system32\Drivers\volsnap.sys => Datei ist digital signiert LastRegBack: 2015-09-22 16:19 ==================== Ende von FRST.txt ============================ Ich hoffe, dass ich nicht was falsch gemacht habe. |
26.09.2015, 19:43 | #9 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Was meinst Du mit die Festplatte ist defekt? Erklär mal genauer. Java und Adobe updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\gry.exe C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\mism.exe C:\Program Files (x86)\jetztspielenob.de\tbjetz.dll C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\tbjet0.dll C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (1).exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (2).exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (3).exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter.exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter3.10.6.727.exe C:\Users\Cristina\Downloads\LphantV7de.exe C:\Users\Cristina\Downloads\SpilgamesHeroesofHellas2OlympiaDe.exe Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
http://support2.microsoft.com/kb/929135/de Bitte einen Clean Boot machen. Wenn das Problem dann weg ist, einzeln wieder Dienste aktivieren, dazwischen immer einen Reboot machen. Solange bis Du weißt welcher Dienst die Probleme macht. Diesen dann hier benennen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.09.2015, 13:57 | #10 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Hallo Schrauber Sorry, hat wieder sehr lange gedauert alles. Nachfolgend meine Erörterungen, was alles passiert ist: Festplatte: Diese war nach dem ESET Scan komplett futsch. Zuerst kam eine Fehlermeldung, dass der Papierkorp für den Datenträger nicht mehr funktioniert. Dann kam plötzlich ein Fenster, welches fragt, ob es überprüft und repariert werden soll oder ob man ohne Überprüfung vorgehen will. Dann hat es sich aufgehangen und lies sich auch nicht mehr laden/erkennen. Seit vorhin funktioniert es aber wieder. Ich kann mir das weiterhin nicht erklären. Updates: Java hat nach mehreren Anläufen endlich geklappt. Adobe spinnt leider und hängt sich immer wieder auf. Ich bekomme es nicht geupdatet. Nachfolgend das gewünschte Logfile: Code:
ATTFilter Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version:23-09-2015 durchgeführt von Cristina (2015-09-27 11:47:13) Run:1 Gestartet von C:\Users\Cristina\Desktop Geladene Profile: Cristina (Verfügbare Profile: Cristina) Start-Modus: Normal ============================================== fixlist Inhalt: ***************** C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\gry.exe C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\mism.exe C:\Program Files (x86)\jetztspielenob.de\tbjetz.dll C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\tbjet0.dll C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (1).exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (2).exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (3).exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter.exe C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter3.10.6.727.exe C:\Users\Cristina\Downloads\LphantV7de.exe C:\Users\Cristina\Downloads\SpilgamesHeroesofHellas2OlympiaDe.exe Emptytemp: ***************** C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\gry.exe => erfolgreich verschoben C:\Program Files (x86)\Jetztspielen.de\HeroesOfHellas\mism.exe => erfolgreich verschoben C:\Program Files (x86)\jetztspielenob.de\tbjetz.dll => erfolgreich verschoben C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\tbjet0.dll => erfolgreich verschoben C:\Users\Cristina\AppData\LocalLow\jetztspielenob.de\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll => erfolgreich verschoben C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (1).exe => erfolgreich verschoben C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (2).exe => erfolgreich verschoben C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter (3).exe => erfolgreich verschoben C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter.exe => erfolgreich verschoben C:\Users\Cristina\Downloads\FreeYouTubeToMP3Converter3.10.6.727.exe => erfolgreich verschoben C:\Users\Cristina\Downloads\LphantV7de.exe => erfolgreich verschoben C:\Users\Cristina\Downloads\SpilgamesHeroesofHellas2OlympiaDe.exe => erfolgreich verschoben EmptyTemp: => 662.3 MB temporäre Dateien entfernt. Das System musste neu gestartet werden.. ==== Ende von Fixlog 11:49:32 ==== Ich bin jeden Dienst durchgegangen. Wirklich eindeutig identifzieren konnte ich keinen. Bei dem einen oder anderen hat es einen kleinen Moment länger gedauert: AMD External Events Utility Dritek WMI Service Acer ePower Service My WinLocker Service NTI IScheduleSvc Steam Client Service Wirklich heftig ist es erst wieder gewesen, als alles aktiviert war. Ich muss aber dazu sagen, dass es seit dem FRST-Entfernen etwas besser geworden ist. Hab jedenfalls das Gefühl. |
28.09.2015, 13:30 | #11 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Also besteht jetzt noch Handlungsbedarf? Und die Festplatte würde ich tauschen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.09.2015, 13:52 | #12 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Gute Frage Was hatte ich mir denn eigentlich eingefangen? Muss ich mir noch Sorgen machen? Meinst Du jetzt die externe Festplatte? |
29.09.2015, 12:09 | #13 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Ja, die meine ich. Da war nur Adware. Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: Combofix deinstallieren .
Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Absicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie . Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.09.2015, 20:36 | #14 |
| Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt Hey Schrauber Ich versuche nun seit heute Morgen die Windows-Updates zu installieren (sehr viele). Hierbei tritt immer ein Fehler auf und er versucht es wieder rückgängig zu machen. Ich komme nicht mehr bis zum Desktop, da er sich immer daran aufhängt, selbst im abgesicherten Modus. Hast Du eine Idee, wie man das umgehen kann? |
01.10.2015, 18:24 | #15 |
/// the machine /// TB-Ausbilder | Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt hi, Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7, 64 Bit, langsamer Rechner, Malwarebytes 128 Funde, Avira gestoppt |
antivirus, device driver, dnsapi.dll, entfernen, f.txt, feedback, festplatte, flash player, homepage, langsamer rechner, launch, programm, pup.optional.apntoolbar, pup.optional.conduit, pup.optional.conduittb.gen, pup.optional.dvdvideosoft, pup.optional.dvdvideosofttb, pup.optional.opencandy, pup.optional.pricegong, registry, software, svchost.exe, symantec, win32/pricegong.a, win32/toolbar.conduit, win32/toolbar.conduit.ai, win32/toolbar.conduit.ap, win32/toolbar.conduit.b, win32/toolbar.searchsuite.y |