Hallo Matthias,
hier noch die mbam und Zoek Logdateien.
Gruß
jflack Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 06.04.2014
Suchlauf-Zeit: 18:31:00
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.06.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: Asus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 231431
Verstrichene Zeit: 18 Min, 50 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 16
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, In Quarantäne, [b14f639d17e95ea29215142e56ac768a],
PUP.Optional.MegaBrowse.A, HKLM\SOFTWARE\Mega Browse, In Quarantäne, [15ebf50bb94744bc6b21d78e82808977],
PUP.Optional.MegaBrowse.A, HKU\S-1-5-21-3974147251-177897506-2495822883-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Mega Browse, In Quarantäne, [be4220e0a15f35cbdbb02e37d32fc739],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0, In Quarantäne, [56aa31cf6898a55b40501548976bc739],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
Dateien: 18
PUP.Optional.Crimsolite.A, C:\Users\Asus\AppData\Local\Temp\is1590112554\2484379_stp\setup.exe, In Quarantäne, [7c84817f9f61db25485ce11d20e302fe],
PUP.Optional.MySearchDial.A, C:\Users\Asus\AppData\Local\Temp\is2690362\mysearchdial.dll, In Quarantäne, [17e90df34ab603fd8b0fd07b52afe020],
PUP.Optional.MySearchDial.A, C:\Users\Asus\AppData\Local\Temp\is3458994\mysearchdial.dll, In Quarantäne, [946cfc04de22f010fe9c83c80001ed13],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0.localstorage, In Quarantäne, [49b7679958a822de9067f26c59a9ff01],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0.localstorage-journal, In Quarantäne, [a45cf70933cd629ed324025cab570cf4],
PUP.Optional.MySearchDial.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi, In Quarantäne, [55ab9b658977ab5589cdafb2cf336997],
PUP.Optional.MegaBrowse.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\nkzlfv9v.default\extensions\{29b136c9-938d-4d3d-8df8-d649d9b74d02}.xpi, In Quarantäne, [da2613ed4cb47c8488a0cf95669c8b75],
PUP.Optional.MegaBrowse.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox\extensions\{29b136c9-938d-4d3d-8df8-d649d9b74d02}.xpi, In Quarantäne, [b24ede2225db27d98b9dea7ad32f0bf5],
PUP.Optional.MegaBrowse.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870\extensions\{29b136c9-938d-4d3d-8df8-d649d9b74d02}.xpi, In Quarantäne, [6a96b050a7592fd180a8cd9747bb38c8],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0\13, In Quarantäne, [56aa31cf6898a55b40501548976bc739],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\000785.ldb, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\000791.log, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\CURRENT, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\LOCK, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\LOG, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\LOG.old, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\iefogiieekeeeeaiklglonbockmhmkgd\MANIFEST-000789, In Quarantäne, [cf31d0305ca4af51b5dfc19c41c1fa06],
PUP.Optional.MySearchDial.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_14_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtBtCyDzzyE0EtCtAyD0ByCtB0AtN0D0Tzu0SzztByDtN1L2XzutBtFtCzztFzztFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0DzytB0AtAyEyDtGyE0CyBtCtGyBtBzzzztG0ByD0B0FtGyCyB0D0C0CtD0F0AyB0DyD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0F0FtA0EyCzytBtG0ByCyByDtG0FtCyDtCtG0EyByDyCtGyC0ByE0Dzy0F0FyB0CyDzzyB2Q&cr=579548144&ir=",), Ersetzt,[b14f966a07f97090c948e55ced1707f9]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Asus on 06.04.2014 at 18:50:21,93.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Asus\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
06.04.2014 18:52:14 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\nkzlfv9v.default\prefs.js:
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\nkzlfv9v.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox\prefs.js:
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
user_pref("browser.search.defaultengine", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870\prefs.js:
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://suche.web.de/starthp?src=tb_newtab_ff,exp_nafs_treatment");
user_pref("browser.search.defaultengine", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Asus\AppData\Roaming\TomTom\HOME\Profiles\1ryhukpi.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Asus\AppData\Roaming\TomTom\HOME\Profiles\1ryhukpi.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\nkzlfv9v.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1908_.backup
ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox
user.js not found
---- Lines mysearch removed from prefs.js ----
user_pref("extensions.irmysearch.aflt", "dsites_14_14_ch");
user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtBtBtCyDzzyE0EtCtAyD0ByCtB0AtN0D0Tzu0SzztByDtN1L2XzutBtFtCzztFzytFtDtN1L1CzutCyEtDtAtDyD1V1
user_pref("extensions.irmysearch.cr", "2076409355");
user_pref("extensions.irmysearch.instlRef", "140305_d");
---- Lines mysearch modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\
---- FireFox user.js and prefs.js backups ----
prefs__1908_.backup
ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870
user.js not found
---- Lines mysearch removed from prefs.js ----
user_pref("extensions.irmysearch.aflt", "dsites_14_14_ch");
user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtBtBtCyDzzyE0EtCtAyD0ByCtB0AtN0D0Tzu0SzztByDtN1L2XzutBtFtCzztFzytFtDtN1L1CzutCyEtDtAtDyD1V1
user_pref("extensions.irmysearch.cr", "2076409355");
user_pref("extensions.irmysearch.instlRef", "140305_d");
---- FireFox user.js and prefs.js backups ----
prefs__1908_.backup
ProfilePath: C:\Users\Asus\AppData\Roaming\TomTom\HOME\Profiles\1ryhukpi.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1908_.backup
==== Deleting Files \ Folders ======================
C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox\extensions\ffxtlbr@mysearchdial.com not found
C:\Program Files\Mega Browse deleted
C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\nkzlfv9v.default\extensions\staged deleted
C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox\jetpack deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF" [18.11.2013 12:25]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\nkzlfv9v.default
- Undetermined - %ProfilePath%\extensions\toolbar@web.de
- Undetermined - %ProfilePath%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
- Undetermined - %ProfilePath%\extensions\{95f24680-9e31-11da-a746-0800200c9a66}
- Undetermined - %ProfilePath%\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}
- Undetermined - %ProfilePath%\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox
- Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF
- Clickamp;Clean - %ProfilePath%\extensions\clickclean@hotcleaner.com
- GoogleSharing - %ProfilePath%\extensions\googlesharing@extension.thoughtcrime.org
- Cryptocat - %ProfilePath%\extensions\cryptocat@crypto.cat.xpi
- Lightbeam - %ProfilePath%\extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi
- WEB.DE MailCheck - %ProfilePath%\extensions\toolbar@web.de.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870
- Internet Download Manager Squared - %ProfilePath%\extensions\idmsq@idmsq.com
- WEB.DE MailCheck - %ProfilePath%\extensions\toolbar@web.de.xpi
ProfilePath: C:\Users\Asus\AppData\Roaming\TomTom\HOME\Profiles\1ryhukpi.default
- Map status indicator - C:\Program Files\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com
- TomTom HOME default theme - C:\Program Files\TomTom HOME 2\xul\extensions\baseTheme@tomtom.com
AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\v6typ25n.tarnfox
E83B541C71965CFA1DEFF846CD6E9ECD - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll - Google Update
95812430959AE88CDD0301AB3A71913B - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13
3220B1254AEF7A191187EC03F51B3D61 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
B2576571746839180833E048AC2CCA5C - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
Profilepath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870
E83B541C71965CFA1DEFF846CD6E9ECD - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll - Google Update
95812430959AE88CDD0301AB3A71913B - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13
3220B1254AEF7A191187EC03F51B3D61 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
B2576571746839180833E048AC2CCA5C - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[02.03.2012 11:53]
mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files\Norton 360\Engine\21.2.0.38\Exts\Chrome.crx[11.03.2014 22:44]
Skype Click to Call - Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Norton Identity Protection - Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{1F030088-8BE3-4AA3-9D03-26D4DB23DA80} Amazon Url="hxxp://go.web.de/br/ie8_search_amazon/?keywords={searchTerms}"
{2BA724D2-45DC-4B4D-8064-5D20686A1339} Englische Ergebnisse Url="hxxp://go.mail.com/br/ie8_search_web/?su={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{968E5101-323F-437E-B302-C9A3854F21B4} WEB.DE Suche Url="hxxp://go.web.de/br/ie8_search_web/?su={searchTerms}"
{C1302AE2-8B4F-4F0D-BEAC-E121028FCC02} eBay Url="hxxp://go.web.de/br/ie8_search_ebay/?q={searchTerms}"
==== Reset Google Chrome ======================
C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\Users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Asus\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\Asus\AppData\Local\Mozilla\Firefox\Profiles\v6typ25n.tarnfox\Cache emptied successfully
C:\Users\Asus\AppData\Local\Mozilla\Firefox\Profiles\yalum6vb.default-1383907381870\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=589 folders=87 89522971 bytes)
==== Empty Temp Folders ======================
C:\Users\Asus\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Asus\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on 06.04.2014 at 19:16:20,83 ====================== |