Hier die Logs: Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.03.19.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16521
Andreas :: ANDREAS-HP [Administrator]
Schutz: Aktiviert
19/03/2014 18:33:56
MBAM-log-2014-03-19 (18-44-32).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 269835
Laufzeit: 6 Minute(n), 37 Sekunde(n)
Infizierte Speicherprozesse: 3
C:\Program Files\SavingsbullFilter\SavingsbullFilterService64.exe (PUP.Optional.SavingsBull.A) -> 2064 -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\conadvanced.exe (PUP.Optional.Context2Pro.A) -> 3804 -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\contextfr.exe (PUP.Optional.Context2Pro.A) -> 3556 -> Keine Aktion durchgeführt.
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 40
HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Keine Aktion durchgeführt.
HKCR\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3} (PUP.Optional.ScorpionSaver) -> Keine Aktion durchgeführt.
HKCR\CLSID\{33119133-0854-469d-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Keine Aktion durchgeführt.
HKCR\TypeLib\{03119103-0854-469d-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Keine Aktion durchgeführt.
HKCR\Interface\{23119123-0854-469D-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Keine Aktion durchgeführt.
HKCR\UtilityChest_49.SkinLauncherSettings.1 (PUP.Optional.FunWebProducts.A) -> Keine Aktion durchgeführt.
HKCR\UtilityChest_49.SkinLauncherSettings (PUP.Optional.FunWebProducts.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3444c3c5-6c56-4a16-a453-832b05bf6ea4} (PUP.Optional.MoviesToolBar.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3444c3c5-6c56-4a16-a453-832b05bf6ea4} (PUP.Optional.MoviesToolBar.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346} (PUP.Optional.ValueApps.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite (PUP.Optional.DigitalSites.A) -> Keine Aktion durchgeführt.
HKLM\SYSTEM\CurrentControlSet\Services\SavingsbullFilterService64 (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Context2pro (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\BabylonToolbar (PUP.Optional.BabylonToolBar.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\DataMngr_Toolbar (PUP.Optional.DataMngr.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Funmoods (PUP.FunMoods) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Keine Aktion durchgeführt.
HKCU\Software\Iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt.
HKCU\Software\SavingsBull (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
HKCU\Software\AppDataLow\Software\Savings Bull (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
HKCU\Software\AppDataLow\Software\SavingsBull (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\BI (PUP.Optional.FilesFrog.A) -> Keine Aktion durchgeführt.
HKCU\Software\Conduit\FF (PUP.Optional.Conduit.A) -> Keine Aktion durchgeführt.
HKCU\Software\Conduit\ValueApps (PUP.Optional.ValueApps.A) -> Keine Aktion durchgeführt.
HKCU\Software\Distromatic\Toolbars (PUP.Optional.AlexaTB.A) -> Keine Aktion durchgeführt.
HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\BabylonToolbar (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\SavingsbullFilter (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\DATAMNGR (PUP.Optional.MoviesToolbar.A) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Keine Aktion durchgeführt.
HKLM\Software\awesomehpSoftware (PUP.Optional.Awesomehp.A) -> Keine Aktion durchgeführt.
HKLM\Software\Iminent (PUP.Optional.Iminent.A) -> Keine Aktion durchgeführt.
Infizierte Registrierungswerte: 9
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{3444c3c5-6c56-4a16-a453-832b05bf6ea4} (PUP.Optional.MoviesToolBar.A) -> Daten: Movies Toolbar (Dist. by Somoto Ltd.) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{3444c3c5-6c56-4a16-a453-832b05bf6ea4} (PUP.Optional.MoviesToolBar.A) -> Daten: -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|conadvanced (PUP.Optional.Context2Pro.A) -> Daten: C:\Users\Andreas\AppData\Local\Context2pro\conadvanced.exe -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|contextfr (PUP.Optional.Context2Pro.A) -> Daten: C:\Users\Andreas\AppData\Local\Context2pro\contextfr.exe -> Keine Aktion durchgeführt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|contextprod (PUP.Optional.Context2Pro.A) -> Daten: C:\Users\Andreas\AppData\Local\Context2pro\contextprod.exe -> Keine Aktion durchgeführt.
HKCU\Software\BI|ui_path_filesfrog (PUP.Optional.FilesFrog.A) -> Daten: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker -> Keine Aktion durchgeführt.
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0Q1O2W1R1D0D1S1J -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Datamngr|uninstallstring (PUP.Optional.MoviesToolbar.A) -> Daten: C:\Program Files (x86)\Movies Toolbar\SafetyNut\uninstall.exe -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|lightningnewtab@gmail.com (PUP.Optional.Lightning.A) -> Daten: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\extensions\lightningnewtab@gmail.com.xpi -> Keine Aktion durchgeführt.
Infizierte Dateiobjekte der Registrierung: 3
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (PUP.Optional.Awesomehp.A) -> Bösartig: (hxxp://www.awesomehp.com/web/?type=ds&ts=1392155160&from=tugs&uid=HitachiXHTS547575A9E384_J2540054DYL3ZEDYL3ZEX&q={searchTerms}) Gut: (hxxp://www.google.com) -> Keine Aktion durchgeführt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Awesomehp.A) -> Bösartig: (hxxp://www.awesomehp.com/?type=hp&ts=1392155160&from=tugs&uid=HitachiXHTS547575A9E384_J2540054DYL3ZEDYL3ZEX) Gut: (hxxp://www.google.com) -> Keine Aktion durchgeführt.
HKLM\Software\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.Awesomehp.A) -> Bösartig: (hxxp://www.awesomehp.com/?type=hp&ts=1392155160&from=tugs&uid=HitachiXHTS547575A9E384_J2540054DYL3ZEDYL3ZEX) Gut: (hxxp://www.google.com) -> Keine Aktion durchgeführt.
Infizierte Verzeichnisse: 25
C:\Users\Andreas\AppData\Roaming\ValueApps\CH (PUP.Optional.ValueApps.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSites\UpdateProc (PUP.Optional.Updater) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Program Files\Level Quality Watcher\v1.01 (PUP.Optional.Adpeak) -> Keine Aktion durchgeführt.
C:\ProgramData\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\ProgramData\BonanzaDealsLive\Update (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\ProgramData\BonanzaDealsLive\Update\Log (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\BonanzaDealsLive (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\BonanzaDealsLive\CrashReports (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\Program Files\Conduit\ValueApps (PUP.Optional.ValueAppsplugin.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\Conduit\ValueApps (PUP.Optional.ValueAppsplugin.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Conduit\ValueApps (PUP.Optional.ValueAppsplugin.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0 (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\contentScripts (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\ProgramData\IePluginService (PUP.Optional.IePluginService.A) -> Keine Aktion durchgeführt.
C:\ProgramData\IePluginService\update (PUP.Optional.IePluginService.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
Infizierte Dateien: 63
C:\ProgramData\DSearchLink\DSearchLink.exe (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe (PUP.Optional.DigitalSites.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\Downloads\7ZipSetup.exe (PUP.Optional.Somoto.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\Downloads\Player.exe (PUP.Optional.BundleInstaller.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\Downloads\SoftonicDownloader_para_malwarebytes-anti-malware.exe (PUP.Optional.Softonic.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\Downloads\SoftonicDownloader_para_pdf-split-and-merge.exe (PUP.Optional.Softonic) -> Keine Aktion durchgeführt.
C:\Users\Andreas\Downloads\UltimateCodec.exe (PUP.Optional.BundleInstaller.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\Downloads\ZipExtractorSetup.exe (PUP.Optional.InstallCore) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\ValueApps\CH\TBVerifier.dll (PUP.Optional.ValueApps.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\sample.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\Installbat64.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\Microsoft.Deployment.WindowsInstaller.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\Microsoft.Deployment.WindowsInstaller.xml (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\netfilter64.sys (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\nfapi.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\nfregdrv.exe (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\ProtocolFilters.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files\SavingsbullFilter\SavingsbullFilterService64.exe (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSites\UpdateProc\UpdateTask.exe (PUP.Optional.Updater) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSites\UpdateProc\config.dat (PUP.Optional.Updater) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSites\UpdateProc\info.dat (PUP.Optional.Updater) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSites\UpdateProc\STTL.DAT (PUP.Optional.Updater) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSites\UpdateProc\TTL.DAT (PUP.Optional.Updater) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc\config.dat (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc\info.dat (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc\prod.dat (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage (PUP.Optional.BrowserDefender.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\notifications.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\conadvanced.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\Context2pro_Uninstaller.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\contextfr.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\contextnav.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\contextprod.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Context2pro\libwindoc.exe (PUP.Optional.Context2Pro.A) -> Keine Aktion durchgeführt.
C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe (PUP.Optional.Adpeak) -> Keine Aktion durchgeführt.
C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe (PUP.Optional.Adpeak) -> Keine Aktion durchgeführt.
C:\ProgramData\BonanzaDealsLive\Update\Log\BonanzaDealsLive.log (PUP.Optional.BonanzaDeals.A) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\background.html (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\icon.png (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\icon128.png (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\icon16.png (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\icon48.png (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\manifest.json (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\options.html (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\popup.html (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\js\background.js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\js\options.js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\background.html (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\settings.json (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\background.js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\iframeHost.html (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\iframeHost.js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\popup.js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon\1.0.0_0\mam\scripts\contentScripts\contentScript.js (PUP.Optional.ValueApps) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\bootstrap.js.old (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\CustomActionInstall (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\CustomActionUninstall (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\ff_main.js.old (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\Microsoft.Deployment.WindowsInstaller.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\Microsoft.Deployment.WindowsInstaller.xml (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
C:\Program Files (x86)\SavingsBull\SendJson.dll (PUP.Optional.SavingsBull.A) -> Keine Aktion durchgeführt.
(Ende) Code:
# AdwCleaner v3.022 - Reporte Creado 19/03/2014 en 19:01:45
# Actualizado 13/03/2014 por Xplode
# Sistema Operativo : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nombre de usuario : Andreas - ANDREAS-HP
# Ejecutado desde : C:\Users\Andreas\Downloads\adwcleaner.exe
# Opción : Limpiar
***** [ Servicios ] *****
***** [ Archivos / Carpetas ] *****
***** [ Accesos directos ] *****
Acceso directo Desinfectado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Acceso directo Desinfectado : C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Acceso directo Desinfectado : C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Acceso directo Desinfectado : C:\Users\Andreas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Acceso directo Desinfectado : C:\Users\Andreas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Acceso directo Desinfectado : C:\Users\Andreas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registro ] *****
Clave Borrar : HKLM\SOFTWARE\Classes\Prod.cap
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.DynamicBarButton
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.DynamicBarButton.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.FeedManager
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.FeedManager.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLMenu
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLMenu.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLPanel
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.HTMLPanel.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.MultipleButton
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.MultipleButton.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.PseudoTransparentPlugin
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.PseudoTransparentPlugin.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.Radio
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.Radio.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.RadioSettings
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.RadioSettings.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.ScriptButton
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.ScriptButton.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.SettingsPlugin
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.SettingsPlugin.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.SkinLauncher
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.SkinLauncher.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.ThirdPartyInstaller
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.ThirdPartyInstaller.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.ToolbarProtector
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.ToolbarProtector.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.UrlAlertButton
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.UrlAlertButton.1
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.XMLSessionPlugin
Clave Borrar : HKLM\SOFTWARE\Classes\UtilityChest_49.XMLSessionPlugin.1
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Clave Borrar : HKCU\Software\92d7ddbc3ebf43
Clave Borrar : HKLM\SOFTWARE\92d7ddbc3ebf43
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_para_pdf-split-and-merge_RASAPI32
Clave Borrar : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_para_pdf-split-and-merge_RASMANCS
Clave Borrar : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Clave Borrar : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{23699B0B-C14D-4054-A545-FC0927BB0879}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{25151605-D156-49DD-A659-20E69C1EE15F}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{268CA04C-106C-4636-B707-95E8CD5859E0}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{2BB3E614-F616-42DD-A99A-69C1FC268741}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{35274ADF-B8DE-4909-80D1-A26269216903}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{3F2F1B3C-EDA7-46EC-A1CA-12A67CD00A82}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{5BBF357E-EA8C-48BF-83CA-DE279FB83BBA}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{698E7AA1-A28E-4064-A9AB-822171AF4EF4}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{6AAFD84D-5F7F-42E5-9FB4-157925C3ED2F}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{83CE5D73-E3DE-4DC5-82C2-3B65DFD0A849}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{878A5A0A-DC0A-4C37-BBE2-18C30E50F449}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{8C428C4B-C9E2-4B74-B791-88C3FEE48F36}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{929825DF-A1B4-40C9-8F3C-6DA06BADC150}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{9F19923D-2A4C-45EF-A026-AE7DEE5D022C}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{A72B8EA8-5B63-4C90-9FE8-D9C76C99DE32}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{C86BFADB-406F-47C7-A8D8-FAA37B39089F}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{D92EDE9A-70A4-469F-AF8F-38C3F278B0A1}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{F67A3AA8-88EE-4A3A-863A-B13A19F8696C}
