DJSpeedy | 28.05.2014 18:24 | so... chef :-) alles erledigt.
Schritt 1: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-05-2014 02
Ran by Lars at 2014-05-28 18:31:04 Run:1
Running from C:\Users\Lars\Desktop\Adware Tools\Schritt 1
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:7777
SearchScopes: HKCU - {758B870D-DF78-4A6A-9955-DEDDCACF94DC} URL =
FF Extension: Address Bar Search - C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}.xpi [2013-10-25]
FF Extension: HD Streamer - C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\Extensions\hd_streamer@iMedia [2014-05-24]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Task: {3AF57CFF-0CF4-4755-BF98-509EC78AC5C8} - \DigitalSite No Task File <==== ATTENTION
Task: {6E3A13BA-8055-4948-94A4-C385C5873545} - \bench-sys No Task File <==== ATTENTION
Task: {A3AE5A93-2948-485B-A93D-82B057BF782B} - \BitGuard No Task File <==== ATTENTION
C:\Program Files (x86)\Vtools
C:\Users\Lars\AppData\Roaming\Apple Computer\MobileSync\Backup\0ab4a4c543c7fae001fed414d82909d2e9baf9d7
C:\Windows\System32\dfrg
C:\Windows\SysWOW64\dfrg
Reboot:
end
*****************
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{758B870D-DF78-4A6A-9955-DEDDCACF94DC} => Key deleted successfully.
HKCR\CLSID\{758B870D-DF78-4A6A-9955-DEDDCACF94DC} => Key not found.
C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}.xpi => Moved successfully.
C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\Extensions\hd_streamer@iMedia => Moved successfully.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3AF57CFF-0CF4-4755-BF98-509EC78AC5C8} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AF57CFF-0CF4-4755-BF98-509EC78AC5C8} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DigitalSite => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6E3A13BA-8055-4948-94A4-C385C5873545} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6E3A13BA-8055-4948-94A4-C385C5873545} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bench-sys => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3AE5A93-2948-485B-A93D-82B057BF782B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3AE5A93-2948-485B-A93D-82B057BF782B} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BitGuard => Key deleted successfully.
C:\Program Files (x86)\Vtools => Moved successfully.
C:\Users\Lars\AppData\Roaming\Apple Computer\MobileSync\Backup\0ab4a4c543c7fae001fed414d82909d2e9baf9d7 => Moved successfully.
"C:\Windows\System32\dfrg" => File/Directory not found.
C:\Windows\SysWOW64\dfrg => Moved successfully.
The system needed a reboot.
==== End of Fixlog ==== Schritt 2: Code:
Zoek.exe v5.0.0.0 Updated 22-05-2014
Tool run by Lars on 28.05.2014 at 18:37:33,26.
Microsoft Windows 7 eXtreme™ Draconis Edition 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Lars\Desktop\Adware Tools\Schritt 2\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
28.05.2014 18:38:43 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\SearchScopes\{41F23684-D0B3-4D6C-AC19-5D82E79E82CD} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{5BFEFF94-6411-4B74-A947-4969134B24DE} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{82E1477C-B154-48D3-9891-33D83C26BCD3} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311851132} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{93DBF2BB-A2B3-4683-A92E-57E60751F346} deleted successfully
HKEY_USERS\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{5BFEFF94-6411-4B74-A947-4969134B24DE} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\prefs.js:
Added to C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default
user.js not found
---- Lines valueApps removed from prefs.js ----
user_pref("valueApps.autoDisableScopes", 0);
---- Lines mybrowserbar removed from prefs.js ----
user_pref("extensions.vtools@mybrowserbar.com.install-event-fired", true);
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- Lines a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532 removed from prefs.js ----
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.active", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.addressbar", "NA");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.addressbarenhanced", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.asyncdb_dbWasSet", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.backgroundver", 1);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.certdomaininstaller", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.changeprevious", false);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie._GPL_aoi.value", "%221386793968%22");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie._GPL_parent_zoneid.expiration", "Fri Feb
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie._GPL_parent_zoneid.value", "%22345637%22"
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie._GPL_zoneid.value", "%22456211%22");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie.geo.expiration", "Wed Dec 18 2013 21:32:4
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie.geo.value", "%22DE%22");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie.InstallationTime.value", "%221386793458%2
