mousebear | 04.05.2014 20:06 | Hallo,
danke für deine schnelle Hilfe! :)
Die Scans haben insgesamt alle einige Stunden gedauert, aber jetzt ist alles fertig.
Meine Logfiles: mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 04.05.2014 18:44:04, SYSTEM, JACKSON, Protection, Malware Protection, Starting,
Protection, 04.05.2014 18:44:04, SYSTEM, JACKSON, Protection, Malware Protection, Started,
Protection, 04.05.2014 18:44:04, SYSTEM, JACKSON, Protection, Malicious Website Protection, Starting,
Protection, 04.05.2014 18:44:07, SYSTEM, JACKSON, Protection, Malicious Website Protection, Started,
Update, 04.05.2014 18:44:08, SYSTEM, JACKSON, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 04.05.2014 18:44:20, SYSTEM, JACKSON, Manual, Malware Database, 2014.3.4.9, 2014.5.4.8,
Protection, 04.05.2014 18:44:21, SYSTEM, JACKSON, Protection, Refresh, Starting,
Protection, 04.05.2014 18:44:21, SYSTEM, JACKSON, Protection, Malicious Website Protection, Stopping,
Protection, 04.05.2014 18:44:23, SYSTEM, JACKSON, Protection, Malicious Website Protection, Stopped,
Protection, 04.05.2014 18:44:27, SYSTEM, JACKSON, Protection, Refresh, Success,
Protection, 04.05.2014 18:44:27, SYSTEM, JACKSON, Protection, Malicious Website Protection, Starting,
Protection, 04.05.2014 18:44:28, SYSTEM, JACKSON, Protection, Malicious Website Protection, Started,
Detection, 04.05.2014 19:22:01, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.HQTotalS.A, C:\Program Files (x86)\HQTotalS\HQTotalS-firefoxinstaller.exe, Quarantine, [dc8c97b698e372c47f7e362f50b1d030]
Detection, 04.05.2014 19:22:01, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.HQTotalS.A, C:\Program Files (x86)\HQTotalS\HQTotalS-chromeinstaller.exe, Quarantine, [7deb58f51368a096f00db4b1e021758b]
Detection, 04.05.2014 20:22:01, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.HQTotalS.A, c:\program files (x86)\hqtotals\hqtotals-firefoxinstaller.exe, Quarantine, [dc8c97b698e372c47f7e362f50b1d030]
Detection, 04.05.2014 20:22:01, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.HQTotalS.A, c:\program files (x86)\hqtotals\hqtotals-chromeinstaller.exe, Quarantine, [7deb58f51368a096f00db4b1e021758b]
Protection, 04.05.2014 20:22:01, SYSTEM, JACKSON, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\hqtotals\hqtotals-firefoxinstaller.exe,
Error, 04.05.2014 20:22:01, SYSTEM, JACKSON, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\hqtotals\hqtotals-firefoxinstaller.exe,
Error, 04.05.2014 20:22:01, SYSTEM, JACKSON, Protection, SDKQuarantine, 2, Failed, c:\program files (x86)\hqtotals\hqtotals-chromeinstaller.exe,
Protection, 04.05.2014 20:33:29, SYSTEM, JACKSON, Protection, Malware Protection, Starting,
Protection, 04.05.2014 20:33:29, SYSTEM, JACKSON, Protection, Malware Protection, Started,
Protection, 04.05.2014 20:33:29, SYSTEM, JACKSON, Protection, Malicious Website Protection, Starting,
Protection, 04.05.2014 20:34:56, SYSTEM, JACKSON, Protection, Malicious Website Protection, Started,
Detection, 04.05.2014 20:36:27, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\defaults\preferences\prefs.js, Quarantine, [04643815b0cb64d2eaecd598c73b14ec]
Detection, 04.05.2014 20:36:31, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\locale\en-US\translations.dtd, Quarantine, [cb9d65e82952bd79fbdb5f0e42c07987]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\baseObject.js, Quarantine, [3d2b9cb1512a4beb3e98254855ad2fd1]
Detection, 04.05.2014 20:36:31, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\skin\skin.css, Quarantine, [4127d27b8dee9d99be18c0ad13efee12]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\browser.xul, Quarantine, [175150fdfc7f9e9831a593da887ab24e]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\platformVersion.js, Quarantine, [9fc99fae4a3159ddc412e885ef13db25]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\consts.js, Quarantine, [5a0e9eaf611adb5ba5313835f2106a96]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\logFile.js, Quarantine, [185082cb5724fe38b22477f6f30f4fb1]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\xhr.js, Quarantine, [96d2a2ab067566d02bab8ae3e51da25e]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\utils.js, Quarantine, [83e5bf8ef08b91a54c8a204df909a25e]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\console.js, Quarantine, [86e2b09d215ae6505a7ccda0e0222ed2]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\reports.js, Quarantine, [94d455f83c3f42f40acc94d9f210ee12]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\delegate.js, Quarantine, [5810311cceadbb7b488e6c0114ee51af]
