Hallo Schrauber,
Danke!! für deine Nachricht.
Ich krieg das hin.
Soll ich auch die Firewall deaktivieren? Ich mache das erstmal mit bestehender Firewall, schalte nur Antivir und Spybot aus. - Und was sind CODE-Tags ? Ergibt sich das von allein?
Na, ich mach mal.
Schöne Grüße
Clara
Code:
ComboFix 13-12-04.02 - Percy Tibbles 04.12.2013 11:04:20.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3692.2245 [GMT 1:00]
ausgeführt von:: c:\users\Percy Tibbles\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\LyricsContainer
c:\program files (x86)\LyricsContainer\01.crx
c:\program files (x86)\LyricsContainer\01.xpi
c:\program files (x86)\LyricsContainer\02.crx
c:\program files (x86)\LyricsContainer\02.xpi
c:\program files (x86)\LyricsContainer\128.crx
c:\program files (x86)\LyricsContainer\128.dat
c:\program files (x86)\LyricsContainer\128.xpi
c:\program files (x86)\LyricsContainer\chrome.manifest
c:\program files (x86)\LyricsContainer\crx.dat
c:\program files (x86)\LyricsContainer\crx.db
c:\program files (x86)\LyricsContainer\sqlite3.dll
c:\program files (x86)\LyricsContainer\Uninstall.exe
c:\program files (x86)\LyricsContainer\xpi.dat
c:\program files (x86)\LyricsContainer\xpi.db
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome.manifest
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\asyncDB.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\background.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\browserAction.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\contextMenu.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\dbManager.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\dom_bg.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\fileManager.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\firefox.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\firefoxNotifications.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\firefoxOmnibox.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\message.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\pageAction.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\request.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\tabs.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\api\webRequest.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\background.html
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\baseObject.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\browser.xul
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\console.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\consts.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\delegate.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\extensionDataStore.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\folderIOWrapper.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\httpObserver.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\IDBWrapper.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\installer.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\logFile.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\prefs.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\progressListenerObserver.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\registry.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\reloadObserver.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\reports.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\requestObject.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\searchSettings.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\uninstallObserver.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\updateManager.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\utils.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\core\xhr.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\dialog.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\main.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\options.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\options.xul
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\chrome\content\search_dialog.xul
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\defaults\preferences\prefs.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\manifest.xml
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins.json
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\1_base.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\102_dealply_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\103_intext_5_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\104_jollywallet_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\105_corticas_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\108_icm_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\117_coupons_intext_ads_5_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\119_similar_web_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\120_luck_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\123_intext_adv_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\124_superfish_no_search_no_coupons_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\125_arcadi2_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\126_revizer_ws_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\127_revizer_p_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\128_superfish_pricora_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\135_arcadi3_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\138_getdeal_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\14_CrossriderUtils.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\141_corticas_ru_m.js.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\142_intext_fa_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\155_ibario_pops_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\158_50onred_ads_only_no_fb_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\159_cortica_rollover_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\16_FFAppAPIWrapper.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\17_jQuery.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\171_arcadi2_sourceID_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\174_arcadi_serp_dynamic_id_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\175_coolmirage_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\178_revizer_ws_dynamic_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\179_revizer_p_dynamic_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\180_bpo_serp_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\184_noproblemppc_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\189_active_sanity.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\190_pops_5_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\191_ciuvo_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\192_revizer_ws_dynamic_b2b_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\193_revizer_p_dynamic_b2b_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\194_retargeting_bi_m.js.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\195_icm_convertmedia_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\197_kreapixel_pops_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\199_superfish_no_coupons_plushd_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\200_foxydeal_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\21_debug.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\22_resources.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\28_initializer.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\4_jquery_1_7_1.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\47_resources_background.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\64_appApiMessage.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\7_hooks.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\72_appApiValidation.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\78_CrossriderInfo.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\87_ginyas_wrapper.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\9_search_engine_hook.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\91_monetizationLoader.js.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\93_superfish_no_coupons_m.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins\98_omniCommands.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\userCode\background.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\userCode\extension.js
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\install.rdf
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\locale\en-US\translations.dtd
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\button1.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\button2.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\button3.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\button4.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\button5.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\crossrider_statusbar.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\icon128.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\icon16.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\icon24.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\icon48.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\panelarrow-up.png
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\popup.html
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\skin.css
c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\skin\update.css
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-11-04 bis 2013-12-04 ))))))))))))))))))))))))))))))
.
.
