Tobias2000 | 17.04.2014 14:04 | Danke, dass du immer so schnell antwortest! Tut mir Leid, dass es jetzt so lange gedauert hat, aber dafür gab es dieses Mal keine Probleme:) Hier sind die vier Logs von MBAM, AdwCleaner, JRT und FRST: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.04.2014
Suchlauf-Zeit: 21:29:03
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.15.10
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Tobias Pusinelli
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 265467
Verstrichene Zeit: 24 Min, 58 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 10
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [7d83fa0633cda0607254f356927054ac],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3483559876-173142988-3089211926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\mysearchdial.com, In Quarantäne, [05fb0bf532ce1ce45837d3bff80beb15],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3483559876-173142988-3089211926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [d42c17e9e31d43bd2e21ff7c06fc7b85],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3483559876-173142988-3089211926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [d52b36ca837d55ab7f0b0a87887be61a],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3483559876-173142988-3089211926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0H1L1J1L1S1R1N, In Quarantäne, [d52b36ca837d55ab7f0b0a87887be61a]
Registrierungsdaten: 3
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=),Ersetzt,[ef1105fb768ae41c1fc4dd465fa5b749]
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=),Ersetzt,[a95797697789619fa63db073e024817f]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3483559876-173142988-3089211926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=),Ersetzt,[12ee6a964eb24bb509d9061d2ada946c]
Ordner: 0
(No malicious items detected)
Dateien: 66
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi, In Quarantäne, [f60a9c64ab55e41c3828e386649eeb15],
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\searchplugins\Mysearchdial.xml, In Quarantäne, [42be738dab55ef11ddbf0b650bf7c63a],
PUP.Optional.FunMoods.A, C:\Users\Tobias Pusinelli\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, In Quarantäne, [b8483fc1946c46ba9b23bae0e41f8878],
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=",), Ersetzt,[26daa25eac54748c0cd93e11df25d22e]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=", "hxxp://de.msn.com/?pc=UP97&ocid=UP97DHP", "hxxp://www.google.com/ig/redirectdomain?brand=TEUA&bmod=TEUA" ],), Ersetzt,[c33dce3241bf1be52ee97bd5d03432ce]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.AL", 2);), Ersetzt,[7a868f71926ebb45bb8da7a830d4d828]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.aflt", "dsites_14_13_ff");), Ersetzt,[3dc3f40cc937f40c52f6b699669e11ef]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");), Ersetzt,[db253bc5b848c33d1e2a301fe0246c94]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q");), Ersetzt,[6898ea16b64aef111d2b1f307c885aa6]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cntry", "DE");), Ersetzt,[4db30df38779e21e3513aaa502024fb1]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cr", "945200470");), Ersetzt,[46bac33d39c75ea20f393f104abac13f]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltLng", "");), Ersetzt,[c13fb54bb64aa65abd8bc887f4106799]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltSrch", true);), Ersetzt,[a957649cd42cf7093216e06f33d104fc]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dnsErr", true);), Ersetzt,[ed134eb2f7095aa6fe4abe91ae5616ea]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,1828564131,3396905322,2787570089,1850357963,3855095921,1516386922,3836221436,2015489896,270173904,3729539987,424611005,965674394,609003582,2041931190,3874294282,2774755777,931959409,398575749,3999997753,1104451911,1233863968,4280856088,1554076246,1949401179,1770772786,3253391265,3778438159,1649478750,2848156272,2476712966,3103989719,475488147,1715867073,3594694113,3774606882,4036647035,1593922001,4110151693,2941033654,3206511613");), Ersetzt,[8e721fe18080ff01df69d07f2ed65ca4]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.excTlbr", false);), Ersetzt,[51af59a79e6221df3b0d86c90ff5ee12]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hdrMd5", "397A4CFBD60A6DF2E76F1C7B9B3FD14C");), Ersetzt,[4cb4e7196e92d828054386c936ce6799]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpg", true);), Ersetzt,[b14fac54f40c42be96b227287f85d52b]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=");), Ersetzt,[3bc5e51bd030e818a7a180cf45bfa15f]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.id", "E840F2DF4D77D713");), Ersetzt,[847ca35d12ee808080c84a05f212ef11]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlDay", "16157");), Ersetzt,[b24ed22e3ec2c040ee5af857ad57639d]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlRef", "140305_b");), Ersetzt,[e917f30ded13a7590b3d0d42887cd52b]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=");), Ersetzt,[39c747b99f61b14fb2969fb045bfdc24]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.020:15:20");), Ersetzt,[8b7541bfae523bc5de6ab699da2a8080]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=");), Ersetzt,[728e52ae887858a8ed5b54fb3ec6e51b]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"94\",\"lastVrsn\":\"94\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");), Ersetzt,[639d22de5ca408f87ace143b996b46ba]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prdct", "mysearchdial");), Ersetzt,[08f88c7403fd8d73113789c6f80cce32]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");), Ersetzt,[5fa1e81839c7c43ca7a12f2004002ed2]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.sg", "none");), Ersetzt,[6a9607f915eb728e2721fc53be46a35d]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");), Ersetzt,[748c36ca3bc5f907381080cf41c30000]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrId", "base");), Ersetzt,[8d73e61a659b5ea2c187311e57ad06fa]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=&q=");), Ersetzt,[e51b47b931cfb64abf89dd72956f2ad6]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");), Ersetzt,[50b01be5f10f05fb093fe9669173f60a]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");), Ersetzt,[fd03f01018e86d93e36564eba95b0ef2]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.newTab", false);), Ersetzt,[f40ca55b7f8101fff85082cd6d97d62a]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.smplGrp", "none");), Ersetzt,[ac54f70947b90ff173d5e96646be5ca4]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.020:15:20");), Ersetzt,[837d4bb55ea2be421c2c014eca3a11ef]
PUP.Optional.MySearch.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.aflt", "dsites_14_13_ff");), Ersetzt,[8d7315ebe02013edda6690bf8f75de22]
PUP.Optional.MySearch.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.instlRef", "140305_b");), Ersetzt,[5aa69769659bb64ad36dec6337cd6d93]
PUP.Optional.MySearch.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.cr", "945200470");), Ersetzt,[d62aed1341bfec14d46c61ee06fe59a7]
PUP.Optional.MySearch.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q");), Ersetzt,[ed13758bcd33b44c004056f9cf35e41c]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpg", true);), Ersetzt,[1ee24fb1a0601ae657f20e415ca8fa06]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=");), Ersetzt,[c63a8878d927778983c6c78824e0e21e]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltSrch", true);), Ersetzt,[8d734ab6ff018e72de6b16398c78ca36]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");), Ersetzt,[2ed2f60a9a6667992d1cf25d0cf8d42c]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dnsErr", true);), Ersetzt,[4cb48a7616ea6799da6f82cd4fb549b7]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.newTab", false);), Ersetzt,[fb05c8386f910bf561e890bfc3416e92]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=");), Ersetzt,[40c0cc34b749669af75257f8d133857b]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=&q=");), Ersetzt,[53ad03fdb848e61aea5ffe51897bad53]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.id", "E840F2DF4D77D713");), Ersetzt,[956b738d3ac6c838de6b3e11fe064bb5]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlDay", "16157");), Ersetzt,[bb4530d06a9659a7173258f753b118e8]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");), Ersetzt,[3ac65da35ca4c63a99b0db7454b0ba46]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");), Ersetzt,[936dfc0433cdba46ea5f75da11f3ec14]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.020:15:20");), Ersetzt,[39c70af6c8384fb1d0791c33758fc739]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");), Ersetzt,[4cb4ad5319e7e21e34150f40689c03fd]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prdct", "mysearchdial");), Ersetzt,[907058a8da269e62e26727280bf9ca36]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.aflt", "dsites_14_13_ff");), Ersetzt,[48b87f81af5177893a0f87c8eb19fd03]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.smplGrp", "none");), Ersetzt,[59a7fe0253adec14ac9d8ec117edcc34]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrId", "base");), Ersetzt,[e51b926eef11c838034637181ce85ba5]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlRef", "140305_b");), Ersetzt,[6c947a86e41c6b9582c7163930d44fb1]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltLng", "");), Ersetzt,[bc44b14fdb25f010e0694807a36137c9]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");), Ersetzt,[1fe1768a2cd4af5138117ad56e96cd33]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.excTlbr", false);), Ersetzt,[5ea2f010fc0427d93b0e72dd50b41ce4]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cr", "945200470");), Ersetzt,[30d03ec21de356aab8917fd0669e05fb]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q");), Ersetzt,[f20e7090649cd0305fea044be61ee21e]
PUP.Optional.MySearchDial.A, C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.AL", 2);), Ersetzt,[3cc45aa6ee128e72f356d67933d1659b]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 15/04/2014 um 21:47:51
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Tobias Pusinelli - TOBI
# Gestartet von : C:\Users\Tobias Pusinelli\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it!
Ordner Gelöscht : C:\Program Files (x86)\Mobogenie
Ordner Gelöscht : C:\Program Files (x86)\openit
Ordner Gelöscht : C:\Program Files (x86)\PC Speed Maximizer
Ordner Gelöscht : C:\Users\Tobias Pusinelli\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Tobias Pusinelli\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\Tobias Pusinelli\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Tobias Pusinelli\Documents\PC Speed Maximizer
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Datei Gelöscht : C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\searchplugins\bingp.xml
Datei Gelöscht : C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\openit open it!
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.order.1", "Mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.AL", 2);
Zeile gelöscht : user_pref("extensions.mysearchdial.aflt", "dsites_14_13_ff");
Zeile gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
Zeile gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0Bz[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.cntry", "DE");
Zeile gelöscht : user_pref("extensions.mysearchdial.cr", "945200470");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
Zeile gelöscht : user_pref("extensions.mysearchdial.hdrMd5", "397A4CFBD60A6DF2E76F1C7B9B3FD14C");
Zeile gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
Zeile gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutC[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.id", "E840F2DF4D77D713");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlDay", "16157");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "140305_b");
Zeile gelöscht : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyE[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.020:15:20");
Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1Czu[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"94\",\"lastVrsn\":\"94\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.sg", "none");
Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1C[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.020:15:20");
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Tobias Pusinelli\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [6428 octets] - [15/04/2014 21:47:09]
AdwCleaner[S0].txt - [6185 octets] - [15/04/2014 21:47:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6245 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Tobias Pusinelli on 15.04.2014 at 21:55:12,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2D1A2C13-2E8E-4782-8C41-1CB11C07EB55}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Tobias Pusinelli\appdata\local\{AF1C6AB3-65CC-4F23-8022-4C605CF85494}
Successfully deleted: [Empty Folder] C:\Users\Tobias Pusinelli\appdata\local\{CFF4B9FD-1EA2-4378-AB06-6F96C5371CBC}
~~~ FireFox
Emptied folder: C:\Users\Tobias Pusinelli\AppData\Roaming\mozilla\firefox\profiles\jeqqehcy.default\minidumps [82 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.04.2014 at 22:02:03,95
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by Tobias Pusinelli (administrator) on TOBI on 16-04-2014 11:18:16
Running from C:\Users\Tobias Pusinelli\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
() C:\Windows\System32\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(TOSHIBA Corporation) C:\windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
() C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-15] (Realtek Semiconductor)
HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2165120 2012-03-22] (SRS Labs, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-19] (Synaptics Incorporated)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [590256 2011-09-22] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2011-12-13] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1548208 2011-11-24] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2011-11-25] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\...\Run: [Toshiba Registration] => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2012-02-17] (Toshiba Europe GmbH)
HKLM\...\Run: [Trend Micro Titanium] => C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [1111568 2011-10-08] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [197152 2011-02-10] (Trend Micro Inc.)
HKLM-x32\...\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1492264 2011-11-18] (Nero AG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-01-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ITSecMng] => C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [80840 2011-04-01] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-05] (Intel Corporation)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-3483559876-173142988-3089211926-1000\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-3483559876-173142988-3089211926-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3483559876-173142988-3089211926-1000\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO)
HKU\S-1-5-21-3483559876-173142988-3089211926-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3483559876-173142988-3089211926-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
GroupPolicyUsers\S-1-5-21-3483559876-173142988-3089211926-1004\User: Group Policy restriction detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {2D1A2C13-2E8E-4782-8C41-1CB11C07EB55} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2D1A2C13-2E8E-4782-8C41-1CB11C07EB55} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites_14_13_ff&cd=2XzuyEtN2Y1L1Qzu0EzzyEtD0FtB0D0FyE0DyByB0DyBtCtAtN0D0Tzu0SzztCzztN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAzztByE0DyEtCzztG0F0D0BzytGyEyDtA0BtGyBtD0EtCtGtB0EyEyDyE0DyDyCzz0B0EyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyC0CtAtCyCyBzztCtG0CyE0C0BtGzyyCzy0AtGtAyByB0BtGyC0EtByBzztD0A0FtCyDyEtD2Q&cr=945200470&ir=
SearchScopes: HKLM-x32 - {2D1A2C13-2E8E-4782-8C41-1CB11C07EB55} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TEUA;
SearchScopes: HKCU - 19F8394510814529823EEC4A183FCDF2 URL =
BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\TmIEPlg32.dll (Trend Micro Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe64.dll (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\TmIEPlg32.dll (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Tobias Pusinelli\AppData\Roaming\Mozilla\Firefox\Profiles\jeqqehcy.default
FF SearchEngineOrder.3: Bing
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\firefoxextension\
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1505\6.6.1088\firefoxextension\ []
Chrome:
=======
CHR DefaultSearchProvider: "name": "Mysearchdial"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U30) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Nero Kwik Media Helper) - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (McAfee Security Scan+) - C:\Users\Tobias Pusinelli\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-03-08]
CHR Extension: (Google Wallet) - C:\Users\Tobias Pusinelli\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
==================== Services (Whitelisted) =================
R2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-09] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-21] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-21] (Intel Corporation)
R2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202328 2012-12-07] (Kaspersky Lab ZAO)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
S2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2012-08-06] (Trend Micro Inc.)
R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2012-08-06] (Trend Micro Inc.)
R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2012-08-06] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2012-08-06] (Trend Micro Inc.)
S3 Tosrfcom; No ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-16 11:17 - 2014-04-16 11:17 - 00000000 ____D () C:\Users\Tobias Pusinelli\Desktop\FRST-OlderVersion
2014-04-15 22:02 - 2014-04-15 22:02 - 00001162 _____ () C:\Users\Tobias Pusinelli\Desktop\JRT.txt
2014-04-15 21:55 - 2014-04-15 21:55 - 00000000 ____D () C:\windows\ERUNT
2014-04-15 21:54 - 2014-04-15 21:54 - 01016261 _____ (Thisisu) C:\Users\Tobias Pusinelli\Desktop\JRT.exe
2014-04-15 21:49 - 2014-04-15 21:49 - 00006329 _____ () C:\Users\Tobias Pusinelli\Desktop\AdwCleaner[S0].txt
2014-04-15 21:46 - 2014-04-15 21:47 - 00000000 ____D () C:\AdwCleaner
2014-04-15 21:45 - 2014-04-15 21:45 - 01426178 _____ () C:\Users\Tobias Pusinelli\Desktop\adwcleaner.exe
2014-04-15 21:44 - 2014-04-15 21:44 - 00026890 _____ () C:\Users\Tobias Pusinelli\Desktop\mbam.txt
2014-04-15 21:01 - 2014-04-15 21:42 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-15 21:01 - 2014-04-15 21:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-15 21:01 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-11 20:36 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-11 20:36 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-11 20:36 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-11 20:36 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-11 20:36 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-10 16:05 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-10 16:05 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-10 16:05 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-10 16:05 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-10 16:04 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-10 16:04 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-10 16:04 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-10 16:04 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-10 16:04 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-10 16:04 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-10 16:04 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-10 16:04 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-10 16:04 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-10 16:04 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-10 16:04 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-10 16:04 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-07 20:59 - 2014-04-07 20:59 - 00027408 _____ () C:\ComboFix.txt
2014-04-07 20:48 - 2014-04-07 20:59 - 00000000 ____D () C:\Qoobox
2014-04-07 20:48 - 2014-04-07 20:58 - 00000000 ____D () C:\windows\erdnt
2014-04-07 20:48 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-04-07 20:48 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-04-07 20:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-04-07 20:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-04-07 20:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-04-07 20:48 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-04-07 20:48 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-04-07 20:48 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-04-07 20:46 - 2014-04-07 20:47 - 05195663 ____R (Swearware) C:\Users\Tobias Pusinelli\Desktop\ComboFix.exe
2014-04-05 22:28 - 2014-04-16 11:18 - 00021515 _____ () C:\Users\Tobias Pusinelli\Desktop\FRST.txt
2014-04-05 22:28 - 2014-04-05 22:30 - 00051766 _____ () C:\Users\Tobias Pusinelli\Desktop\FRST 2.txt
2014-03-31 20:29 - 2014-04-07 20:44 - 00001275 _____ () C:\Users\Tobias Pusinelli\Desktop\Revo Uninstaller.lnk
2014-03-31 20:29 - 2014-04-07 20:44 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-31 20:26 - 2014-03-31 20:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tobias Pusinelli\Desktop\revosetup95.exe
2014-03-29 20:49 - 2014-03-29 20:49 - 00002516 _____ () C:\Users\Tobias Pusinelli\Desktop\Gmer.txt
2014-03-29 20:08 - 2014-03-29 20:08 - 00380416 _____ () C:\Users\Tobias Pusinelli\Desktop\Gmer-19357.exe
2014-03-29 20:06 - 2014-03-29 20:53 - 00035525 _____ () C:\Users\Tobias Pusinelli\Desktop\Addition.txt
2014-03-29 20:05 - 2014-04-16 11:18 - 00000000 ____D () C:\FRST
2014-03-29 19:57 - 2014-04-16 11:17 - 02054144 _____ (Farbar) C:\Users\Tobias Pusinelli\Desktop\FRST64.exe
2014-03-29 19:57 - 2014-03-29 19:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 19:56 - 2014-03-29 19:57 - 00000476 _____ () C:\Users\Tobias Pusinelli\Desktop\defogger_disable.log
2014-03-29 19:55 - 2014-03-29 19:55 - 00000494 _____ () C:\Users\Tobias Pusinelli\Downloads\defogger_disable.log
2014-03-29 19:55 - 2014-03-29 19:55 - 00000000 _____ () C:\Users\Tobias Pusinelli\defogger_reenable
2014-03-29 19:53 - 2014-03-29 19:53 - 00050477 _____ () C:\Users\Tobias Pusinelli\Desktop\Defogger.exe
2014-03-28 23:50 - 2014-03-28 23:50 - 00233520 _____ () C:\windows\RegBootClean64.exe
2014-03-28 21:46 - 2014-03-29 00:08 - 00328492 _____ () C:\Users\Tobias Pusinelli\AppData\Local\census.cache
2014-03-28 21:46 - 2014-03-29 00:08 - 00116909 _____ () C:\Users\Tobias Pusinelli\AppData\Local\ars.cache
2014-03-28 21:27 - 2014-03-28 23:53 - 00000036 _____ () C:\Users\Tobias Pusinelli\AppData\Local\housecall.guid.cache
2014-03-28 21:25 - 2014-03-28 21:25 - 02405664 _____ (Trend Micro Inc.) C:\Users\Tobias Pusinelli\Downloads\HousecallLauncher64.exe
2014-03-28 21:16 - 2014-03-28 23:49 - 00000066 _____ () C:\Users\Tobias Pusinelli\AppData\Roaming\WB.CFG
2014-03-28 21:15 - 2014-03-28 21:15 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Local\cache
2014-03-28 21:15 - 2014-03-28 21:15 - 00000000 ____D () C:\Users\Tobias Pusinelli\.android
2014-03-28 21:15 - 2014-03-28 21:15 - 00000000 _____ () C:\Users\Tobias Pusinelli\daemonprocess.txt
2014-03-28 21:13 - 2014-03-28 21:15 - 02346186 _____ () C:\Users\Tobias Pusinelli\Downloads\TechnicLauncher(2).exe
2014-03-28 21:11 - 2014-03-28 21:11 - 00685648 _____ () C:\Users\Tobias Pusinelli\Downloads\ZipSetup.exe
2014-03-28 21:03 - 2014-03-28 21:04 - 02346186 _____ () C:\Users\Tobias Pusinelli\Downloads\TechnicLauncher(1).exe
2014-03-28 20:59 - 2014-04-15 14:31 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\TS3Client
2014-03-28 20:58 - 2014-03-28 20:58 - 00000978 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-03-28 20:58 - 2014-03-28 20:58 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-28 20:55 - 2014-03-28 20:58 - 29498592 _____ (TeamSpeak Systems GmbH) C:\Users\Tobias Pusinelli\Downloads\TeamSpeak3-Client-win64-3.0.14.exe
2014-03-28 20:30 - 2014-03-28 20:40 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\.technic
2014-03-28 20:30 - 2014-03-28 20:30 - 02346186 _____ () C:\Users\Tobias Pusinelli\Downloads\TechnicLauncher.exe
2014-03-25 20:57 - 2014-03-26 20:46 - 00000355 _____ () C:\Users\Tobias Pusinelli\Downloads\Serverregeln.txt
2014-03-23 20:41 - 2014-03-23 20:41 - 00001088 _____ () C:\Users\Tobias Pusinelli\Desktop\Kaspersky Security Scan.lnk
2014-03-23 20:41 - 2014-03-23 20:41 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
2014-03-23 20:40 - 2014-03-23 20:40 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-23 20:40 - 2014-03-23 20:40 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-03-23 20:35 - 2014-03-23 20:35 - 00185944 _____ (Лаборатория Касперского) C:\Users\Tobias Pusinelli\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5623.exe
2014-03-23 19:43 - 2014-03-23 19:43 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\Malwarebytes
2014-03-23 19:42 - 2014-04-15 21:01 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-23 19:42 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-23 19:39 - 2014-03-23 19:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tobias Pusinelli\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-23 18:40 - 2014-03-23 18:40 - 04745728 _____ (AVAST Software) C:\Users\Tobias Pusinelli\Downloads\aswMBR.exe
2014-03-22 19:55 - 2014-03-22 19:55 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-22 19:55 - 2014-03-22 19:55 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Local\Skype
==================== One Month Modified Files and Folders =======
2014-04-16 11:18 - 2014-04-05 22:28 - 00021515 _____ () C:\Users\Tobias Pusinelli\Desktop\FRST.txt
2014-04-16 11:18 - 2014-03-29 20:05 - 00000000 ____D () C:\FRST
2014-04-16 11:17 - 2014-04-16 11:17 - 00000000 ____D () C:\Users\Tobias Pusinelli\Desktop\FRST-OlderVersion
2014-04-16 11:17 - 2014-03-29 19:57 - 02054144 _____ (Farbar) C:\Users\Tobias Pusinelli\Desktop\FRST64.exe
2014-04-16 11:15 - 2012-07-08 19:17 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\Skype
2014-04-16 11:15 - 2012-07-07 12:13 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-04-16 11:15 - 2012-02-17 07:25 - 00001124 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-16 11:15 - 2012-02-17 07:19 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-15 22:02 - 2014-04-15 22:02 - 00001162 _____ () C:\Users\Tobias Pusinelli\Desktop\JRT.txt
2014-04-15 21:55 - 2014-04-15 21:55 - 00000000 ____D () C:\windows\ERUNT
2014-04-15 21:55 - 2009-07-14 06:45 - 00024400 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-15 21:55 - 2009-07-14 06:45 - 00024400 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-15 21:54 - 2014-04-15 21:54 - 01016261 _____ (Thisisu) C:\Users\Tobias Pusinelli\Desktop\JRT.exe
2014-04-15 21:53 - 2011-02-11 10:21 - 00711094 _____ () C:\windows\system32\perfh007.dat
2014-04-15 21:53 - 2011-02-11 10:21 - 00153542 _____ () C:\windows\system32\perfc007.dat
2014-04-15 21:53 - 2009-07-14 07:13 - 01651648 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-15 21:52 - 2012-07-07 12:07 - 01195890 _____ () C:\windows\WindowsUpdate.log
2014-04-15 21:49 - 2014-04-15 21:49 - 00006329 _____ () C:\Users\Tobias Pusinelli\Desktop\AdwCleaner[S0].txt
2014-04-15 21:49 - 2012-02-17 07:25 - 00001120 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-15 21:48 - 2012-07-07 12:13 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-04-15 21:48 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-15 21:48 - 2009-07-14 06:51 - 00085339 _____ () C:\windows\setupact.log
2014-04-15 21:47 - 2014-04-15 21:46 - 00000000 ____D () C:\AdwCleaner
2014-04-15 21:45 - 2014-04-15 21:45 - 01426178 _____ () C:\Users\Tobias Pusinelli\Desktop\adwcleaner.exe
2014-04-15 21:44 - 2014-04-15 21:44 - 00026890 _____ () C:\Users\Tobias Pusinelli\Desktop\mbam.txt
2014-04-15 21:42 - 2014-04-15 21:01 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-15 21:40 - 2012-02-17 07:19 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-04-15 21:40 - 2012-02-17 07:19 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-15 21:40 - 2012-02-17 07:19 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-15 21:38 - 2012-09-06 20:12 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Local\Adobe
2014-04-15 21:30 - 2010-11-21 05:47 - 01009988 _____ () C:\windows\PFRO.log
2014-04-15 21:29 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\Vss
2014-04-15 21:01 - 2014-04-15 21:01 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-15 21:01 - 2014-03-23 19:43 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\Malwarebytes
2014-04-15 21:01 - 2014-03-23 19:42 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-15 21:01 - 2014-03-16 21:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-15 20:53 - 2013-07-15 18:31 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\.minecraft
2014-04-15 14:31 - 2014-03-28 20:59 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\TS3Client
2014-04-12 19:55 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF
2014-04-11 21:42 - 2009-07-14 07:08 - 00032632 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-04-11 20:33 - 2012-02-17 07:25 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-10 17:42 - 2013-10-13 11:28 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-10 17:42 - 2013-10-13 11:28 - 00000000 ____D () C:\windows\system32\MRT
2014-04-07 20:59 - 2014-04-07 20:59 - 00027408 _____ () C:\ComboFix.txt
2014-04-07 20:59 - 2014-04-07 20:48 - 00000000 ____D () C:\Qoobox
2014-04-07 20:59 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-07 20:58 - 2014-04-07 20:48 - 00000000 ____D () C:\windows\erdnt
2014-04-07 20:57 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini
2014-04-07 20:47 - 2014-04-07 20:46 - 05195663 ____R (Swearware) C:\Users\Tobias Pusinelli\Desktop\ComboFix.exe
2014-04-07 20:44 - 2014-03-31 20:29 - 00001275 _____ () C:\Users\Tobias Pusinelli\Desktop\Revo Uninstaller.lnk
2014-04-07 20:44 - 2014-03-31 20:29 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-05 22:30 - 2014-04-05 22:28 - 00051766 _____ () C:\Users\Tobias Pusinelli\Desktop\FRST 2.txt
2014-04-03 09:51 - 2014-04-15 21:01 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-03 09:51 - 2014-03-16 21:12 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:50 - 2014-03-23 19:42 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-03-31 20:27 - 2014-03-31 20:26 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Tobias Pusinelli\Desktop\revosetup95.exe
2014-03-31 03:16 - 2014-04-10 16:05 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-10 16:05 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-10 16:05 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-10 16:05 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-30 20:34 - 2012-07-07 21:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 21:48 - 2014-03-16 21:12 - 00000000 ____D () C:\Users\Tobias Pusinelli\Desktop\mbar
2014-03-29 20:53 - 2014-03-29 20:06 - 00035525 _____ () C:\Users\Tobias Pusinelli\Desktop\Addition.txt
2014-03-29 20:49 - 2014-03-29 20:49 - 00002516 _____ () C:\Users\Tobias Pusinelli\Desktop\Gmer.txt
2014-03-29 20:08 - 2014-03-29 20:08 - 00380416 _____ () C:\Users\Tobias Pusinelli\Desktop\Gmer-19357.exe
2014-03-29 19:57 - 2014-03-29 19:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 19:57 - 2014-03-29 19:56 - 00000476 _____ () C:\Users\Tobias Pusinelli\Desktop\defogger_disable.log
2014-03-29 19:55 - 2014-03-29 19:55 - 00000494 _____ () C:\Users\Tobias Pusinelli\Downloads\defogger_disable.log
2014-03-29 19:55 - 2014-03-29 19:55 - 00000000 _____ () C:\Users\Tobias Pusinelli\defogger_reenable
2014-03-29 19:55 - 2012-07-07 18:37 - 00000000 ____D () C:\Users\Tobias Pusinelli
2014-03-29 19:53 - 2014-03-29 19:53 - 00050477 _____ () C:\Users\Tobias Pusinelli\Desktop\Defogger.exe
2014-03-29 00:08 - 2014-03-28 21:46 - 00328492 _____ () C:\Users\Tobias Pusinelli\AppData\Local\census.cache
2014-03-29 00:08 - 2014-03-28 21:46 - 00116909 _____ () C:\Users\Tobias Pusinelli\AppData\Local\ars.cache
2014-03-28 23:53 - 2014-03-28 21:27 - 00000036 _____ () C:\Users\Tobias Pusinelli\AppData\Local\housecall.guid.cache
2014-03-28 23:50 - 2014-03-28 23:50 - 00233520 _____ () C:\windows\RegBootClean64.exe
2014-03-28 23:49 - 2014-03-28 21:16 - 00000066 _____ () C:\Users\Tobias Pusinelli\AppData\Roaming\WB.CFG
2014-03-28 21:25 - 2014-03-28 21:25 - 02405664 _____ (Trend Micro Inc.) C:\Users\Tobias Pusinelli\Downloads\HousecallLauncher64.exe
2014-03-28 21:15 - 2014-03-28 21:15 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Local\cache
2014-03-28 21:15 - 2014-03-28 21:15 - 00000000 ____D () C:\Users\Tobias Pusinelli\.android
2014-03-28 21:15 - 2014-03-28 21:15 - 00000000 _____ () C:\Users\Tobias Pusinelli\daemonprocess.txt
2014-03-28 21:15 - 2014-03-28 21:13 - 02346186 _____ () C:\Users\Tobias Pusinelli\Downloads\TechnicLauncher(2).exe
2014-03-28 21:11 - 2014-03-28 21:11 - 00685648 _____ () C:\Users\Tobias Pusinelli\Downloads\ZipSetup.exe
2014-03-28 21:04 - 2014-03-28 21:03 - 02346186 _____ () C:\Users\Tobias Pusinelli\Downloads\TechnicLauncher(1).exe
2014-03-28 20:58 - 2014-03-28 20:58 - 00000978 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-03-28 20:58 - 2014-03-28 20:58 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-28 20:58 - 2014-03-28 20:55 - 29498592 _____ (TeamSpeak Systems GmbH) C:\Users\Tobias Pusinelli\Downloads\TeamSpeak3-Client-win64-3.0.14.exe
2014-03-28 20:40 - 2014-03-28 20:30 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\.technic
2014-03-28 20:30 - 2014-03-28 20:30 - 02346186 _____ () C:\Users\Tobias Pusinelli\Downloads\TechnicLauncher.exe
2014-03-27 21:18 - 2012-08-06 22:02 - 00000000 ____D () C:\ProgramData\Trend Micro
2014-03-26 21:27 - 2012-02-17 07:25 - 00004120 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-26 21:27 - 2012-02-17 07:25 - 00003868 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-26 20:46 - 2014-03-25 20:57 - 00000355 _____ () C:\Users\Tobias Pusinelli\Downloads\Serverregeln.txt
2014-03-23 20:41 - 2014-03-23 20:41 - 00001088 _____ () C:\Users\Tobias Pusinelli\Desktop\Kaspersky Security Scan.lnk
2014-03-23 20:41 - 2014-03-23 20:41 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
2014-03-23 20:40 - 2014-03-23 20:40 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-03-23 20:40 - 2014-03-23 20:40 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-03-23 20:35 - 2014-03-23 20:35 - 00185944 _____ (Лаборатория Касперского) C:\Users\Tobias Pusinelli\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5623.exe
2014-03-23 19:40 - 2014-03-16 21:14 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-03-23 19:39 - 2014-03-23 19:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tobias Pusinelli\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-23 18:40 - 2014-03-23 18:40 - 04745728 _____ (AVAST Software) C:\Users\Tobias Pusinelli\Downloads\aswMBR.exe
2014-03-22 19:55 - 2014-03-22 19:55 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-22 19:55 - 2014-03-22 19:55 - 00000000 ____D () C:\Users\Tobias Pusinelli\AppData\Local\Skype
2014-03-22 19:55 - 2012-02-17 07:01 - 00000000 ____D () C:\ProgramData\Skype
2014-03-21 21:20 - 2014-03-10 20:35 - 00000000 ____D () C:\Users\Tobias Pusinelli\Downloads\authlib
Some content of TEMP:
====================
C:\Users\Tobias Pusinelli\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-15 14:14
==================== End Of Log ============================ --- --- --- |