Detection, 04.05.2014 20:36:31, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\registry.js, Quarantine, [33351835364586b01fb70a6326dcc63a]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\prefs.js, Quarantine, [10589bb20e6d290d577f79f4669c56aa]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\IDBWrapper.js, Quarantine, [6dfb26277cfffd390fc74c21f50db34d]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\folderIOWrapper.js, Quarantine, [76f2024b8af1fe38d204e885897905fb]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\reloadObserver.js, Quarantine, [01677dd0b6c5a393597d1f4e7b8735cb]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\background.js, Quarantine, [abbdeb625e1d46f014c2e28baa580ef2]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\browserAction.js, Quarantine, [93d5094433483ef80ec8c2abac56936d]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\dom_bg.js, Quarantine, [8bdd92bb681361d5f0e61e4fce34f10f]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\contextMenu.js, Quarantine, [1d4b5fee4833191d22b45d1027dbda26]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\windowsMessagingHandler.js, Quarantine, [7bedfc5188f31d198452c5a8659d23dd]
Detection, 04.05.2014 20:36:32, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\asyncDB.js, Quarantine, [e484c4894a319c9a5185cca17e848977]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\fileManager.js, Quarantine, [0f5994b95a215cdafed85d1026dc19e7]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\firefox.js, Quarantine, [98d0d07dff7c989e8a4ce28bd32fc33d]
Detection, 04.05.2014 20:36:32, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\firefoxNotifications.js, Quarantine, [1256e6678bf082b4b71f5815e51db947]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\firefoxOmnibox.js, Quarantine, [f375d4799edd63d3399d303da35fe818]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\message.js, Quarantine, [6cfcf954bcbf999d8d49a7c6c63ca55b]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\request.js, Quarantine, [c0a8d67788f34aec7e58e58869994db3]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\tabs.js, Quarantine, [194ffe4f0c6fd95d7e587af3936f3fc1]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\pageAction.js, Quarantine, [bcaceb6293e8d06673637af3ea1823dd]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\addressBarChangeObserver.js, Quarantine, [432554f97dfe310506d06c01aa589c64]
Detection, 04.05.2014 20:36:33, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\uninstallObserver.js, Quarantine, [0c5c133abcbf95a1676ff776f30fe917]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\progressListenerObserver.js, Quarantine, [8bdd3b12e29947ef964086e72ad85ba5]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\httpObserver.js, Quarantine, [fd6b19342a5179bddbfb2e3ff50d21df]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\requestObject.js, Quarantine, [1355173693e832042ea81d5021e14fb1]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api\webRequest.js, Quarantine, [d98f37162c4fd75f4a8ca3ca4fb3ab55]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\searchSettings.js, Quarantine, [b2b69ab3621992a4aa2ca9c415ed14ec]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\extensionDataStore.js, Quarantine, [bdab98b5c7b471c5775facc1cc3609f7]
Detection, 04.05.2014 20:36:33, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\updateManager.js, Quarantine, [6efa044966151d191eb88ce111f10df3]
Detection, 04.05.2014 20:36:34, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\core\installer.js, Quarantine, [fe6ae8650f6cee4831a5125b16ecd12f]
Detection, 04.05.2014 20:36:34, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\api.js, Quarantine, [491fbe8fb9c24de9bf179fceab577888]
Detection, 04.05.2014 20:36:34, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\main.js, Quarantine, [3b2db4997803f442a72fb1bc8b77df21]
Detection, 04.05.2014 20:36:34, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\manifest.xml, Quarantine, [4127d578e7946ec8389ec1ac3cc65ca4]
Detection, 04.05.2014 20:36:34, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\chrome\content\background.html, Quarantine, [1157b895324995a14e88f37aa959b54b]
Detection, 04.05.2014 20:36:34, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins.json, Quarantine, [5f0977d6a5d6f0469c3a323b16ecd22e]
Detection, 04.05.2014 20:36:35, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\246_setup.js, Quarantine, [e3853c114f2c64d2ede9e5881ee47888]
Detection, 04.05.2014 20:36:35, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\4_jquery_1_7_1.js, Quarantine, [5414dd70d3a868ce8c4a4b226999bc44]
Detection, 04.05.2014 20:36:35, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\14_CrossriderUtils.js, Quarantine, [c7a1cb826b10a88ec61099d4d131b749]
Detection, 04.05.2014 20:36:35, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\78_CrossriderInfo.js, Quarantine, [5315a3aa4437e05623b3dd9003ffe41c]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\16_FFAppAPIWrapper.js, Quarantine, [e97f371698e393a3a92d28454fb3c838]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\64_appApiMessage.js, Quarantine, [aabea9a4f487b284ffd72b421ce6d32d]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\183_tabsWrapper.js, Quarantine, [06626ce1275493a396405518cb3707f9]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\207_dbWrapper.js, Quarantine, [a4c4d8757902171f28ae0865bb473cc4]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\47_resources_background.js, Quarantine, [f96f50fdec8fff3715c13c31c24029d7]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\182_openUrl.js, Quarantine, [de8ac885ea9159ddf6e0a1cc8082e818]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\72_appApiValidation.js, Quarantine, [f6727fce26558bab55814c21649ea957]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\98_omniCommands.js, Quarantine, [5117cc813c3fb97dbd1970fd18eac937]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\93_superfish_no_coupons_m.js, Quarantine, [e880fe4fa2d993a3f8defa7392703ec2]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\102_dealply_m.js, Quarantine, [016798b589f21f17c313501de2201fe1]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\123_intext_adv_m.js, Quarantine, [0a5e9db06f0cf93dc51158157290a060]
Detection, 04.05.2014 20:36:36, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\155_ibario_pops_m.js, Quarantine, [e0882a2336459e98dcfa551847bb758b]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\178_revizer_ws_dynamic_m.js, Quarantine, [1058222bfc7f3bfb2caaff6e887a768a]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\179_revizer_p_dynamic_m.js, Quarantine, [1b4d48056615082e4c8a97d67d8536ca]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\180_bpo_serp_m.js, Quarantine, [83e53e0f9ae153e3ba1cc8a511f127d9]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\184_noproblemppc_m.js, Quarantine, [e97f8ebf5a21b97d4e88b1bc35cd9e62]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\191_ciuvo_m.js, Quarantine, [e286a2abaad155e150867af36f930bf5]
Detection, 04.05.2014 20:36:37, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\220_icm_base_m.js, Quarantine, [6efa1736bcbf5fd77660f77615ed2bd5]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\195_icm_convertmedia_m.js, Quarantine, [066257f65b200d297561353819e91ce4]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\223_imonomy_m.js, Quarantine, [3434ff4ed2a983b392440e5f59a9ab55]
Detection, 04.05.2014 20:36:37, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\231_revizer_ws_dynamic_2_m.js, Quarantine, [551389c4136851e52ea895d80df5be42]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\232_revizer_p_dynamic_2_m.js, Quarantine, [d593f05d91ead2644c8a9ad39171b749]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\242_price_gong_m.js, Quarantine, [0f59d07d473491a58551c6a7719147b9]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\244_engageya_inner_m.js, Quarantine, [343487c63d3e3afc3c9a0d6021e1926e]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\91_monetizationLoader.js.js, Quarantine, [4424f05d88f3e3536373a1cc72909c64]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\17_jQuery.js, Quarantine, [541437166a1185b15b7b5b12a55de41c]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\13_CrossriderAppUtils.js, Quarantine, [87e196b7fb80ab8b884ec3aa9d6502fe]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\1_base.js, Quarantine, [91d717365d1eae88904672fb758dc838]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\21_debug.js, Quarantine, [4d1ba4a94d2e1e183d99ff6e21e1b848]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\22_resources.js, Quarantine, [04641b325a215fd716c047262bd7c937]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\7_hooks.js, Quarantine, [9fc99faec7b4f145a92df27bc83a37c9]
Detection, 04.05.2014 20:36:38, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\9_search_engine_hook.js, Quarantine, [63053c119cdf63d3f5e13a336e9441bf]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\103_intext_5_m.js, Quarantine, [1751cd80d9a277bf3d9989e45fa36898]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\104_jollywallet_m.js, Quarantine, [96d21f2e3e3dbc7aa82e1657c240d828]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\119_similar_web_m.js, Quarantine, [70f8bc911d5e8ea82aace984857dcb35]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\190_pops_5_m.js, Quarantine, [87e169e4f48752e41cba68059d6519e7]
Detection, 04.05.2014 20:36:39, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\257_adextent_m.js, Quarantine, [1a4e56f75e1d87af0acc77f67191e719]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\177_crossriderDashboard.js, Quarantine, [0365b09dd5a685b1b620ed800200ca36]
Detection, 04.05.2014 20:36:39, SYSTEM, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\plugins\28_initializer.js, Quarantine, [76f29db00a71989e5284e786c2406898]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\userCode\background.js, Quarantine, [abbdf6571b60a096ce0882eb09f90000]
Detection, 04.05.2014 20:36:39, *****, JACKSON, Protection, Malware Protection, File, PUP.Optional.CrossRider.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com\extensionData\userCode\extension.js, Quarantine, [432583cabdbe3105a0366a0335cd6c94]
(end) AdwCleaner: Code:
# AdwCleaner v3.206 - Bericht erstellt am 04/05/2014 um 20:45:05
# Aktualisiert 04/05/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : ***** - JACKSON
# Gestartet von : C:\Users\*****\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\AnyProtectEx
Ordner Gelöscht : C:\Program Files (x86)\Uninstaller
Ordner Gelöscht : C:\Program Files (x86)\HQTotalS
Ordner Gelöscht : C:\Users\*****\.android
Ordner Gelöscht : C:\Users\*****\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\Extensions\ee5ad154-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com
Datei Gelöscht : C:\END
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\*****\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\*****\AppData\Roaming\aps.scan.results
Datei Gelöscht : C:\Users\*****\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\WINDOWS\Tasks\APSnotifierPP1.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\APSnotifierPP1
Datei Gelöscht : C:\WINDOWS\Tasks\APSnotifierPP2.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\APSnotifierPP2
Datei Gelöscht : C:\WINDOWS\Tasks\APSnotifierPP3.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\APSnotifierPP3
Datei Gelöscht : C:\WINDOWS\Tasks\HQTotalS-chromeinstaller.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\HQTotalS-chromeinstaller
Datei Gelöscht : C:\WINDOWS\Tasks\HQTotalS-codedownloader.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\HQTotalS-codedownloader
Datei Gelöscht : C:\WINDOWS\Tasks\HQTotalS-enabler.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\HQTotalS-enabler
Datei Gelöscht : C:\WINDOWS\Tasks\HQTotalS-firefoxinstaller.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\HQTotalS-firefoxinstaller
Datei Gelöscht : C:\WINDOWS\Tasks\HQTotalS-updater.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\HQTotalS-updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0053172.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0053172.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0053172.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0053172.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511311172}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522312272}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555315572}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566316672}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544314472}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511311172}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511311172}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{005abe5c-3967-4be4-900e-36f4ea332ca5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ffbd811e-7003-45ab-8283-3af1f8e7a367}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511311172}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522312272}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555315572}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566316672}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511311172}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{005abe5c-3967-4be4-900e-36f4ea332ca5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ffbd811e-7003-45ab-8283-3af1f8e7a367}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Re_Markable
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\HQTotalS
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\HQTotalS
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16518
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\prefs.js ]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.InstallationThankYouPage", false);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.InstallationTime", 1395242501);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.active", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.addressbar", "NA");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.addressbarenhanced", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172_dbWasSet_FF25_FIX", true[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.asyncdb.was_copied", "true");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.asyncdb_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.asyncdb_dbWasSet_FF25_FIX", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.asyncinternaldb.was_copied", "true");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.asyncinternaldb_dbWasSet", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.asyncinternaldb_dbWasSet_FF25_FIX", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.backgroundver", 2);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.certdomaininstaller", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.changeprevious", false);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.InstallationTime.value", "%221395242501%22");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22001325%22%2C%22sub_id%22%3A%220%22%2C%22uz[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.load_balancer.expiration", "Sun May 04 2014 21:28:40 GMT+0200");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%201%2C%5C%22Endpoint%5C%22%3A%20%5C%2[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.previous_page.value", "%22hxxps%3A//lernen.h-da.de/course/view.php%3Fid%3D477%22");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.cookie.user_id.value", "%2214569e60aba8d5486c277aed47f18026%22");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.description", "HQ Videos is an add-on for your Internet browser that enhances your online experien[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.domain", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.enablesearch", false);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.homepage", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.iframe", false);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%227F9C81190DBB49DBBE1FA9C99E864[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22001325%22%2C%22sub_id%22%3A%220%22%2C%[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22001325%22%2C%22sub_id%22%3A%220%2[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%227F9C81190DBB49DBBE1F[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_appVer.value", "51");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_lastVersion.value", "1");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_meta.value", "%7B%7D");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_nextCheck.expiration", "Sun May 04 2014 21:28:39 GMT+0200");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_nextCheck.value", "true");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_queue.value", "%7B%7D");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.__defualt_browser__.value", "%22ff%22");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%227F9C8119[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin__disable_bi_pixel_.expiration", "Fri May 09 2014 18:52:16 GMT+0200"[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin__disable_bi_pixel_.value", "true");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_bundledWithHash.value", "null");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_last_executable_request.expiration", "Mon May 05 2014 06:41:03 GMT+[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_last_executable_request.value", "%22hxxp%3A//filepony.de/dl-bWJhbS1[...]
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.lastDailyReport", "1399209560377");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.lastUpdate", "1399210119037");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.manifesturl", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.name", "HQ-Video-Pro-1.9");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.newtab", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.opensearch", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.pluginsurl", "hxxp://js.clientdemostack.com/plugin/apps/53172/plugins/094/ff/plugins.json");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.pluginsversion", 44);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.publisher", "HQ-Video");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.searchstatus", 0);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.setnewtab", false);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.thankyou", "");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.updateinterval", 360);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.53172.ver", 51);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.FilesValidatorDueTime", "1399209558990");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.apps", "53172");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.bic", "14569e60aba8d5486c277aed47f18026");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.cid", 53172);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.firstrun", false);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.hadappinstalled", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.installationdate", 1398708043);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.modetype", "production");
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.reportInstall", true);
Zeile gelöscht : user_pref("extensions.aee5ad154f9094cc0aa51d7e94e3fb0af36204afdf43e49179c718384e2e4d3adcom53172.statsDailyCounter", 10);
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14569e60aba8d5486c277aed47f18026");
*************************
AdwCleaner[R0].txt - [25784 octets] - [04/05/2014 20:42:50]
AdwCleaner[S0].txt - [23403 octets] - [04/05/2014 20:45:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [23464 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Shi Jackson on 04.05.2014 at 20:51:42,12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Myfree Codec
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
~~~ FireFox
Emptied folder: C:\Users\Shi Jackson\AppData\Roaming\mozilla\firefox\profiles\yx3tnvw9.default-1397594658270\minidumps [4 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.05.2014 at 20:57:02,63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-05-2014
Ran by ***** (administrator) on JACKSON on 04-05-2014 20:59:44
Running from C:\Users\*****\Desktop
Windows 8.1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
() C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2608040 2012-08-14] (TOSHIBA Corporation)
HKLM\...\Run: [TODDMain] => C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe [213136 2012-08-05] ()
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [169896 2012-08-14] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [356776 2012-07-11] (TOSHIBA Corporation)
HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2170784 2012-07-27] (SRS Labs, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-08-02] (Intel Corporation)
HKLM-x32\...\Run: [TPUReg(x86)] => "C:\Program Files\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM-x32\...\Run: [TPUReg] => C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe [6884352 2012-08-23] (Pegatron Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://toshiba13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
SearchScopes: HKLM - DefaultScope {4C4C4BD3-CE9A-4C19-9072-D108E021FDC6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
SearchScopes: HKLM - {4C4C4BD3-CE9A-4C19-9072-D108E021FDC6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
SearchScopes: HKLM-x32 - {4C4C4BD3-CE9A-4C19-9072-D108E021FDC6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MATMJS
SearchScopes: HKCU - {4C4C4BD3-CE9A-4C19-9072-D108E021FDC6} URL =
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yx3tnvw9.default-1397594658270\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-19]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2014-01-07]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227936 2013-11-09] (WildTangent)
R2 GFNEXSrv; C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe [156672 2011-10-14] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [114656 2012-08-14] (Toshiba Europe GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-04] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R2 PEGAGFN; C:\Program Files (x86)\TOSHIBA\Password Utility\PEGAGFN.sys [14344 2009-09-12] (PEGATRON)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation )
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-14] (Synaptics Incorporated)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-28] (Microsoft Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [28632 2012-07-31] (Windows (R) Win 7 DDK provider)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-04 20:59 - 2014-05-04 20:59 - 00013977 _____ () C:\Users\*****\Desktop\FRST.txt
2014-05-04 20:57 - 2014-05-04 20:57 - 00001002 _____ () C:\Users\*****\Desktop\JRT.txt
2014-05-04 20:51 - 2014-05-04 20:51 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-04 20:50 - 2014-05-04 20:50 - 01016261 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe
2014-05-04 20:42 - 2014-05-04 20:45 - 00000000 ____D () C:\AdwCleaner
2014-05-04 20:40 - 2014-05-04 20:40 - 01313617 _____ () C:\Users\*****\Desktop\adwcleaner.exe
2014-05-04 18:44 - 2014-05-04 20:48 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-04 18:43 - 2014-05-04 18:43 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-04 18:43 - 2014-05-04 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-04 18:43 - 2014-05-04 18:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-04 18:43 - 2014-05-04 18:43 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-04 18:43 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-04 18:43 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-04 18:43 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-04 18:41 - 2014-05-04 18:41 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\*****\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-03 16:23 - 2014-05-04 20:39 - 00000000 ____D () C:\Users\*****\Desktop\infos_trojanerboard
2014-05-02 15:55 - 2014-05-02 15:56 - 00380416 _____ () C:\Users\*****\Desktop\i58wrslu.exe
2014-05-02 15:50 - 2014-05-04 20:59 - 00000000 ____D () C:\FRST
2014-05-02 15:48 - 2014-05-02 15:48 - 02062336 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2014-05-02 15:46 - 2014-05-02 15:46 - 00000000 _____ () C:\Users\*****\defogger_reenable
2014-05-02 15:45 - 2014-05-02 15:46 - 00050477 _____ () C:\Users\*****\Desktop\Defogger.exe
2014-05-02 15:22 - 2014-04-29 18:00 - 23133184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-05-02 15:22 - 2014-04-29 16:47 - 17074688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-05-02 15:00 - 2014-05-02 15:35 - 00024004 _____ () C:\Users\*****\Desktop\Kopie von Exposé IWk.odt
2014-05-02 13:49 - 2014-05-02 16:29 - 00024983 _____ () C:\Users\*****\Desktop\Quellen_IWK.odt
2014-05-02 13:49 - 2014-05-02 13:49 - 01218719 _____ () C:\Users\*****\Desktop\IWK.dotm
2014-05-01 20:29 - 2012-09-20 13:46 - 00155065 _____ () C:\Users\*****\Desktop\_D7C9761finish.jpeg
2014-05-01 20:29 - 2012-08-06 19:06 - 00161031 _____ () C:\Users\*****\Desktop\_D7C9889.jpeg
2014-05-01 20:29 - 2012-08-06 19:00 - 10687912 _____ () C:\Users\*****\Desktop\_D7C9865finish.jpeg
2014-05-01 20:10 - 2014-05-01 20:10 - 00000000 ____D () C:\Users\*****\Desktop\Julz Geb '13
2014-05-01 20:06 - 2014-05-01 20:07 - 00000000 ____D () C:\Users\*****\Desktop\Julz Abschied_FFM
2014-04-28 20:22 - 2014-04-28 20:22 - 17931952 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2014-04-15 22:44 - 2014-04-15 22:44 - 00000000 ____D () C:\Users\*****\Desktop\Alte Firefox-Daten
2014-04-11 11:20 - 2014-03-14 16:00 - 20085800 _____ (intelligent views gmbh) C:\Users\*****\Desktop\kb.exe
2014-04-11 11:17 - 2014-04-11 11:17 - 00001186 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-11 11:17 - 2014-04-11 11:17 - 00001174 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-11 11:17 - 2014-04-11 11:17 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Mozilla
2014-04-11 11:17 - 2014-04-11 11:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-10 10:25 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-04-10 10:25 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2014-04-10 10:25 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-04-10 10:25 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-04-10 10:25 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-04-10 10:25 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-04-10 10:16 - 2014-04-10 10:16 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-04-09 18:32 - 2014-04-11 11:10 - 00002218 _____ () C:\WINDOWS\IE10_main.log
2014-04-06 19:55 - 2014-04-11 13:54 - 00000000 ____D () C:\Users\*****\sets
2014-04-04 14:19 - 2014-04-04 14:19 - 00000000 ____D () C:\Users\*****\Glossar_Oekologie
==================== One Month Modified Files and Folders =======
2014-05-04 20:59 - 2014-05-04 20:59 - 00013977 _____ () C:\Users\*****\Desktop\FRST.txt
2014-05-04 20:59 - 2014-05-02 15:50 - 00000000 ____D () C:\FRST
2014-05-04 20:57 - 2014-05-04 20:57 - 00001002 _____ () C:\Users\*****\Desktop\JRT.txt
2014-05-04 20:51 - 2014-05-04 20:51 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-04 20:51 - 2013-09-30 06:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-04 20:51 - 2013-09-30 05:56 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2014-05-04 20:51 - 2013-09-30 05:56 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2014-05-04 20:50 - 2014-05-04 20:50 - 01016261 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe
2014-05-04 20:48 - 2014-05-04 18:44 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-04 20:48 - 2013-11-28 01:08 - 00000000 __RDO () C:\Users\*****\SkyDrive
2014-05-04 20:46 - 2013-09-29 21:04 - 00007732 _____ () C:\WINDOWS\PFRO.log
2014-05-04 20:46 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-04 20:45 - 2014-05-04 20:42 - 00000000 ____D () C:\AdwCleaner
2014-05-04 20:45 - 2013-11-28 00:28 - 00000000 ____D () C:\Users\*****
2014-05-04 20:45 - 2013-08-22 15:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2014-05-04 20:40 - 2014-05-04 20:40 - 01313617 _____ () C:\Users\*****\Desktop\adwcleaner.exe
2014-05-04 20:39 - 2014-05-03 16:23 - 00000000 ____D () C:\Users\*****\Desktop\infos_trojanerboard
2014-05-04 20:22 - 2013-04-23 21:32 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-04 20:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-05-04 18:49 - 2013-02-04 19:14 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1304462860-3059654524-3767983173-1001
2014-05-04 18:43 - 2014-05-04 18:43 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-04 18:43 - 2014-05-04 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-04 18:43 - 2014-05-04 18:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-04 18:43 - 2014-05-04 18:43 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-04 18:41 - 2014-05-04 18:41 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\*****\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-04 17:43 - 2013-07-04 15:31 - 00000000 ____D () C:\Users\*****\Documents\Studium
2014-05-04 17:42 - 2013-11-28 00:47 - 01641311 _____ () C:\WINDOWS\WindowsUpdate.log
2014-05-04 15:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-05-03 16:15 - 2014-01-17 22:25 - 00000000 ____D () C:\Users\*****\Desktop\Originals
2014-05-03 16:11 - 2013-02-21 14:41 - 00016384 ____H () C:\Users\*****\Desktop\photothumb.db
2014-05-02 16:29 - 2014-05-02 13:49 - 00024983 _____ () C:\Users\*****\Desktop\Quellen_IWK.odt
2014-05-02 15:56 - 2014-05-02 15:55 - 00380416 _____ () C:\Users\*****\Desktop\i58wrslu.exe
2014-05-02 15:48 - 2014-05-02 15:48 - 02062336 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe
2014-05-02 15:46 - 2014-05-02 15:46 - 00000000 _____ () C:\Users\*****\defogger_reenable
2014-05-02 15:46 - 2014-05-02 15:45 - 00050477 _____ () C:\Users\*****\Desktop\Defogger.exe
2014-05-02 15:35 - 2014-05-02 15:00 - 00024004 _____ () C:\Users\*****\Desktop\Kopie von Exposé IWk.odt
2014-05-02 13:49 - 2014-05-02 13:49 - 01218719 _____ () C:\Users\*****\Desktop\IWK.dotm
2014-05-01 20:10 - 2014-05-01 20:10 - 00000000 ____D () C:\Users\*****\Desktop\Julz Geb '13
2014-05-01 20:07 - 2014-05-01 20:06 - 00000000 ____D () C:\Users\*****\Desktop\Julz Abschied_FFM
2014-04-29 18:00 - 2014-05-02 15:22 - 23133184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-29 16:47 - 2014-05-02 15:22 - 17074688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-04-28 22:04 - 2013-06-24 12:43 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-28 20:22 - 2014-04-28 20:22 - 17931952 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2014-04-28 20:22 - 2013-04-23 21:32 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-23 02:24 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-04-23 02:24 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-16 16:07 - 2013-05-16 23:46 - 00000000 ____D () C:\Users\*****\Originals
2014-04-15 22:44 - 2014-04-15 22:44 - 00000000 ____D () C:\Users\*****\Desktop\Alte Firefox-Daten
2014-04-11 13:54 - 2014-04-06 19:55 - 00000000 ____D () C:\Users\*****\sets
2014-04-11 12:34 - 2013-07-17 21:50 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-11 12:33 - 2013-02-04 20:06 - 90655440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-11 11:17 - 2014-04-11 11:17 - 00001186 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-11 11:17 - 2014-04-11 11:17 - 00001174 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-11 11:17 - 2014-04-11 11:17 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Mozilla
2014-04-11 11:17 - 2014-04-11 11:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-11 11:17 - 2014-03-29 17:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-11 11:10 - 2014-04-09 18:32 - 00002218 _____ () C:\WINDOWS\IE10_main.log
2014-04-10 10:16 - 2014-04-10 10:16 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-04-09 18:53 - 2013-08-22 16:46 - 00308617 _____ () C:\WINDOWS\setupact.log
2014-04-04 14:19 - 2014-04-04 14:19 - 00000000 ____D () C:\Users\*****\Glossar_Oekologie
Some content of TEMP:
====================
C:\Users\*****\AppData\Local\Temp\avgnt.exe
C:\Users\*****\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\*****\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\*****\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\*****\AppData\Local\Temp\i4jdel0.exe
C:\Users\*****\AppData\Local\Temp\ICReinstall_FreeYouTubeToMP3Converter.exe
C:\Users\*****\AppData\Local\Temp\Quarantine.exe
C:\Users\*****\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\*****\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\*****\AppData\Local\Temp\TUUUninstallHelper.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-01 19:28
==================== End Of Log ============================ --- --- --- |