2013-12-04 10:14 . 2013-12-04 10:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-12-03 08:15 . 2013-12-03 08:15 -------- d-----w- C:\FRST
2013-12-02 16:45 . 2013-12-02 16:45 -------- d-----w- c:\programdata\McAfee
2013-11-30 19:40 . 2013-11-30 19:40 -------- d-----w- c:\program files (x86)\VideoDownloadConverter
2013-11-28 14:31 . 2013-11-28 14:32 -------- d-----w- c:\program files\Paint.NET
2013-11-28 14:30 . 2013-11-28 15:15 -------- d-----w- c:\users\Percy Tibbles\AppData\Local\Paint.NET
2013-11-28 12:10 . 2013-11-28 12:13 -------- d-----w- c:\users\Percy Tibbles\AppData\Local\Google
2013-11-28 12:10 . 2013-11-28 12:10 -------- d-----w- c:\program files (x86)\Google
2013-11-28 08:27 . 2013-11-28 08:27 -------- d-----w- c:\programdata\CheckPoint
2013-11-28 08:06 . 2013-11-28 08:06 -------- d-----w- c:\users\Percy Tibbles\AppData\Roaming\Windows Net Data
2013-11-28 08:06 . 2013-11-28 08:06 -------- d-----w- c:\users\Percy Tibbles\AppData\Roaming\Nvu
2013-11-28 08:06 . 2013-11-28 17:03 -------- d-----w- c:\program files (x86)\Nvu
2013-11-24 15:53 . 2013-11-24 15:53 -------- d-----w- c:\program files (x86)\Allin1Convert_8h
2013-11-21 20:09 . 2013-11-21 20:09 -------- d-----w- c:\program files\Uninstaller
2013-11-21 19:59 . 2013-11-21 19:59 -------- d-----w- c:\program files (x86)\VideoPlayer
2013-11-21 19:59 . 2013-11-21 20:00 -------- d-----w- c:\program files (x86)\Feven 1.5
2013-11-21 19:59 . 2013-11-21 20:00 -------- d-----w- c:\program files (x86)\Plus-HD-1.3
2013-11-18 18:05 . 2013-12-04 09:45 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-11-18 18:05 . 2013-12-04 09:48 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-02 16:46 . 2013-09-10 21:35 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-02 16:46 . 2012-04-09 20:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110311121157}]
2013-11-21 19:59 641896 ----a-w- c:\program files (x86)\Plus-HD-1.3\Plus-HD-1.3-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110311851132}]
2013-11-21 19:59 641896 ----a-w- c:\program files (x86)\Feven 1.5\Feven 1.5-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{312f84fb-8970-4fd3-bddb-7012eac4afc9}]
2013-11-30 19:39 716360 ----a-w- c:\progra~2\VIDEOD~2\bar\1.bin\4zbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{a4c2fb10-84c3-44eb-9f9e-860fa1d9a797}]
2013-11-24 15:53 62864 ----a-w- c:\program files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b}]
2013-11-30 19:39 62864 ----a-w- c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d}]
2013-11-24 15:53 716360 ----a-w- c:\progra~2\ALLIN1~2\bar\1.bin\8hbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{cd1a63ba-a08c-431b-9a34-f240aadc728d}"= "c:\program files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll" [2013-11-24 716360]
"{48586425-6bb7-4f51-8dc6-38c88e3ebb58}"= "c:\program files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll" [2013-11-30 716360]
.
[HKEY_CLASSES_ROOT\clsid\{cd1a63ba-a08c-431b-9a34-f240aadc728d}]
.
[HKEY_CLASSES_ROOT\clsid\{48586425-6bb7-4f51-8dc6-38c88e3ebb58}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-11-10 343168]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"HotkeyMon"="AsusSender.exe" [2012-01-05 34728]
"HotkeyService"="AsusSender.exe" [2012-01-05 34728]
"SuperHybridEngine"="AsusSender.exe" [2012-01-05 34728]
"CapsHook"="AsusSender.exe" [2012-01-05 34728]
"ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe" [2011-07-29 737104]
"ASUS Smart Camera"="c:\program files (x86)\ASUS\ASUS Smart Camera\SmartCamera.exe" [2012-02-03 1883824]
"iSeriesCharge"="AsusSender.exe" [2012-01-05 34728]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2012-04-09 3331312]
"Allin1Convert Search Scope Monitor"="c:\progra~2\ALLIN1~2\bar\1.bin\8hsrchmn.exe" [2013-11-24 44784]
"Allin1Convert_8h Browser Plugin Loader"="c:\progra~2\ALLIN1~2\bar\1.bin\8hbrmon.exe" [2013-11-24 30096]
"VideoDownloadConverter Search Scope Monitor"="c:\progra~2\VIDEOD~2\bar\1.bin\4zsrchmn.exe" [2013-11-30 44784]
"VideoDownloadConverter_4z Browser Plugin Loader"="c:\progra~2\VIDEOD~2\bar\1.bin\4zbrmon.exe" [2013-11-30 30096]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2012-4-9 549040]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-12-23 1131808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 DCDhcpService;DCDhcpService;c:\program files\WiSharing\DCDhcpService.exe;c:\program files\WiSharing\DCDhcpService.exe [x]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AiDriver;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiDriver.sys;c:\windows\SYSNATIVE\DRIVERS\AiDriver.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK WMIACPI\epcwmiacpi64.sys;c:\program files (x86)\ASUS\ATK WMIACPI\epcwmiacpi64.sys [x]
S2 Allin1Convert_8hService;Allin1ConvertService;c:\progra~2\ALLIN1~2\bar\1.bin\8hbarsvc.exe;c:\progra~2\ALLIN1~2\bar\1.bin\8hbarsvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AsusService;Asus Launcher Service;c:\windows\SysWOW64\AsusService.exe;c:\windows\SysWOW64\AsusService.exe [x]
S2 VideoDownloadConverter_4zService;VideoDownloadConverterService;c:\progra~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe;c:\progra~2\VIDEOD~2\bar\1.bin\4zbarsvc.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys;c:\windows\SYSNATIVE\DRIVERS\bcmvwl64.sys [x]
S3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 rtsuvc;Realtek USB2.0 PC Camera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-12-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-10 16:46]
.