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.description", "Feven Shopping Companion");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.domain", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.enablesearch", false);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.homepage", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.iframe", false);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.InstallationThankYouPage", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.InstallationTime", 1386793458);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb._country_code_.expiration", "Fri Feb
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb._country_code_.value", "%22DE%22");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.monetization_plugin_last_executable_r
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.monetization_plugin_last_executable_r
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_appVer.value", "70");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_nextCheck.expiration", "Fri
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.lastDailyReport", "1386917723748");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.lastUpdate", "1386917726442");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.manifesturl", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.name", "Feven 1.5");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.newtab", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.opensearch", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.pluginsurl", "https://w9u6a2p6.ssl.hwcdn.net/plu
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.pluginsversion", 67);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.publisher", "Feven");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.searchstatus", 0);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.setnewtab", false);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.thankyou", "");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.updateinterval", 360);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.38532.ver", 70);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.apps", "38532");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.bic", "13f624d4447e0b1cdd658fca7c4587f0");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.cid", 38532);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.firstrun", false);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.hadappinstalled", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.installationdate", 1386793544);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.modetype", "production");
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.reportInstall", true);
user_pref("extensions.a249911bcd1bd4d668c17df533609e6d8c76f3de9939e4922b73c5d7a3139375dcom38532.statsDailyCounter", 3);
---- Lines extensions.LOHi64S1y removed from prefs.js ----
user_pref("extensions.LOHi64S1y.epoch", "1401005967");
user_pref("extensions.LOHi64S1y.url", "hxxp://centergoodfind.info/sync2/?q=hfZ9ofDSBShEAen0rHC6tMqLDe49CNU0mwkMCMlNhd9FrHwGrTkGrTn9rHCMBzqUojw9rdkGqda
---- Lines extensions.N6yO5tA removed from prefs.js ----
user_pref("extensions.N6yO5tA.epoch", "1401005967");
user_pref("extensions.N6yO5tA.url", "hxxp://safefacile.net/sync2/?q=hfZ9oeDGDzrMCyVUojr6qGhTB6lKDzt4okmxtNtVh7n0rjrFrTs8rTs9rTnEtMFHhd9Fqda8rTnEpdsFrT
---- Lines extensions.tQmox removed from prefs.js ----
user_pref("extensions.tQmox.epoch", "1401005967");
---- FireFox user.js and prefs.js backups ----
prefs__1847_.backup
==== Deleting Files \ Folders ======================
C:\Users\Lars\AppData\LocalLow\{65B31E28-C534-5B46-55EB-9AAB46858685} deleted
C:\Users\Lars\AppData\Local\Packages\windows_ie_ac_001\AC\{65B31E28-C534-5B46-55EB-9AAB46858685} deleted
C:\PROGRA~3\DDJ_ASIO_Driver deleted
C:\Users\Lars\.android deleted
C:\PROGRA~3\InstallMate deleted
C:\Users\Lars\AppData\Local\cache deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Windows\Syswow64\InstallUtil.InstallLog deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted
"C:\PROGRA~3\9868df398bf17eec\{4820778D-AB0D-6D18-C316-52A6A0E1D507}" deleted
"C:\PROGRA~3\9868df398bf17eec\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}" deleted
"C:\PROGRA~3\9868df398bf17eec\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}.old" deleted
"C:\PROGRA~3\9868df398bf17eec\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}" deleted
"C:\PROGRA~3\9868df398bf17eec\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" deleted
"C:\PROGRA~3\9868df398bf17eec\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}.old" deleted
"C:\PROGRA~3\9868df398bf17eec\{CA41BB14-E67B-1653-C57B-5CA99418A866}" deleted
"C:\PROGRA~3\9868df398bf17eec\{E32743D3-5789-6E4F-3998-06FB87C9214B}" deleted
"C:\PROGRA~3\9868df398bf17eec" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"gacela2@nurago.com"="C:\Program Files (x86)\GfK Internet-Monitor" [28.05.2014 18:34]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [25.02.2013 19:27]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default
- GfK Internet-Monitor - C:\Program Files (x86)\GfK Internet-Monitor
- LastPass - %ProfilePath%\extensions\support@lastpass.com
- Flashblock - %ProfilePath%\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
- Personas Plus - %ProfilePath%\extensions\personas@christopher.beard.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Download Statusbar - %ProfilePath%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
- Tab Mix Plus - %ProfilePath%\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default
A58DE0A570148AF5FF3512B2A340D09F - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll - Shockwave Flash