Clave Borrar : HKLM\SOFTWARE\Classes\CLSID\{F8E1BDAB-F48F-46F9-8693-4EECB83D1AD7}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{0E1FE4D8-70CE-417E-8FF4-C2B17FF3DD07}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{13B8FF9D-DEB0-4070-B846-D049218307B3}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{1E877590-30B7-400E-A835-B942489EB7BC}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Clave Borrar : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{103E3C9A-E8AE-4B19-A339-01FE9439763E}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{24486CE9-7BC2-4516-B743-39FFDD4F861B}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{326C4F48-FE3B-4E54-9118-9B6C3B6C9B1E}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{39D884BB-2881-4F3A-B9B9-2D3AF4C2C191}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{59E5BDB9-126F-4575-901E-D32132A19B94}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{5CF866F0-10A3-4ED4-9BE3-668F2F148E2F}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{618B2F0C-A1AF-4D1D-9354-CF0C42AF5BCB}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{8EFEE482-37BC-4F3D-83E6-CB5BBE077E43}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{CE1482C8-E8FD-4277-9A4F-094D712F6B60}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{EEFDBFA7-0F18-4216-8F90-6B6F71D6AB83}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{F12BA68C-976E-4567-BA3B-629DFCEBC5FE}
Clave Borrar : HKLM\SOFTWARE\Classes\TypeLib\{F66F6A81-E727-4774-B461-8A5CB7F7DE07}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06E05B40-77FA-40B6-9077-ED1A7577B1EF}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Clave Borrar : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Clave Borrar : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Clave Borrar : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25151605-D156-49DD-A659-20E69C1EE15F}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{268CA04C-106C-4636-B707-95E8CD5859E0}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{698E7AA1-A28E-4064-A9AB-822171AF4EF4}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8C428C4B-C9E2-4B74-B791-88C3FEE48F36}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9F19923D-2A4C-45EF-A026-AE7DEE5D022C}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F67A3AA8-88EE-4A3A-863A-B13A19F8696C}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0E1FE4D8-70CE-417E-8FF4-C2B17FF3DD07}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{13B8FF9D-DEB0-4070-B846-D049218307B3}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E877590-30B7-400E-A835-B942489EB7BC}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{878A5A0A-DC0A-4C37-BBE2-18C30E50F449}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{992177A5-DF3C-4EC2-B779-6A5F94704CCC}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFBAF9B2-2093-4D16-9D1F-348AE68408E4}
Clave Borrar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clave Borrar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clave Borrar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{84DC9F6C-C9A5-4C64-AB67-D6EF60F963C8}
Clave Borrar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clave Borrar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{84DC9F6C-C9A5-4C64-AB67-D6EF60F963C8}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{0E1FE4D8-70CE-417E-8FF4-C2B17FF3DD07}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{13B8FF9D-DEB0-4070-B846-D049218307B3}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{1E877590-30B7-400E-A835-B942489EB7BC}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Clave Borrar : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93DBF2BB-A2B3-4683-A92E-57E60751F346}
Clave Borrar : HKCU\Software\Conduit
Clave Borrar : HKCU\Software\Delta
Clave Borrar : HKCU\Software\distromatic
Clave Borrar : HKCU\Software\dsiteproducts
Clave Borrar : HKCU\Software\lollipop
Clave Borrar : HKCU\Software\OCS
Clave Borrar : HKCU\Software\Softonic
Clave Borrar : HKCU\Software\systweak
Clave Borrar : HKCU\Software\UtilityChest_49
Clave Borrar : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Clave Borrar : HKCU\Software\AppDataLow\Software\Conduit
Clave Borrar : HKCU\Software\AppDataLow\Software\SmartBar
Clave Borrar : HKCU\Software\AppDataLow\Software\UtilityChest_49
Clave Borrar : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Clave Borrar : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Clave Borrar : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Clave Borrar : HKLM\Software\Babylon
Clave Borrar : HKLM\Software\Delta
Clave Borrar : HKLM\Software\SafetyNut
Clave Borrar : HKLM\Software\supTab
Clave Borrar : HKLM\Software\supWPM
Clave Borrar : HKLM\Software\systweak
Clave Borrar : HKLM\Software\UtilityChest_49
Clave Borrar : HKLM\Software\Wpm
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Clave Borrar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UtilityChest_49bar Uninstall
Clave Borrar : [x64] HKLM\SOFTWARE\Iminent
Clave Borrar : [x64] HKLM\SOFTWARE\Savings Bull
Clave Borrar : [x64] HKLM\SOFTWARE\SavingsBull Filter
Clave Borrar : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{813BA625-B0FA-48D8-9B75-59759C88C219}
Clave Borrar : HKLM\Software\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D
Clave Borrar : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Clave Borrar : HKLM\Software\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
Clave Borrar : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Navegadores ] *****
-\\ Internet Explorer v11.0.9600.16521
Ajustes Restaurar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Ajustes Restaurar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v27.0.1 (es-ES)
[ Archivo : C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\prefs.js ]
Linea borrada : user_pref("CT3241944.1000082.isDisplayHidden", "true");
Linea borrada : user_pref("CT3241944.1000082.isPlayDisplay", "true");
Linea borrada : user_pref("CT3241944.1000234.TWC_TMP_city", "MADRID");
Linea borrada : user_pref("CT3241944.1000234.TWC_TMP_country", "ES");
Linea borrada : user_pref("CT3241944.1000234.TWC_locId", "SPXX0050");
Linea borrada : user_pref("CT3241944.1000234.TWC_location", "Madrid, EspaÃÃâ€*’Ãâ€Â*’Ãâ€ÂÂ*’ÃÃâ€*’â[...]
Linea borrada : user_pref("CT3241944.1000234.TWC_region", "ES");
Linea borrada : user_pref("CT3241944.1000234.TWC_temp_dis", "c");
Linea borrada : user_pref("CT3241944.1000234.TWC_wind_dis", "kmh");
Linea borrada : user_pref("extensions.crossrider.bic", "14422ebd76d36df960ca527520aa738a");
Linea borrada : user_pref("extensions.delta.admin", false);
Linea borrada : user_pref("extensions.delta.aflt", "babsst");
Linea borrada : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Linea borrada : user_pref("extensions.delta.autoRvrt", "false");
Linea borrada : user_pref("extensions.delta.dfltLng", "es");
Linea borrada : user_pref("extensions.delta.excTlbr", false);
Linea borrada : user_pref("extensions.delta.ffxUnstlRst", true);
Linea borrada : user_pref("extensions.delta.id", "b49482c2000000000000000000000000");
Linea borrada : user_pref("extensions.delta.instlDay", "15976");
Linea borrada : user_pref("extensions.delta.instlRef", "sst");
Linea borrada : user_pref("extensions.delta.newTab", false);
Linea borrada : user_pref("extensions.delta.prdct", "delta");
Linea borrada : user_pref("extensions.delta.prtnrId", "delta");
Linea borrada : user_pref("extensions.delta.rvrt", "false");
Linea borrada : user_pref("extensions.delta.smplGrp", "none");
Linea borrada : user_pref("extensions.delta.tlbrId", "base");
Linea borrada : user_pref("extensions.delta.tlbrSrchUrl", "");
Linea borrada : user_pref("extensions.delta.vrsn", "1.8.24.6");
Linea borrada : user_pref("extensions.delta.vrsnTs", "1.8.24.616:58:47");
Linea borrada : user_pref("extensions.delta.vrsni", "1.8.24.6");
Linea borrada : user_pref("extensions.delta_i.babExt", "");
Linea borrada : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=240913_238&tsp=5019");
Linea borrada : user_pref("extensions.delta_i.srcExt", "ss");
Linea borrada : user_pref("iminent.LayoutId", "1");
Linea borrada : user_pref("iminent.ShowThankyouPixel", "0");
Linea borrada : user_pref("iminent.externalScripts.iRobinHood.menuURL", "hxxp://iminent.donation-tools.org/home.aspx?pkgId=wrDCtcK4wrnCtsKxwrPCt8K3");
Linea borrada : user_pref("iminent.registerToolbarEvent102", "1392748912208");
Linea borrada : user_pref("iminent.registerToolbarEvent109", "1393522911968");
Linea borrada : user_pref("iminent.registerToolbarEvent111", "1393522912022");
Linea borrada : user_pref("iminent.registerToolbarEvent112", "1393522912831");
Linea borrada : user_pref("iminent.registerToolbarEvent122", "1393522912072");
Linea borrada : user_pref("iminent.trackExternalScripts1", "1393968454280");
Linea borrada : user_pref("iminent.trackExternalScripts2", "1393968454341");
Linea borrada : user_pref("iminent.trackExternalScripts3", "1394482076557");
Linea borrada : user_pref("iminent.version", "8.10.2.1");
Linea borrada : user_pref("valueApps.ct3319214./9B+7E+x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E,x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E-x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E.:2z527.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E.x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E/x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E06CG5EL8:", "6E6D6870726F70737773");
Linea borrada : user_pref("valueApps.ct3319214./9B+7E06CG5EL8:.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E06CG5EL;8I:K", "247E2D2F226A74736E76787576797D79242F4B49474F42357D5D5C3D");
Linea borrada : user_pref("valueApps.ct3319214./9B+7E06CG5EL;8I:K.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E0x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E1x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E2x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E3x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E4x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E5x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E6x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E7x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E8x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E9x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E:x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E;x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E<x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E=x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E>x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E?x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7E@x305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7EAx305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7EBE3G=;D9N9=D", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57");
Linea borrada : user_pref("valueApps.ct3319214./9B+7EBE3G=;D9N9=D.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B+7EBx305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7ECx305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7EDx305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B+7Etx305.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214./9B-0?3G>D", "3B3F6F3E6D6B6C737A77734777207D7E7C4E254D5151522A21232656552A575D5C2B2B5E");
Linea borrada : user_pref("valueApps.ct3319214./9B-0?3G>D.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B-0?3G@6:5;", "");
Linea borrada : user_pref("valueApps.ct3319214./9B-0?3G@6:5;.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B-0?3GFA7EF", "2B2E2C3D");
Linea borrada : user_pref("valueApps.ct3319214./9B-0?3GFA7EF.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B-3=3ECCJA=F>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D686365533C70766C66755E");
Linea borrada : user_pref("valueApps.ct3319214./9B-3=3ECCJA=F>.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B/>01=9A6K6<IM;KRIE@PDAWM", "6A696B7273747576");
Linea borrada : user_pref("valueApps.ct3319214./9B/>01=9A6K6<IM;KRIE@PDAWM.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B3=>@44I48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F");
Linea borrada : user_pref("valueApps.ct3319214./9B3=>@44I48?.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B5BA==9CJAG", "3A3F6B6B6A6D6F417A6F7147754779777C7D4E7B4F");
Linea borrada : user_pref("valueApps.ct3319214./9B5BA==9CJAG.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B6B11G4C56B>F;P;ANR@P", "6E6D6870726F70737677747278");
Linea borrada : user_pref("valueApps.ct3319214./9B6B11G4C56B>F;P;ANR@P.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B90E@.3C;7B=?OFB>>RHIQS", "393F352F3E");
Linea borrada : user_pref("valueApps.ct3319214./9B90E@.3C;7B=?OFB>>RHIQS.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B9643G3/9E", "6A");
Linea borrada : user_pref("valueApps.ct3319214./9B9643G3/9E.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B;45>:BI9I7IE", "2B2E2C3D");
Linea borrada : user_pref("valueApps.ct3319214./9B;45>:BI9I7IE.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B<:222H64<", "393F352F3E");
Linea borrada : user_pref("valueApps.ct3319214./9B<:222H64<.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B<:222H64<L8DAJ", "6D70706E7674737976772A787A727976757E7C");
Linea borrada : user_pref("valueApps.ct3319214./9B<:222H64<L8DAJ.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B=+03EH8H8J?:", "4443");
Linea borrada : user_pref("valueApps.ct3319214./9B=+03EH8H8J?:.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B?+E2A52D8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
Linea borrada : user_pref("valueApps.ct3319214./9B?+E2A52D8.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9B?B0D:8AJ62<H", "6D");
Linea borrada : user_pref("valueApps.ct3319214./9B?B0D:8AJ62<H.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214./9BA@0<0BI6A7GN:6@L?", "6C");
Linea borrada : user_pref("valueApps.ct3319214./9BA@0<0BI6A7GN:6@L?.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.PG_ENABLE", "74727565");
Linea borrada : user_pref("valueApps.ct3319214.PG_ENABLE.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.SF_JUST_INSTALLED", "46414C5345");
Linea borrada : user_pref("valueApps.ct3319214.SF_JUST_INSTALLED.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.SF_STATUS", "454E41424C4544");
Linea borrada : user_pref("valueApps.ct3319214.SF_STATUS.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.SF_USER_ID", "6369645F3131323230313432323438333137323637373033");
Linea borrada : user_pref("valueApps.ct3319214.SF_USER_ID.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214._key_cl_active", "36383566343066362D356237372D343863362D626634322D336162366132633833303439");
Linea borrada : user_pref("valueApps.ct3319214._key_cl_active.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.cb_experience_000", "3131");
Linea borrada : user_pref("valueApps.ct3319214.cb_experience_000.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.cb_firstuse0100", "31");
Linea borrada : user_pref("valueApps.ct3319214.cb_firstuse0100.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.cb_user_id_000", "43423635333031393733303832305F313339323332343933333532385F46697265666F78");
Linea borrada : user_pref("valueApps.ct3319214.cb_user_id_000.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.cbfirsttime", "5475652046656220313120323031342032323A34383A323720474D542B30313030");
Linea borrada : user_pref("valueApps.ct3319214.cbfirsttime.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appStateReportTime", "31333934353538363535323739");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appStateReportTime.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appState_Clarity_Active", "6F6E");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appState_Clarity_Active.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appsConfig.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appsDefaultEnabled", "6E756C6C");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_appsDefaultEnabled.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_calledSetupService", "31");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_calledSetupService.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_currentBadgeValue", "31");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_currentBadgeValue.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_currentVersion", "312E31332E302E3137");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_currentVersion.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_first_time", "31");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_first_time.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_lastInstallationSessionGuid", "7B31386631623232332D663033312D346231612D623065382D3731376439366331316430657D");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_lastInstallationSessionGuid.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_lastLoginTime", "31333934353538363535363336");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_lastLoginTime.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_localization.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_mamEnabled", "74727565");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_mamEnabled.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_newApps", "5B5D");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_newApps.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_settings1.13.0.17.storedInFile", true);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_showWelcomeGadget", "66616C7365");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_showWelcomeGadget.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_stamp", "313130325F31");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_stamp.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_userBornDate", "3230313430323132");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_userBornDate.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_userId", "64303234643635632D313064632D346264612D393962662D353263313965613137316538");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_userId.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_user_approval_interacted", "");
Linea borrada : user_pref("valueApps.ct3319214.mam_gk_user_approval_interacted.storedInFile", false);
Linea borrada : user_pref("valueApps.ct3319214.url_history0001", "73746172743A3A3A636C69636B68616E646C65723A3A3A313339323332343933343638362C2C2C73746172743A3A3A636C69636B68616E646C65723A3A3A31333932373531303135383437[...]
Linea borrada : user_pref("valueApps.ct3319214.url_history0001.storedInFile", true);
-\\ Google Chrome v33.0.1750.154
[ Archivo : C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Borrar : homepage
Borrar : search_url
Borrar : keyword
*************************
AdwCleaner[R0].txt - [45348 octets] - [19/03/2014 18:56:55]
AdwCleaner[R1].txt - [41366 octets] - [19/03/2014 19:00:20]
AdwCleaner[S0].txt - [3914 octets] - [19/03/2014 18:58:09]
AdwCleaner[S1].txt - [37583 octets] - [19/03/2014 19:01:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [37644 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Home Premium x64
Ran by Andreas on 19/03/2014 at 19:17:06,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\speedypc software
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2334838483-4133862729-1016828376-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\speedypc software
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updatewhilokii_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updatewhilokii_rasmancs
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{39201A40-FC19-4B3A-9C4F-667BB6A02AB1}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AC3FD9EA-0A53-4EB3-AF72-00BBE159B55A}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{39201A40-FC19-4B3A-9C4F-667BB6A02AB1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\speedypc software"
Successfully deleted: [Folder] "C:\Users\Andreas\AppData\Roaming\speedypc software"
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{052C4DEC-7EF3-4A16-83CF-0E9EC216F884}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{0E63275A-85A4-48F4-ADD1-90F194C3E82A}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{659FCAE3-6961-4B6D-8088-38672D981688}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{6720CF05-29CE-4B46-A3F6-D35FAE6BF1D8}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{74F2E0A6-7A59-49B7-BA2D-24AD993FEEB7}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{9BE9ABE0-808F-4FA3-ADB8-56B72B6F5D3A}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{B0E5DB39-493C-4D5D-A769-0E69C9736C54}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{B4C8C286-161B-4BBB-9124-154CA645DE53}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{DE1BC479-6C90-4D9A-8BF3-34E3AB9D1993}
Successfully deleted: [Empty Folder] C:\Users\Andreas\appdata\local\{E71EBFB6-A6C2-49EC-ABD3-28544D4EF3E6}
~~~ FireFox
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\49ffxtbr@utilitychest_49.com
Emptied folder: C:\Users\Andreas\AppData\Roaming\mozilla\firefox\profiles\st2jilhu.default\minidumps [168 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19/03/2014 at 19:32:44,19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Andreas (administrator) on ANDREAS-HP on 19-03-2014 19:45:38
Running from C:\Users\Andreas\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Spanish Modern Sort
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
() C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-10] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2010-12-17] (IDT, Inc.)
HKLM\...\Run: [SetDefault] - C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [42808 2011-06-27] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-07-05] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HPQuickWebProxy] - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2011-07-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\qttask.exe [155648 2012-05-23] (Apple Computer, Inc.)
HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [103992 2011-09-13] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [UIExec] - C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe [156448 2012-05-04] ()
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-11] (AVAST Software)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2334838483-4133862729-1016828376-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
Startup: C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Supervisar alertas de tinta - HP Officejet 4620 series.lnk
ShortcutTarget: Supervisar alertas de tinta - HP Officejet 4620 series.lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM - {39201A40-FC19-4B3A-9C4F-667BB6A02AB1} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {52db1893-8a90-4192-aede-08e00b8f8473} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=105&systemid=473&v=a11465-148&apn_uid=2331992103804423&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/1185-111090-7840-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/1185-111090-7840-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKCU - 371749EC7A94488FB1ECF9797D04316C URL = hxxp://start.funmoods.com/results.php?f=4&a=promose&q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/1185-111090-7840-3/4?mpre=hxxp://shop.ebay.com/?_nkw={searchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: No Name - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - No File
BHO-x32: No Name - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Aplicación auxiliar de inicio de sesión de Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {2DAB6EF1-66C3-427C-87CD-8DC448C47EAE} https://www5.aeat.es/es13/h/tgvicab.cab
DPF: HKLM-x32 {947B00D2-962D-4A35-9E48-98EE6A442B41} https://www1.agenciatributaria.gob.es/ADUA/internet/aded1503.cab
DPF: HKLM-x32 {B785FA3C-1DE9-4D20-8396-613C486FE95E} https://www1.agenciatributaria.gob.es/es13/h/cactivex.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default
FF SearchEngineOrder.1: Google
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @UtilityChest_49.com/Plugin - C:\Program Files (x86)\UtilityChest_49\bar\1.bin\NP49Stub.dll No File
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\drae.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-es.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-es.xml
FF Extension: United States English Spellchecker - C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\Extensions\en-US@dictionaries.addons.mozilla.org [2013-03-25]
FF Extension: HP Detect - C:\Users\Andreas\AppData\Roaming\Mozilla\Firefox\Profiles\st2jilhu.default\Extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} [2012-06-04]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-03]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-04]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-06-18]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-04]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchProvider: Amazon
CHR DefaultSearchURL: hxxp://www.google.com
CHR Extension: (Google Docs) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-11]
CHR Extension: (Google Drive) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-11]
CHR Extension: (YouTube) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-11]
CHR Extension: (Búsqueda de Google) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-11]
CHR Extension: (Skype Click to Call) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-02-25]
CHR Extension: (Google Wallet) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-11]
CHR Extension: (Gmail) - C:\Users\Andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-11]
CHR HKLM-x32\...\Chrome\Extension: [dljhohhmfjfhgfhpgkfefjoojfobodhn] - C:\Program Files (x86)\Whilokii\dljhohhmfjfhgfhpgkfefjoojfobodhn.crx [2014-02-11]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-02-11]
CHR HKLM-x32\...\Chrome\Extension: [iaimhpklononapfjngelgdokckfjekfc] - C:\Program Files (x86)\Whilokii\iaimhpklononapfjngelgdokckfjekfc.crx [2014-02-11]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-07-05] (Advanced Micro Devices, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-11] (AVAST Software)
R3 Blackberry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 UI Assistant Service; C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe [274208 2012-05-04] ()
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-02-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-02-11] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-11] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-11] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2014-01-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-02-11] ()
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61592 2013-12-17] (NetFilterSDK.com)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [78336 2013-01-03] (Research In Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-19 19:45 - 2014-03-19 19:45 - 00022734 _____ () C:\Users\Andreas\Downloads\FRST.txt
2014-03-19 19:41 - 2014-03-19 19:42 - 02157056 _____ (Farbar) C:\Users\Andreas\Downloads\FRST64.exe
2014-03-19 19:32 - 2014-03-19 19:32 - 00003543 _____ () C:\Users\Andreas\Desktop\JRT.txt
2014-03-19 19:17 - 2014-03-19 19:17 - 00000000 ____D () C:\Windows\ERUNT
2014-03-19 19:15 - 2014-03-19 19:15 - 01037734 _____ (Thisisu) C:\Users\Andreas\Downloads\JRT.exe
2014-03-19 19:06 - 2014-03-19 19:06 - 00037973 _____ () C:\Users\Andreas\Desktop\AdwCleaner[S1].txt
2014-03-19 18:55 - 2014-03-19 19:01 - 00000000 ____D () C:\AdwCleaner
2014-03-19 18:54 - 2014-03-19 18:54 - 01950720 _____ () C:\Users\Andreas\Downloads\adwcleaner.exe
2014-03-19 18:29 - 2014-03-19 18:32 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-19 18:29 - 2014-03-19 18:29 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\Malwarebytes
2014-03-19 18:29 - 2014-03-19 18:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-19 18:28 - 2014-03-19 18:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-19 18:28 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-19 18:26 - 2014-03-19 18:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andreas\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-19 18:17 - 2014-03-19 18:17 - 00000000 ____D () C:\Windows\SysWOW64\sda
2014-03-19 18:16 - 2014-03-19 18:16 - 09888360 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll
2014-03-19 18:16 - 2014-03-19 18:16 - 00338536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys
2014-03-19 18:13 - 2014-03-19 18:13 - 00001995 _____ () C:\Users\Public\Desktop\HP Photo Creations.lnk
2014-03-19 18:13 - 2014-03-19 18:13 - 00000000 ____D () C:\ProgramData\Visan
2014-03-19 18:13 - 2014-03-19 18:13 - 00000000 ____D () C:\ProgramData\HP Photo Creations
2014-03-19 18:13 - 2014-03-19 18:13 - 00000000 ____D () C:\Program Files (x86)\HP Photo Creations
2014-03-18 18:51 - 2014-03-18 18:51 - 00028667 _____ () C:\ComboFix.txt
2014-03-18 18:24 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-03-18 18:24 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-03-18 18:24 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-03-18 18:24 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-03-18 18:24 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-03-18 18:24 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-03-18 18:24 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-03-18 18:24 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-03-18 18:23 - 2014-03-18 18:51 - 00000000 ____D () C:\Qoobox
2014-03-18 18:23 - 2014-03-18 18:49 - 00000000 ____D () C:\Windows\erdnt
2014-03-18 18:15 - 2014-03-18 18:15 - 05190594 ____R (Swearware) C:\Users\Andreas\Desktop\ComboFix.exe
2014-03-12 21:18 - 2014-03-12 21:18 - 00008197 _____ () C:\Users\Andreas\Desktop\gmer.7z
2014-03-12 21:11 - 2014-03-12 21:11 - 01110476 _____ () C:\Users\Andreas\Downloads\7z920.exe
2014-03-12 21:11 - 2014-03-12 21:11 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-03-12 20:41 - 2014-03-12 20:41 - 00419222 _____ () C:\Users\Andreas\Desktop\gmer.txt
2014-03-12 20:19 - 2014-03-12 20:19 - 00380416 _____ () C:\Users\Andreas\Desktop\Gmer-19357.exe
2014-03-12 19:26 - 2014-03-12 19:27 - 00052615 _____ () C:\Users\Andreas\Desktop\Addition.txt
2014-03-12 19:25 - 2014-03-19 19:45 - 00000000 ____D () C:\FRST
2014-03-12 19:25 - 2014-03-12 19:27 - 00072070 _____ () C:\Users\Andreas\Desktop\FRST.txt
2014-03-12 19:21 - 2014-03-12 19:21 - 02157056 _____ (Farbar) C:\Users\Andreas\Desktop\FRST64.exe
2014-03-12 19:16 - 2014-03-12 19:17 - 00000476 _____ () C:\Users\Andreas\Desktop\defogger_disable.log
2014-03-12 19:16 - 2014-03-12 19:16 - 00000000 _____ () C:\Users\Andreas\defogger_reenable
2014-03-12 19:14 - 2014-03-12 19:14 - 00050477 _____ () C:\Users\Andreas\Desktop\Defogger.exe
2014-03-11 20:57 - 2014-03-18 21:03 - 00003198 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForAndreas
2014-03-11 20:57 - 2014-03-18 21:03 - 00000340 _____ () C:\Windows\Tasks\HPCeeScheduleForAndreas.job
2014-03-11 20:41 - 2014-03-11 20:41 - 553205555 _____ () C:\Windows\MEMORY.DMP
2014-03-11 20:41 - 2014-03-11 20:41 - 00275064 _____ () C:\Windows\Minidump\031114-132039-01.dmp
2014-03-11 20:41 - 2014-03-11 20:41 - 00000000 ____D () C:\Windows\Minidump
2014-03-11 20:15 - 2014-03-11 20:15 - 05095824 _____ (SpeedyPC Software, Inc.) C:\Users\Andreas\Downloads\SpeedyPC Pro Installer.exe
2014-03-11 18:33 - 2014-03-11 18:33 - 00000000 _____ () C:\autoexec.bat
2014-03-11 18:32 - 2014-03-11 18:32 - 00002262 _____ () C:\Users\Andreas\Desktop\SpyHunter.lnk
2014-03-11 18:32 - 2014-03-11 18:32 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-03-11 18:32 - 2014-03-11 18:32 - 00000000 ____D () C:\sh4ldr
2014-03-11 18:32 - 2014-03-11 18:32 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-03-11 18:31 - 2014-03-12 18:20 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-03-11 18:27 - 2014-03-11 18:27 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Andreas\Downloads\SpyHunter-Installer.exe
2014-03-11 18:24 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-11 18:24 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-11 18:24 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-11 18:24 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-11 18:24 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-11 18:24 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-11 18:24 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-11 18:24 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-11 18:24 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-11 18:24 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-11 18:24 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-11 18:24 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-11 18:24 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-11 18:24 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-11 18:24 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-11 18:24 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-11 18:24 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-11 18:24 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-11 18:24 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-11 18:24 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-11 18:24 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-11 18:24 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-11 18:24 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-11 18:24 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-11 18:24 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-11 18:24 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-11 18:24 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-11 18:24 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-11 18:24 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-11 18:24 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-11 18:24 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-11 18:24 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-11 18:24 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-11 18:24 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-11 18:24 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-11 18:24 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-11 18:24 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-11 18:24 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-11 18:24 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-11 18:24 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-11 18:24 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-11 18:24 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-11 18:24 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-11 18:24 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-11 18:22 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-11 18:22 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-11 18:22 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-11 18:22 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-10 23:05 - 2014-03-10 23:05 - 00001205 _____ () C:\Users\Andreas\Downloads\FixNCR.reg
2014-03-10 21:00 - 2014-03-10 21:00 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-10 21:00 - 2014-03-10 21:00 - 00000000 ____D () C:\Users\Andreas\AppData\Local\Skype
2014-03-10 19:15 - 2014-03-12 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-27 21:57 - 2014-03-19 18:48 - 11639954 _____ () C:\Windows\system32\SavingsBullFilterService.log
2014-02-27 21:57 - 2014-02-27 21:57 - 00000000 _____ () C:\Windows\SysWOW64\Service.log
2014-02-27 21:57 - 2014-02-27 21:57 - 00000000 _____ () C:\Windows\system32\Service.log
2014-02-24 19:26 - 2014-02-24 19:26 - 00002221 _____ () C:\Users\Andreas\Desktop\HP Support Assistant.lnk
2014-02-24 19:21 - 2014-02-24 19:21 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-02-19 20:30 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-02-19 20:30 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-02-19 20:30 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-02-19 20:30 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-02-19 20:29 - 2014-02-19 20:30 - 00005173 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-02-19 20:19 - 2014-02-19 20:19 - 00000000 ____D () C:\extensions
2014-02-17 22:17 - 2014-02-17 22:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-17 22:01 - 2014-02-17 22:01 - 06790649 _____ () C:\Users\Andreas\Downloads\wordpress-3.8.1-es_ES(1).zip
2014-02-17 21:48 - 2014-02-17 21:59 - 00000022 _____ () C:\Users\Andreas\Downloads\wordpress-3.8.1-es_ES.zip
2014-02-17 21:28 - 2014-02-17 21:33 - 00000000 ____D () C:\Program Files (x86)\Amazon
2014-02-17 21:27 - 2014-02-17 21:32 - 00000000 ____D () C:\Program Files (x86)\Systweak Support Dock
2014-02-17 21:27 - 2014-02-17 21:32 - 00000000 ____D () C:\Program Files (x86)\PC Cleaner
2014-02-17 21:27 - 2014-02-17 21:32 - 00000000 ____D () C:\Program Files (x86)\Advanced Disk Recovery
==================== One Month Modified Files and Folders =======
2014-03-19 19:45 - 2014-03-19 19:45 - 00022734 _____ () C:\Users\Andreas\Downloads\FRST.txt
2014-03-19 19:45 - 2014-03-12 19:25 - 00000000 ____D () C:\FRST
2014-03-19 19:42 - 2014-03-19 19:41 - 02157056 _____ (Farbar) C:\Users\Andreas\Downloads\FRST64.exe
2014-03-19 19:40 - 2012-09-12 14:04 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\Skype
2014-03-19 19:32 - 2014-03-19 19:32 - 00003543 _____ () C:\Users\Andreas\Desktop\JRT.txt
2014-03-19 19:31 - 2012-05-17 11:33 - 00000838 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-19 19:17 - 2014-03-19 19:17 - 00000000 ____D () C:\Windows\ERUNT
2014-03-19 19:15 - 2014-03-19 19:15 - 01037734 _____ (Thisisu) C:\Users\Andreas\Downloads\JRT.exe
2014-03-19 19:12 - 2009-07-14 05:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-19 19:12 - 2009-07-14 05:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-19 19:06 - 2014-03-19 19:06 - 00037973 _____ () C:\Users\Andreas\Desktop\AdwCleaner[S1].txt
2014-03-19 19:04 - 2014-02-11 20:46 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-19 19:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-19 19:04 - 2009-07-14 05:51 - 00115328 _____ () C:\Windows\setupact.log
2014-03-19 19:03 - 2014-02-11 20:46 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-19 19:03 - 2012-02-20 11:18 - 01611200 _____ () C:\Windows\WindowsUpdate.log
2014-03-19 19:01 - 2014-03-19 18:55 - 00000000 ____D () C:\AdwCleaner
2014-03-19 19:01 - 2012-05-15 18:39 - 00000977 _____ () C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-19 18:58 - 2014-02-11 20:48 - 00001288 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-19 18:58 - 2012-05-17 08:53 - 00001053 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-19 18:54 - 2014-03-19 18:54 - 01950720 _____ () C:\Users\Andreas\Downloads\adwcleaner.exe
2014-03-19 18:54 - 2012-05-15 18:39 - 00003994 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{81EDD4D1-C001-44A4-A67F-76F8783CE17C}
2014-03-19 18:49 - 2010-11-21 04:47 - 00804022 _____ () C:\Windows\PFRO.log
2014-03-19 18:48 - 2014-02-27 21:57 - 11639954 _____ () C:\Windows\system32\SavingsBullFilterService.log
2014-03-19 18:32 - 2014-03-19 18:29 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-19 18:32 - 2014-03-19 18:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-19 18:29 - 2014-03-19 18:29 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\Malwarebytes
2014-03-19 18:29 - 2014-03-19 18:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-19 18:26 - 2014-03-19 18:26 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Andreas\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-19 18:19 - 2011-07-21 06:53 - 00748422 _____ () C:\Windows\system32\perfh00A.dat
2014-03-19 18:19 - 2011-07-21 06:53 - 00159604 _____ () C:\Windows\system32\perfc00A.dat
2014-03-19 18:19 - 2009-07-14 06:13 - 01679834 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-19 18:18 - 2012-05-17 08:24 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-03-19 18:17 - 2014-03-19 18:17 - 00000000 ____D () C:\Windows\SysWOW64\sda
2014-03-19 18:17 - 2012-06-04 19:04 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\HpUpdate
2014-03-19 18:17 - 2011-07-20 21:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-19 18:16 - 2014-03-19 18:16 - 09888360 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll
2014-03-19 18:16 - 2014-03-19 18:16 - 00338536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys
2014-03-19 18:16 - 2012-02-20 11:28 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-03-19 18:16 - 2011-02-10 20:23 - 00000000 ____D () C:\SWSetup
2014-03-19 18:13 - 2014-03-19 18:13 - 00001995 _____ () C:\Users\Public\Desktop\HP Photo Creations.lnk
2014-03-19 18:13 - 2014-03-19 18:13 - 00000000 ____D () C:\ProgramData\Visan
2014-03-19 18:13 - 2014-03-19 18:13 - 00000000 ____D () C:\ProgramData\HP Photo Creations
2014-03-19 18:13 - 2014-03-19 18:13 - 00000000 ____D () C:\Program Files (x86)\HP Photo Creations
2014-03-19 18:13 - 2013-06-27 19:30 - 00002248 _____ () C:\Users\Public\Desktop\HP Officejet 4620 series.lnk
2014-03-18 21:25 - 2013-08-15 17:44 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 21:25 - 2012-06-04 11:12 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-18 21:03 - 2014-03-11 20:57 - 00003198 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForAndreas
2014-03-18 21:03 - 2014-03-11 20:57 - 00000340 _____ () C:\Windows\Tasks\HPCeeScheduleForAndreas.job
2014-03-18 19:03 - 2012-06-01 09:31 - 00000000 ____D () C:\Users\Andreas\AppData\Local\CrashDumps
2014-03-18 18:51 - 2014-03-18 18:51 - 00028667 _____ () C:\ComboFix.txt
2014-03-18 18:51 - 2014-03-18 18:23 - 00000000 ____D () C:\Qoobox
2014-03-18 18:51 - 2011-01-26 14:22 - 00000000 ____D () C:\Users\privat
2014-03-18 18:49 - 2014-03-18 18:23 - 00000000 ____D () C:\Windows\erdnt
2014-03-18 18:45 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-03-18 18:42 - 2009-07-14 03:34 - 73400320 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-03-18 18:42 - 2009-07-14 03:34 - 17563648 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-03-18 18:42 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-03-18 18:42 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-03-18 18:42 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-03-18 18:40 - 2012-05-15 18:38 - 00000000 ____D () C:\Users\Andreas
2014-03-18 18:15 - 2014-03-18 18:15 - 05190594 ____R (Swearware) C:\Users\Andreas\Desktop\ComboFix.exe
2014-03-18 18:08 - 2012-09-24 07:15 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-13 19:02 - 2011-01-26 14:20 - 00000000 ____D () C:\privat
2014-03-13 18:57 - 2013-09-28 18:57 - 00000174 _____ () C:\Users\Andreas\AppData\Roaming\WB.CFG
2014-03-13 18:19 - 2012-05-17 08:47 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-03-12 22:44 - 2012-05-17 08:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-12 21:18 - 2014-03-12 21:18 - 00008197 _____ () C:\Users\Andreas\Desktop\gmer.7z
2014-03-12 21:11 - 2014-03-12 21:11 - 01110476 _____ () C:\Users\Andreas\Downloads\7z920.exe
2014-03-12 21:11 - 2014-03-12 21:11 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-03-12 20:41 - 2014-03-12 20:41 - 00419222 _____ () C:\Users\Andreas\Desktop\gmer.txt
2014-03-12 20:19 - 2014-03-12 20:19 - 00380416 _____ () C:\Users\Andreas\Desktop\Gmer-19357.exe
2014-03-12 19:27 - 2014-03-12 19:26 - 00052615 _____ () C:\Users\Andreas\Desktop\Addition.txt
2014-03-12 19:27 - 2014-03-12 19:25 - 00072070 _____ () C:\Users\Andreas\Desktop\FRST.txt
2014-03-12 19:21 - 2014-03-12 19:21 - 02157056 _____ (Farbar) C:\Users\Andreas\Desktop\FRST64.exe
2014-03-12 19:17 - 2014-03-12 19:16 - 00000476 _____ () C:\Users\Andreas\Desktop\defogger_disable.log
2014-03-12 19:16 - 2014-03-12 19:16 - 00000000 _____ () C:\Users\Andreas\defogger_reenable
2014-03-12 19:14 - 2014-03-12 19:14 - 00050477 _____ () C:\Users\Andreas\Desktop\Defogger.exe
2014-03-12 18:20 - 2014-03-11 18:31 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-03-12 18:18 - 2014-03-10 19:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-12 07:30 - 2009-07-14 05:45 - 00295192 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-11 22:31 - 2012-05-17 11:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-11 22:31 - 2012-05-17 11:33 - 00003776 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-11 22:31 - 2011-07-20 21:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-11 21:57 - 2012-09-12 14:04 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-11 20:41 - 2014-03-11 20:41 - 553205555 _____ () C:\Windows\MEMORY.DMP
2014-03-11 20:41 - 2014-03-11 20:41 - 00275064 _____ () C:\Windows\Minidump\031114-132039-01.dmp
2014-03-11 20:41 - 2014-03-11 20:41 - 00000000 ____D () C:\Windows\Minidump
2014-03-11 20:15 - 2014-03-11 20:15 - 05095824 _____ (SpeedyPC Software, Inc.) C:\Users\Andreas\Downloads\SpeedyPC Pro Installer.exe
2014-03-11 18:33 - 2014-03-11 18:33 - 00000000 _____ () C:\autoexec.bat
2014-03-11 18:32 - 2014-03-11 18:32 - 00002262 _____ () C:\Users\Andreas\Desktop\SpyHunter.lnk
2014-03-11 18:32 - 2014-03-11 18:32 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-03-11 18:32 - 2014-03-11 18:32 - 00000000 ____D () C:\sh4ldr
2014-03-11 18:32 - 2014-03-11 18:32 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-03-11 18:27 - 2014-03-11 18:27 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Andreas\Downloads\SpyHunter-Installer.exe
2014-03-10 23:05 - 2014-03-10 23:05 - 00001205 _____ () C:\Users\Andreas\Downloads\FixNCR.reg
2014-03-10 21:00 - 2014-03-10 21:00 - 00002697 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-10 21:00 - 2014-03-10 21:00 - 00000000 ____D () C:\Users\Andreas\AppData\Local\Skype
2014-03-10 21:00 - 2012-09-12 14:04 - 00000000 ____D () C:\ProgramData\Skype
2014-03-10 19:20 - 2012-05-23 17:26 - 00000000 ____D () C:\Users\Andreas\AppData\Roaming\SoftGrid Client
2014-03-10 18:48 - 2012-08-01 17:22 - 00002019 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-03-05 22:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-01 07:05 - 2014-03-11 18:24 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 06:17 - 2014-03-11 18:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 06:16 - 2014-03-11 18:24 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 05:58 - 2014-03-11 18:24 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 05:52 - 2014-03-11 18:24 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 05:51 - 2014-03-11 18:24 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 05:42 - 2014-03-11 18:24 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 05:40 - 2014-03-11 18:24 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 05:37 - 2014-03-11 18:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 05:33 - 2014-03-11 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 05:33 - 2014-03-11 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 05:32 - 2014-03-11 18:24 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 05:30 - 2014-03-11 18:24 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-01 05:23 - 2014-03-11 18:24 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 05:17 - 2014-03-11 18:24 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 05:11 - 2014-03-11 18:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-01 05:02 - 2014-03-11 18:24 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:54 - 2014-03-11 18:24 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:52 - 2014-03-11 18:24 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-01 04:51 - 2014-03-11 18:24 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-11 18:24 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-01 04:43 - 2014-03-11 18:24 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-01 04:43 - 2014-03-11 18:24 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-01 04:42 - 2014-03-11 18:24 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:40 - 2014-03-11 18:24 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-01 04:38 - 2014-03-11 18:24 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-01 04:37 - 2014-03-11 18:24 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-01 04:35 - 2014-03-11 18:24 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 04:18 - 2014-03-11 18:24 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 04:16 - 2014-03-11 18:24 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-01 04:14 - 2014-03-11 18:24 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-01 04:10 - 2014-03-11 18:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 04:03 - 2014-03-11 18:24 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-01 04:00 - 2014-03-11 18:24 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-01 03:57 - 2014-03-11 18:24 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-01 03:38 - 2014-03-11 18:24 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:32 - 2014-03-11 18:24 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-01 03:27 - 2014-03-11 18:24 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-01 03:25 - 2014-03-11 18:24 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 03:25 - 2014-03-11 18:24 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-27 21:57 - 2014-02-27 21:57 - 00000000 _____ () C:\Windows\SysWOW64\Service.log
2014-02-27 21:57 - 2014-02-27 21:57 - 00000000 _____ () C:\Windows\system32\Service.log
2014-02-27 20:13 - 2012-02-20 11:25 - 01654420 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-24 22:03 - 2009-07-14 06:08 - 00032520 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-24 19:26 - 2014-02-24 19:26 - 00002221 _____ () C:\Users\Andreas\Desktop\HP Support Assistant.lnk
2014-02-24 19:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-02-24 19:22 - 2011-07-20 21:32 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-02-24 19:21 - 2014-02-24 19:21 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-02-24 19:19 - 2011-07-20 21:44 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-02-19 20:30 - 2014-02-19 20:29 - 00005173 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-02-19 20:30 - 2012-10-02 07:26 - 00000000 ____D () C:\Program Files (x86)\Java
2014-02-19 20:19 - 2014-02-19 20:19 - 00000000 ____D () C:\extensions
2014-02-17 22:17 - 2014-02-17 22:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-17 22:01 - 2014-02-17 22:01 - 06790649 _____ () C:\Users\Andreas\Downloads\wordpress-3.8.1-es_ES(1).zip
2014-02-17 21:59 - 2014-02-17 21:48 - 00000022 _____ () C:\Users\Andreas\Downloads\wordpress-3.8.1-es_ES.zip
2014-02-17 21:35 - 2012-05-15 18:39 - 00000000 ___RD () C:\Users\Andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-17 21:33 - 2014-02-17 21:28 - 00000000 ____D () C:\Program Files (x86)\Amazon
2014-02-17 21:32 - 2014-02-17 21:27 - 00000000 ____D () C:\Program Files (x86)\Systweak Support Dock
2014-02-17 21:32 - 2014-02-17 21:27 - 00000000 ____D () C:\Program Files (x86)\PC Cleaner
2014-02-17 21:32 - 2014-02-17 21:27 - 00000000 ____D () C:\Program Files (x86)\Advanced Disk Recovery
Some content of TEMP:
====================
C:\Users\Andreas\AppData\Local\Temp\Extract.exe
C:\Users\Andreas\AppData\Local\Temp\Quarantine.exe
C:\Users\Andreas\AppData\Local\Temp\SP55085.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-02 10:57
==================== End Of Log ============================ --- --- --- |