2013-11-21 c:\windows\Tasks\Feven 1.5-chromeinstaller.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-chromeinstaller.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Feven 1.5-codedownloader.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-codedownloader.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Feven 1.5-enabler.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-enabler.exe [2013-11-21 20:00]
.
2013-11-21 c:\windows\Tasks\Feven 1.5-firefoxinstaller.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-firefoxinstaller.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Feven 1.5-updater.job
- c:\program files (x86)\Feven 1.5\Feven 1.5-updater.exe [2013-11-21 20:00]
.
2013-11-21 c:\windows\Tasks\Plus-HD-1.3-chromeinstaller.job
- c:\program files (x86)\Plus-HD-1.3\Plus-HD-1.3-chromeinstaller.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Plus-HD-1.3-codedownloader.job
- c:\program files (x86)\Plus-HD-1.3\Plus-HD-1.3-codedownloader.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Plus-HD-1.3-enabler.job
- c:\program files (x86)\Plus-HD-1.3\Plus-HD-1.3-enabler.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Plus-HD-1.3-firefoxinstaller.job
- c:\program files (x86)\Plus-HD-1.3\Plus-HD-1.3-firefoxinstaller.exe [2013-11-21 19:59]
.
2013-11-21 c:\windows\Tasks\Plus-HD-1.3-updater.job
- c:\program files (x86)\Plus-HD-1.3\Plus-HD-1.3-updater.exe [2013-11-21 20:00]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2011-05-25 07:09 227840 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-21 323584]
"LiveUpdate"="AsusSender.exe" [2011-08-08 34728]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2011-04-14 467120]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-07-20 12632168]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2012-12-13 7138816]
"Allin1Convert Home Page Guard 64 bit"="c:\progra~2\ALLIN1~2\bar\1.bin\AppIntegrator64.exe" [2013-11-24 548936]
"VideoDownloadConverter Home Page Guard 64 bit"="c:\progra~2\VIDEOD~2\bar\1.bin\AppIntegrator64.exe" [2013-11-30 548936]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://home.tb.ask.com/index.jhtml?n=77FD35DB&p2=^AYY^xdm070^YYA^de&ptb=2FB13124-9428-43D2-8CEC-EC2C8AB3F750&si=flvrunner
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1385063937&from=tugs&uid=ST9320325AS_6VDERSDMXXXX6VDERSDM&q={searchTerms}
mDefault_Page_URL = hxxp://do-search.com/?type=hp&ts=1385063937&from=tugs&uid=ST9320325AS_6VDERSDMXXXX6VDERSDM
mStart Page = hxxp://do-search.com/?type=hp&ts=1385063937&from=tugs&uid=ST9320325AS_6VDERSDMXXXX6VDERSDM
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://do-search.com/web/?type=ds&ts=1385063937&from=tugs&uid=ST9320325AS_6VDERSDMXXXX6VDERSDM&q={searchTerms}
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoGOblidooYB&dpid=SnapdoGOblidooYB&co=DE&userid=b60e1415-7c77-d679-9b7d-8bdf5fea9143&searchtype=ds&q={searchTerms}&installDate=15/08/2013
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\
FF - prefs.js: browser.search.selectedEngine - Ask Web Search
FF - prefs.js: browser.startup.homepage - hxxp://home.tb.ask.com/index.jhtml?ptb=273B559C-CF24-4030-8746-35CC2C6FB2DE&n=77fdaabc&p2=^HJ^xdm382^YYA^de&si=pconverter
FF - prefs.js: keyword.URL - hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=273B559C-CF24-4030-8746-35CC2C6FB2DE&n=77fdaabc&ind=2013113020&p2=^HJ^xdm382^YYA^de&si=pconverter&searchfor=
FF - ExtSQL: 2013-11-18 11:06; {b60e1415-7c77-d679-9b7d-8bdf5fea9143}; c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\{b60e1415-7c77-d679-9b7d-8bdf5fea9143}
FF - ExtSQL: 2013-11-21 20:59; 509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com; c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com
FF - ExtSQL: 2013-11-28 09:37; EFGLQA@78ETGYN-0W7FN789T87.COM; c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF - ExtSQL: 2013-11-30 20:39; 4zffxtbr@VideoDownloadConverter_4z.com; c:\users\Percy Tibbles\AppData\Roaming\Mozilla\Firefox\Profiles\r6zvhpqz.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Lyrics@LyricsContainer.co - c:\program files (x86)\LyricsContainer\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-12-04 11:19:38
ComboFix-quarantined-files.txt 2013-12-04 10:19
.
Vor Suchlauf: 9.079.631.872 Bytes frei
Nach Suchlauf: 8.935.448.576 Bytes frei
.
- - End Of File - - 791688B4F70843E8DCB0209FC1B1C171
A36C5E4F47E84449FF07ED3517B43A31
Lieber Schrauber,
Das Programm ist eben durchgelaufen. Ich hab das Ergenis in die Raute-Zeichen gesetzt. Denke, das war so gemeint.
Ich bin sehr vfroh, dass du dir Zeit für mein PC-Problem genommen hast. Bin ziemlich erstaunt, was da alles gefunden und gelöscht wurde.
Könntest du mir kurz schreiben, ob da ein Trojaner/Virus dabei war, der einen speziellen Namen hat? Ich würde gerne den Leuten, die in letzter Zeit Anhänge von mir erhalten haben sagen, worauf sie achten müssten.
Du hattest geschrieben, während des Prozesses die Maus nicht bewegen.
Ich habe die ersten Textzeilen mitgetippt (weil ich dachte, da stehen Anweisungen für mich, die ich nicht verlieren wollte) . Bevor Stufe 1 angezeigt wurde, hatte ich mit dem Tippen aber aufgehört.
Kurz vor Ende wurde der Monitor schwarz. Da hab ich auf die Leertaste getippt, um wieder sehen zu können.
Das Programm ist glatt durchgelaufen. Nichts hat gemeckert.
Meine letzte Frage betrifft meine externen Festplatten u. USB-Sticks. Wie würdest du vorgehen-und die scannen/reinigen?
Wenn ich die wieder verwende, geht das Spiel doch wieder von vorne los.
Ich sehe gerade, dass ich die externe Festplatte während des Scan-Vorgangs dran hatte. Ist die in einem Abwasch mitgereinigt worden?
Meine allerletzte Frage ist: konnte das, was meinen Rechner geärgert hat, auch die SD Karten meiner Digitalcamera infiziert haben?
Schöne Grüße
von Clara
Lieber Schrauber,
zunächst: Grünu. doppelt unterstrichen sind immer noch einige Worte. Ich habe das bei Antivir gesehen und auch auf eurer Seite.
Aso was das verursacht-das ist noch da.
Ich habe jetzt erstmal Antivir, die free-version installiert - damit ich wenigstens einen minimalen Schutz habe. Ich mit nur auf eurer Seite unterwegs. Allesandere lass ich mal.
Ich werde wahrscheinlich Kaspersy installieren. - Wenn du einen bestimmten Virenscanner favorisierst, lass hören.
Schöne Grüße
Clara
Guten Morgen Schrauber,
ich möchte eine kurze Rückmeldung geben.
Ich habe gestern ausserdem noch meinen Rechner aufgeräumt - einige vorinstallierte Spiele entfernt. Heute läuft die Kiste wie von allein. Das ist wunderbar! 1000x Danke!
Diese grün und doppelt unterstrichenen Worte kommen jetzt nicht mehr so häufig vor-aber sie sind vereinzelt immer noch da. Also das ist im Moment sehr zurückgegangen. -Aber so fing es auch einmal an und wurde täglich mehr.
Ich habe gestern in verschiedenen Foren gelesen mit den vorinstallierten Programmen zu tun ist, die man nicht braucht. "Einfach löschen!" hab ich mehrfach gelesen. Das machte ich. Dann am Ende bin ich auf eine andere Meinung gestoßen. Man sollte die nicht löschen, sondern deaktivieren (damit das System als ganzen stabil bleibt. Auch wenn es sich nur um Spiele handelt).
Wie ist deine Meinung dazu?
Schöne Grüße
Clara