855B79451ECF62602F20EB4D5C71F99B - C:\Windows\SysWoW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director
==== Chrome Look ======================
GfK Internet-Monitor - Lars\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekfcceehmjiicgpkeblpbcpglgdklklh
AdBlock - Lars\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
==== Chrome Fix ======================
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchsunmy.info_0.localstorage deleted successfully
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchsunmy.info_0.localstorage-journal deleted successfully
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_service.pricegong.com_0.localstorage-journal deleted successfully
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_govome.inspsearch.com_0.localstorage-journal deleted successfully
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Reset Google Chrome ======================
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyServer"="http=127.0.0.1:7777"
"ProxyOverride"="*.local"
"ProxyEnable"=dword:00000001
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2C86C44B-F929-3FEC-2B35-93EA97C0F10D} deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Lars\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Lars\AppData\Local\Mozilla\Firefox\Profiles\1ipdivd3.default\Cache will be emptied at reboot
C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\personas\cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=154 folders=32 5620989 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Lars\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Lars\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 28.05.2014 at 18:52:34,83 ======================
Schritt 3: Code:
Code:
HitmanPro 3.7.9.216
www.hitmanpro.com
Computer name . . . . : LARS-PC
Windows . . . . . . . : 6.1.1.7601.X64/4
User name . . . . . . : Lars-PC\Lars
UAC . . . . . . . . . : Disabled
License . . . . . . . : Trial (30 days left)
Scan date . . . . . . : 2014-05-28 19:01:29
Scan mode . . . . . . : Normal
Scan duration . . . . : 5m 56s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : Yes
Threats . . . . . . . : 0
Traces . . . . . . . : 75
Objects scanned . . . : 1.940.503
Files scanned . . . . : 56.691
Remnants scanned . . : 403.112 files / 1.480.700 keys
Suspicious files ____________________________________________________________
C:\Program Files (x86)\Stardock\Fences\DesktopDock.dll
Size . . . . . . . : 803.544 bytes
Age . . . . . . . : 178.3 days (2013-12-01 11:35:45)
Entropy . . . . . : 6.7
SHA-256 . . . . . : FA977C23B9FD2B429FB52145AB9558CE4087674C70ECC8998DC74D8EBBDF89A8
Publisher . . . . : Stardock
Description . . . : Stardock Fences
Version . . . . . : 2.0.1.0
Copyright . . . . : Copyright (C) 2008-2012 Stardock Corporation
RSA Key Size . . . : 2048
Authenticode . . . : Invalid
Fuzzy . . . . . . : 26.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
File belongs to an identified security risk.
C:\Program Files (x86)\Stardock\Fences\DesktopDock64.dll
Size . . . . . . . : 952.024 bytes
Age . . . . . . . : 178.3 days (2013-12-01 11:35:45)
Entropy . . . . . : 6.4
SHA-256 . . . . . : EFC38340D0F1574D8DC208D22E5615C451A51EA55F6A610099D7F8E998DF0A77
Publisher . . . . : Stardock
Description . . . : Stardock Fences
Version . . . . . : 2.0.1.0
Copyright . . . . : Copyright (C) 2008-2012 Stardock Corporation
RSA Key Size . . . : 2048
Authenticode . . . : Invalid
Fuzzy . . . . . . : 28.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
File belongs to an identified security risk.
The file is in use by one or more active processes.
C:\Program Files (x86)\Stardock\Fences\Fences.exe
Size . . . . . . . : 4.017.368 bytes
Age . . . . . . . : 178.3 days (2013-12-01 11:35:45)
Entropy . . . . . : 7.6
SHA-256 . . . . . : CD806CDABD6896D993D2A682FA5C92CD0467DD9403F201F835F8B0B59C2D5E2B
Product . . . . . : Fences
Publisher . . . . : Stardock Corporation
Description . . . : Fences Settings
Version . . . . . : 2.0.1.484
Copyright . . . . : Copyright © 2008-2012 Stardock Corporation
RSA Key Size . . . : 2048
Gossip . . . . . . : Fences
Authenticode . . . : Invalid
Fuzzy . . . . . . : 37.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Uses the Startup folder in the Start Menu to run each time the user logs on.
Uses the Windows Registry to run each time the user logs on.
Program starts automatically without user intervention.
Startup
C:\Users\Lars\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fences.lnk
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Fences
References
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock\Fences.lnk
C:\Users\Lars\Desktop\Customize Fences.lnk
C:\Users\Lars\Desktop\Purchase Fences.lnk
HKU\S-1-5-21-1005217006-152471606-131910131-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Program Files (x86)\Stardock\Fences\Fences.exe
C:\Program Files (x86)\Stardock\Fences\SDActivate.exe
Size . . . . . . . : 1.008.304 bytes
Age . . . . . . . : 178.3 days (2013-12-01 11:35:45)
Entropy . . . . . : 6.1
SHA-256 . . . . . : 9616ED807AAC0F3D9E7FF8D72CD1ABD6918F55F0A285B6DB09C7182F4AF160EB
Product . . . . . : Activate
Publisher . . . . : Stardock Corporation
Description . . . : Product Activation
Version . . . . . : 1.2.3.2
Copyright . . . . : Copyright (C) 2005-2011 Stardock Corporation
RSA Key Size . . . : 2048
Authenticode . . . : Invalid
Fuzzy . . . . . . : 26.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
File belongs to an identified security risk.
C:\Program Files (x86)\Stardock\Fences\sddlc.dll
Size . . . . . . . : 730.288 bytes
Age . . . . . . . : 178.3 days (2013-12-01 11:35:46)
Entropy . . . . . : 6.5
SHA-256 . . . . . : A2A0327CBF26AA391DC1FB551B7048663BB6E73896A02FFAC50EF0E0AD4F27B3
RSA Key Size . . . : 2048
Authenticode . . . : Invalid
Fuzzy . . . . . . : 32.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
File belongs to an identified security risk.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
C:\Program Files (x86)\Stardock\Fences\sddlc64.dll
Size . . . . . . . : 840.368 bytes
Age . . . . . . . : 178.3 days (2013-12-01 11:35:46)
Entropy . . . . . : 6.2
SHA-256 . . . . . : D9C45978637E1478888F7C6E165A2C150AD71A5FD88E8A1623E03F8C25614586
RSA Key Size . . . : 2048
Authenticode . . . : Invalid
Fuzzy . . . . . . : 32.0
Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
File belongs to an identified security risk.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
C:\Users\Lars\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
Size . . . . . . . : 3.145.536 bytes
Age . . . . . . . : 166.4 days (2013-12-13 10:11:22)
Entropy . . . . . : 6.6
SHA-256 . . . . . : DA2E76AFB6C0F0111CC5B3A83B331D2BCA54CC78C56128D2B90B86FC89E7EAA7
RSA Key Size . . . : 2048
Parent Name . . . : C:\Windows\system32\taskeng.exe
Authenticode . . . : Self-signed
Running processes : 1628
Fuzzy . . . . . . : 24.0
Program is code self-signed.
This program is actively listening for inbound network connections.
Uses the Windows Registry to run each time the user logs on.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Program starts automatically without user intervention.
The file is in use by one or more active processes.
Startup
HKU\S-1-5-21-1005217006-152471606-131910131-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Amazon Cloud Player
Network Ports
127.0.0.1:4750
Potential Unwanted Programs _________________________________________________
HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}\ (FLV Player) -> Deleted
HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}\ (FLV Player) -> Deleted
HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}\ (FLV Player) -> Deleted
HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}\ (FLV Player) -> Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964\ (FLV Player) -> Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467\ (FLV Player) -> Deleted
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026} (Iminent) -> Deleted
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5} (Iminent) -> Deleted
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A} (Iminent) -> Deleted
HKLM\SYSTEM\ControlSet001\services\eventlog\Application\IePluginService\ (FTDownloader) -> Deleted
HKLM\SYSTEM\ControlSet001\services\eventlog\Application\Wpm\ (FTDownloader) -> Deleted
HKLM\SYSTEM\ControlSet002\services\eventlog\Application\IePluginService\ (FTDownloader) -> Deleted
HKLM\SYSTEM\ControlSet002\services\eventlog\Application\Wpm\ (FTDownloader) -> Deleted
HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\IePluginService\ (FTDownloader) -> PendingDelete
HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Wpm\ (FTDownloader) -> PendingDelete
HKU\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\SnapDo.exe (FLV Player) -> Deleted
HKU\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\bProtectNewTabPageShow (22Find) -> Deleted
HKU\S-1-5-21-1005217006-152471606-131910131-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing\bProtectShowTabsWelcome (22Find) -> Deleted
Repairs _____________________________________________________________________
Proxyserver auf diesem Computer (Benutzer)
127.0.0.1:7777
Cookies _____________________________________________________________________
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:112.2o7.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:2o7.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.ad-srv.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.dyntracker.de
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.zanox.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.adk2.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.yahoo.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtechus.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:deutschepostag.112.2o7.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:emjcd.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:keygens.nl
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:smartadserver.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:statcounter.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:stats.paypal.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:statse.webtrendslive.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:survey.g.doubleclick.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.12trackway.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.360cpl.nl
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.adform.net
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:track.effiliation.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:tradedoubler.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.etracker.de
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com
C:\Users\Lars\AppData\Local\Google\Chrome\User Data\Default\Cookies:yadro.ru
C:\Users\Lars\AppData\Roaming\Mozilla\Firefox\Profiles\1ipdivd3.default\cookies.sqlite:doubleclick.net
Schritt 4: Code:
Results of screen317's Security Check version 0.99.83
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Microsoft Security Essentials
(On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
Windows Cleaner
Java(TM) 6 Update 24
Java version out of Date!
Adobe Flash Player 13.0.0.214
Adobe Reader 10.1.10 Adobe Reader out of Date!
Mozilla Firefox 25.0.1 Firefox out of Date!
Google Chrome 35.0.1916.114 ````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbam.exe
Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |