Vielen Dank Schrauber.
Ich war im Urlaub und konnte jetzt erst die logs erstellen Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 26.03.2015
Suchlauf-Zeit: 09:41:33
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.26.03
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: xxx
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 493687
Verstrichene Zeit: 10 Min, 48 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 39
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [e932e5652d5d2016242fd19117ec8c74],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [e932e5652d5d2016242fd19117ec8c74],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [b2691c2e3357f640435bafb33ec5659b],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [b2691c2e3357f640435bafb33ec5659b],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [4ccf99b10d7d54e2c98d00297093916f],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}, In Quarantäne, [d843c783533724122e264c16649f2ed2],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, In Quarantäne, [70abed5d93f7ca6c9e650d560bf828d8],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TypeLib\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, In Quarantäne, [ea3126241b6f979fe51e4a19dc27b64a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TypeLib\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, In Quarantäne, [8695ea60e4a6ab8b8b783e25b053669a],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, In Quarantäne, [60bbe466b3d71521bd7df9eb2ad9e11f],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [94876ae0107abf773d119a4834cf758b],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\mysearchdial.com, In Quarantäne, [bc5fdd6dbdcd1323c40bb6671ee739c7],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [e2391436aedc2c0a9495f6c25fa42cd4],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [30ebf6541377ad89fd50e200887b8878],
Registrierungswerte: 13
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{3004627E-F8E9-4E8B-909D-316753CBA923}, mysearchdial Toolbar, In Quarantäne, [e932e5652d5d2016242fd19117ec8c74]
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [48d3400a147660d6084b77ebb251ce32],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, In Quarantäne, [60bbe466b3d71521bd7df9eb2ad9e11f]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}|URL, hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=, In Quarantäne, [e2391436aedc2c0a9495f6c25fa42cd4]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}|TopResultURLFallback, hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=, In Quarantäne, [df3c9dadf298fd392efb595f6f9419e7]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}|FaviconURL, hxxp://start.mysearchdial.com/favicon.ico, In Quarantäne, [c4571733c6c452e444e5e0d8e023bb45]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}|FaviconPath, C:\Program Files (x86)\Mysearchdial\1.8.21.0\FavIcon.ico, In Quarantäne, [fb20ee5caedc0f279a8f437513f006fa]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}|FaviconURLFallback, hxxp://start.mysearchdial.com/favicon.ico, In Quarantäne, [c2597bcf2a601d1965c44672ba49d42c]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Mysearchdial, In Quarantäne, [e932400ad3b72a0cee3ba513e91a05fb]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}|DisplayName, Mysearchdial, In Quarantäne, [fd1e9baf95f572c4cc5d8830cf3417e9]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPDA921272-D426-4F17-B95D-6D0FE0E8D52B&q={searchTerms}&SSPV=, In Quarantäne, [0912a1a95634162003c0c8eac53e1de3]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|SuggestionsURL_JSON, hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [a576db6f2a603600794affb3c043b947]
PUP.Optional.Trovi.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|DisplayName, Trovi search, In Quarantäne, [66b562e86d1dc373c93d0646a95cee12]
Registrierungsdaten: 4
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=),Ersetzt,[78a3d872d3b78fa7c02bae48f80dfd03]
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|Tabs, hxxp://start.mysearchdial.com/?f=2&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=2&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=),Ersetzt,[0c0f68e23852fd39019807e6e322a15f]
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=),Ersetzt,[dc3f19315139c472ca215a9cee1734cc]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPDA921272-D426-4F17-B95D-6D0FE0E8D52B&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://search.conduit.com/?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SPDA921272-D426-4F17-B95D-6D0FE0E8D52B&SSPV=),Ersetzt,[0f0ccf7bec9e86b0b83098556b9ac23e]
Ordner: 8
PUP.Optional.NextLive.A, C:\Users\xxx\AppData\Roaming\newnext.me, In Quarantäne, [4fccad9dc4c62e084f1a86f2689b9967],
PUP.Optional.NextLive.A, C:\Users\xxx\AppData\Roaming\newnext.me\cache, In Quarantäne, [4fccad9dc4c62e084f1a86f2689b9967],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\UI, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SystemSpeedup, C:\Users\xxx\AppData\Roaming\Systweak\ssd, In Quarantäne, [6bb0e961bdcd57dfe88c8e00847fe917],
Dateien: 72
PUP.Optional.Trovi.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\searchplugins\trovi-search.xml, In Quarantäne, [110a084203877fb7580fb73808fb37c9],
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\searchplugins\Mysearchdial.xml, In Quarantäne, [b76492b80a8091a5bb3968944bb8827e],
PUP.Optional.MySpeedDial.A, C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, In Quarantäne, [15069fab46445bdb279f162221e439c7],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [6caf54f62862ee48c7b361df739237c9],
PUP.Optional.NextLive.A, C:\Users\xxx\AppData\Roaming\newnext.me\nengine.cookie, In Quarantäne, [4fccad9dc4c62e084f1a86f2689b9967],
PUP.Optional.NextLive.A, C:\Users\xxx\AppData\Roaming\newnext.me\cache\spark.bin, In Quarantäne, [4fccad9dc4c62e084f1a86f2689b9967],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SearchProtect.A, C:\Users\xxx\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [36e5d476becc2115a211a7e409faa65a],
PUP.Optional.SystemSpeedup, C:\Users\xxx\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [6bb0e961bdcd57dfe88c8e00847fe917],
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.aflt", "dnldstr");), Ersetzt,[d64571d91674bc7a1297d46151b57d83]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ences
/* Do not edit this file.
*
* If you make changes to this file while the), Ersetzt,[0c0fef5b3c4e989e47620a2bd135619f]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (e.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To mak), Ersetzt,[68b317335f2b48eec2e703325caa8f71]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (nning,
* the changes will be overwritten when t), Ersetzt,[948763e7cfbb79bdd1d850e5e620d42c]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (eferences
/* Do not edit this file.
*
* If you), Ersetzt,[8a912d1dc5c54aec8a1f62d332d49c64]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ences
/* Do not edit this file.
*
* If you), Ersetzt,[e6359ab0414993a37930c075d432fe02]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (eferences
/* Do not edit this file.
*
* If yo), Ersetzt,[75a673d7f09aa1959613260f8e7846ba]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If you), Ersetzt,[dc3f391121692313dccd9b9ada2cfb05]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("accessibility.typeaheadfind.flashBar", 0);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1426759264);
user_pref("app.update.lastUpdateTime.background-update-timer", 1426758904);
user_pref("app.update.lastUpdateTime.blocklist-background-update-timer", 1426759384);
user_pref("app.update.lastUpdateTime.browser-cleanup-thumbna), Ersetzt,[3ae155f52961f046eebb66cf8b7bcf31]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: ("app.update.lastUpdateTime.browser-cleanup-thumbnail), Ersetzt,[5dbee66415752e08c7e22e0755b1c937]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If you make changes to this file whi), Ersetzt,[75a6fd4dcbbfdb5be6c359dc996de818]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (s file.
*
* If you make changes to this file), Ersetzt,[879482c8e2a84aeca90052e33dc9ca36]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (references
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences,), Ersetzt,[44d7004a1278ef472188ed482fd71be5]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (
*
* To make a manual change to preferences, you can vis), Ersetzt,[7aa1c48604860c2a3277c96c9f67956b]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you make changes), Ersetzt,[1605282256343204c8e12d0874926a96]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you ma), Ersetzt,[cb50eb5f64267cba41683df819ed4cb4]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences,), Ersetzt,[e43747036426d75f7534fe371aec60a0]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (s.
*
* To make a manual change to preferences, you can visit the), Ersetzt,[ed2e0248abdf1c1a21882e079d6925db]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL), Ersetzt,[18034901850577bf9a0ffe370402eb15]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: ( *
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("accessibility.typeaheadfind.flashBar", 0);
user_pref("app.update.lastUpdateTime.addo), Ersetzt,[7ba0cd7dadddab8b32778ea77f877a86]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: ( overwritten when the application exits.
*
* To make a ), Ersetzt,[2dee7fcb0189181efcadce6762a453ad]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you make changes to t), Ersetzt,[f7247dcda6e4fa3c31784de848be9967]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you make c), Ersetzt,[34e7ee5c96f4ea4c9d0c0b2a86809d63]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (references
/* Do not edit this file.
*
* If you make cha), Ersetzt,[ec2ffa50f69473c3a10892a3f80eb54b]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (* Do not edit this file.
*
* If you make changes), Ersetzt,[f52657f3bfcbd26494153500050129d7]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can vi), Ersetzt,[d447e763cdbd0531208904318c7a38c8]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (* To make a manual change to preferences, you can visi), Ersetzt,[44d708421c6eac8a02a737fe8a7c6e92]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (nces
/* Do not edit this file.
*
* If you make c), Ersetzt,[96852d1d7b0f1e18a405da5b38ce7c84]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If you ), Ersetzt,[a4771733dbaf53e35e4b171e986e3dc3]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ences
/* Do not edit this file.
*
* If you make ), Ersetzt,[7c9fda70e6a4b6809d0c6ec718ee0cf4]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make changes to th), Ersetzt,[a873da700486a2949d0c72c38d79b24e]
PUP.Optional.Conduit.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SPDA921272-D426-4F17-B95D-6D0FE0E8D52B");), Ersetzt,[d546cd7d98f2c670ac4a7cb96d99f808]
PUP.Optional.MySearch.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.aflt", "dnldstr");), Ersetzt,[fd1ea3a787030531aaf869cc4bbb7987]
PUP.Optional.MySearch.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (.mysearchdial.hmpg", true);
user_pref("extensio), Ersetzt,[4bd06edc5634e056acf646ef6e98619f]
PUP.Optional.MySearch.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ons.mysearchdial.hmpg", true);
user_pref("extensio), Ersetzt,[26f5d6747f0b5fd7049e6dc84bbb06fa]
PUP.Optional.MySearch.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (.mysearchdial.hmpg", true);
user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtBy), Ersetzt,[d7442426652542f4dbc750e556b0718f]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpg", true);), Ersetzt,[ee2d4cfe8406e84ec1e93005f80eaa56]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (sions.mysearchdial.hmpg", true);
user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L), Ersetzt,[62b9133797f3f5419c0ec66f8a7c02fe]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1Czu), Ersetzt,[72a9b19987031e187931d65fcb3bcb35]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (s.mysearchdial.hmpg", true);
user_pref("extensions.mysearchdia), Ersetzt,[49d216344743979fcedcb3829d693dc3]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ial.hmpg", true);
user_pref("extensions.mysearchd), Ersetzt,[2af18bbf45455cda6149171e07ff3bc5]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ons.mysearchdial.hmpg", true);
user_pref("extensions), Ersetzt,[df3cd971503a2412941669cc6d99cd33]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (.mysearchdial.hmpg", true);
user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCy), Ersetzt,[60bb7ecc02889b9ba10921145caa14ec]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=");
user_pref("extensions.mysearchdial.dfltSrch", true);
user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
user_pref("extensions.mysearchdi), Ersetzt,[b4675eecc5c5092dfcae65d02adcef11]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=5), Ersetzt,[a774a2a87812ce686f3b9a9bbc4a16ea]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (chdial.hmpg", true);
user_pref("extensions.mysearchdia), Ersetzt,[7ba063e752388caa7a30d36291754fb1]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ysearchdial.hmpg", true);
user_pref("extensions.mysea), Ersetzt,[48d3103adfab79bd47634fe619edb848]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (mysearchdial.hmpg", true);
user_pref("extensions.mysea), Ersetzt,[46d5b9916d1d0f2746640a2bc046fa06]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ysearchdial.hmpg", true);
user_pref("extensions.mysearchdial.hmpg), Ersetzt,[fd1e23275f2b9b9b0e9cb481bd49e917]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (.hmpg", true);
user_pref("extensions.mysearchdial.hmpgUrl", ), Ersetzt,[2cef9cae5b2ff343971349ecbe4837c9]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (hdial.hmpg", true);
user_pref("extensions.mysearchdial.hmp), Ersetzt,[5ac1ea60fb8ff93d0d9d87aed2349c64]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (rchdial.hmpg", true);
user_pref("extensions.mysearch), Ersetzt,[d14ab694a8e2082efdad9e97c1456c94]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (.mysearchdial.hmpg", true);
user_pref("extensions.myse), Ersetzt,[f6258dbdbdcd51e5604a90a59a6c946c]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ysearchdial.hmpg", true);
user_pref("extensions.mys), Ersetzt,[d14a5cee99f11a1c0aa033021de97987]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (s.mysearchdial.hmpg", true);
user_pref("extension), Ersetzt,[7ba0f05a9af063d3c6e43500ef17a957]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ons.mysearchdial.hmpg", true);
user_pref("extens), Ersetzt,[d546b79398f2c670acfeff367f87dd23]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (ions.mysearchdial.hmpg", true);
user_pref("extensions.mysearchdial.hmpgUrl", "http:/), Ersetzt,[b863e268beccd1653c6e3ff65ea860a0]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (r_pref("extensions.mysearchdial.hmpgUrl", "hxxp://st), Ersetzt,[21fad67436548caad8d286af44c27c84]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (.mysearchdial.hmpg", true);
user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCy), Ersetzt,[cf4c84c64446b28449610332e323c53b]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=");), Ersetzt,[2eed69e1642679bd6447ae8747bf04fc]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: ("Mysearchdial");
user_pref("extensions.mysearchdial.dnsErr", true);
user_pref("extensions.mysearchdial_i.newTab", false);
user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dnldstr&cd=2XzuyEt), Ersetzt,[f2295eeca8e22115ebc084b164a2837d]
PUP.Optional.MySearchDial.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js, Gut: (), Schlecht: (Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=501369256&ir=");
user_pref("extensions.mysearchdial.dfltSrch", true);
user_pref("extensions.mysearchdial.srchPrvdr", "Mysear), Ersetzt,[49d24307fb8fd1654863ef4656b0a858]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.113 - Bericht erstellt 26/03/2015 um 10:14:26
# Aktualisiert 22/03/2015 von Xplode
# Datenbank : 2015-03-23.1 [Server]
# Betriebssystem : Windows 7 Professional Service Pack 1 (x64)
# Benutzername : xxx - PETER2
# Gestarted von : C:\Users\xxx\Desktop\AdwCleaner_4.113.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : wStLib64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\wangjihua\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\wangzhisong\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\xxx\AppData\Local\genienext
Ordner Gelöscht : C:\Users\xxx\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\xxx\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\xxx\AppData\Roaming\Systweak
Datei Gelöscht : C:\Users\xxx\Favorites\Startfenster.lnk
Datei Gelöscht : C:\Users\xxx\Favorites\Links\Startfenster.lnk
Datei Gelöscht : C:\Windows\apppatch\apppatch64\vcldr64.dll
Datei Gelöscht : C:\Windows\AppPatch\nbin\VC32Loader.dll
Datei Gelöscht : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\xxx\daemonprocess.txt
Datei Gelöscht : C:\Users\xxx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk
Datei Gelöscht : C:\Users\xxx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk
Datei Gelöscht : C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Datei Gelöscht : C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : avayvaxvaa
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4ED063C9-4A0B-4B44-A9DC-23AFF424A0D3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E74373-58AB-47EB-B0F0-A1D82BB8EB5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F506250D-5B79-4BF6-B68C-E9702440A878}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F506250D-5B79-4BF6-B68C-E9702440A878}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\UpdateStar
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\SPPDCOM
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v36.0.4 (x86 de)
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SPDA921272-D426-4F17-B95D-6D0FE0E8D52B");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.cliqz.session", "ewkr8PB2fkkENIl9G4xVNx9vWpcuBkFZIgGM/HzOoqIPzPWMJkNbOJtTnzmfB4b6");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.aflt", "dnldstr");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.cr", "501369256");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.instlRef", "");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.aflt", "dnldstr");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cntry", "DE");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cr", "501369256");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hdrMd5", "EA98FBD29D1CA362A5F8C8744B6461C4");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD[...]
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.id", "002421264EC717C0");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.instlDay", "16042");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.instlRef", "");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B[...]
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.21.013:39:32");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutC[...]
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"89\",\"lastVrsn\":\"89\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.sg", "none");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtN0D0Tzu0SyBtDtAtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1Czu[...]
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.013:39:32");
[tsav4vvw.default\prefs.js] - Zeile Gelöscht : user_pref("extensionsns.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldstr&cd=2XzuyEtN2Y1L1QzutDtDtByEtBtCtByCyE0E0CyBtCyB0CtDtNtCyD1B1P1R&cr=501369256&ir=");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [8983 Bytes] - [26/03/2015 10:12:20]
AdwCleaner[S0].txt - [8761 Bytes] - [26/03/2015 10:14:26]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8820 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.6 (03.22.2015:1)
OS: Windows 7 Professional x64
Ran by xxx on 26.03.2015 at 10:23:27,11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\xxx\AppData\Roaming\mozilla\firefox\profiles\tsav4vvw.default\minidumps [69 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.03.2015 at 10:26:42,33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by xxx (administrator) on PETER2 on 26-03-2015 10:28:28
Running from C:\Users\xxx\Desktop
Loaded Profiles: xxx & UpdatusUser & NeroMediaHomeUser.4 (Available profiles: xxx & UpdatusUser & NeroMediaHomeUser.4)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Audible, Inc.) C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-25] (CANON INC.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Nero MediaHome 4] => C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe [5178664 2010-10-26] (Nero AG)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1213848 2010-09-14] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2010-09-09] (CANON INC.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\...\Run: [Nero MediaHome 4] => C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe [5178664 2010-10-26] (Nero AG)
HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-14] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Audible Download Manager.lnk
ShortcutTarget: Audible Download Manager.lnk -> C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe (Audible, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2322022785-3556793067-1154166016-1000 -> URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPDA921272-D426-4F17-B95D-6D0FE0E8D52B&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-2322022785-3556793067-1154166016-1000 -> SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKU\S-1-5-21-2322022785-3556793067-1154166016-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2322022785-3556793067-1154166016-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default
FF SearchEngineOrder.1: SuchMaschine
FF SelectedSearchEngine: Google
FF Homepage: https://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-08] ()
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-28] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-08] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-14] (CANON INC.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2013-09-17] (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-11-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-11-11] (NVIDIA Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll [2011-01-22] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll [2014-06-26] (pdfforge GmbH)
FF SearchPlugin: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\searchplugins\google-images.xml [2014-08-31]
FF SearchPlugin: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\searchplugins\google-maps.xml [2014-08-31]
FF SearchPlugin: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\searchplugins\otrkeyfindercom.xml [2013-12-11]
FF SearchPlugin: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\searchplugins\search_engine.xml [2013-12-03]
FF Extension: Avira Browser Safety - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\Extensions\abs@avira.com [2015-03-09]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-09-19]
FF HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\tsav4vvw.default\extensions\cliqz@cliqz.com
FF HKU\S-1-5-21-2322022785-3556793067-1154166016-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR Profile: C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-19] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [992560 2015-03-19] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-20] (Hewlett-Packard Co.) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 NeroMediaHomeService.4; C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe [517416 2010-10-26] (Nero AG)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-03-05] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-22] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [44088 2015-03-05] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
S3 ALSysIO; \??\C:\Users\xxx\AppData\Local\Temp\ALSysIO64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-26 10:26 - 2015-03-26 10:27 - 00000753 _____ () C:\Users\xxx\Desktop\JRT.txt
2015-03-26 10:20 - 2015-03-26 10:21 - 01388782 _____ (Thisisu) C:\Users\xxx\Desktop\JRT.exe
2015-03-26 10:18 - 2015-03-26 10:18 - 00008904 _____ () C:\Users\xxx\Desktop\AdwCleaner[S0].txt
2015-03-26 10:11 - 2015-03-26 10:14 - 00000000 ____D () C:\AdwCleaner
2015-03-26 10:10 - 2015-03-26 10:10 - 02168320 _____ () C:\Users\xxx\Desktop\AdwCleaner_4.113.exe
2015-03-26 10:10 - 2015-03-26 10:10 - 00033223 _____ () C:\Users\xxx\Desktop\mbam.txt
2015-03-26 10:00 - 2015-03-26 10:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-26 09:41 - 2015-03-26 10:08 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-26 09:40 - 2015-03-26 09:40 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-26 09:40 - 2015-03-26 09:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-26 09:40 - 2015-03-26 09:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-26 09:40 - 2015-03-26 09:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-26 09:40 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-26 09:40 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-26 09:40 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-19 11:03 - 2015-03-19 11:03 - 00050733 _____ () C:\Users\xxx\Desktop\FRST neu.txt
2015-03-17 13:44 - 2015-03-17 13:44 - 00025262 _____ () C:\Users\xxx\Desktop\combofix.txt
2015-03-17 13:43 - 2015-03-17 13:43 - 00025262 _____ () C:\ComboFix.txt
2015-03-17 13:28 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-17 13:28 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-17 13:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-17 13:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-17 13:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-17 13:28 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-17 13:28 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-17 13:28 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-17 13:27 - 2015-03-17 13:43 - 00000000 ____D () C:\Qoobox
2015-03-17 13:27 - 2015-03-17 13:42 - 00000000 ____D () C:\Windows\erdnt
2015-03-17 13:27 - 2015-03-17 13:27 - 05615380 ____R (Swearware) C:\Users\xxx\Desktop\ComboFix.exe
2015-03-17 13:24 - 2015-03-17 13:24 - 00001268 _____ () C:\Users\xxx\Desktop\Revo Uninstaller.lnk
2015-03-17 13:24 - 2015-03-17 13:24 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-17 13:22 - 2015-03-17 13:22 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\xxx\Desktop\revosetup95.exe
2015-03-14 20:45 - 2015-03-14 21:17 - 2946552780 _____ () C:\Users\xxx\Desktop\Let_s_Dance_15.03.13_20-15_rtl_225_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-13 21:24 - 2015-03-13 21:42 - 1661513896 _____ () C:\Users\xxx\Desktop\Germany_s_next_Topmodel_____by_Heidi_Klum_15.03.12_20-15_pro7_135_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-13 17:50 - 2015-03-13 17:50 - 00471840 _____ () C:\Windows\Minidump\031315-23484-01.dmp
2015-03-13 17:37 - 2015-03-13 17:37 - 00009285 _____ () C:\Users\xxx\Desktop\gmer.log
2015-03-13 17:26 - 2015-03-13 17:27 - 00023244 _____ () C:\Users\xxx\Desktop\Addition.txt
2015-03-13 17:24 - 2015-03-26 10:28 - 00015585 _____ () C:\Users\xxx\Desktop\FRST.txt
2015-03-13 17:24 - 2015-03-26 10:28 - 00000000 ____D () C:\FRST
2015-03-13 17:17 - 2015-03-13 17:23 - 00000468 _____ () C:\Users\xxx\Desktop\defogger_disable.log
2015-03-13 17:17 - 2015-03-13 17:17 - 00000000 _____ () C:\Users\xxx\defogger_reenable
2015-03-13 17:15 - 2015-03-13 17:15 - 00380416 _____ () C:\Users\xxx\Desktop\Gmer-19357.exe
2015-03-13 17:14 - 2015-03-13 17:15 - 02095616 _____ (Farbar) C:\Users\xxx\Desktop\FRST64.exe
2015-03-13 17:06 - 2015-03-13 17:06 - 00050477 _____ () C:\Users\xxx\Desktop\Defogger.exe
2015-03-12 23:35 - 2015-03-12 23:35 - 00021976 _____ () C:\Windows\system32\Drivers\SPPD.sys
2015-03-12 20:56 - 2015-03-12 21:05 - 640254080 _____ () C:\Users\xxx\Desktop\Der_Bachelor_____Das_grosse_Finale_15.03.11_20-15_rtl_60_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-11 23:54 - 2015-03-12 00:08 - 1371388716 _____ () C:\Users\xxx\Desktop\Fruehling_im_Herbst_12.10.10_21-45_bay3_90_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-10 20:27 - 2015-02-20 05:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-10 20:27 - 2015-02-20 05:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-10 20:27 - 2015-02-20 05:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-10 20:27 - 2015-02-20 05:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-10 20:27 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-10 20:27 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-10 20:27 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-10 20:27 - 2015-02-20 05:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-10 20:27 - 2015-02-20 04:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-10 20:27 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-10 20:27 - 2015-02-03 04:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-10 20:27 - 2015-02-03 04:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-03-10 20:27 - 2015-02-03 04:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-10 20:27 - 2015-02-03 04:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-03-10 20:27 - 2015-02-03 04:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-10 20:27 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-10 20:27 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-10 20:27 - 2015-02-03 04:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-10 20:27 - 2015-02-03 04:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-10 20:27 - 2015-02-03 04:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-10 20:27 - 2015-02-03 04:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-10 20:27 - 2015-02-03 04:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-10 20:27 - 2015-02-03 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-10 20:27 - 2015-02-03 04:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-10 20:27 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-10 20:27 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-03-10 20:27 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-03-10 20:27 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-03-10 20:27 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-03-10 20:27 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-03-10 20:27 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-03-10 20:27 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-03-10 20:27 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-03-10 20:27 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-03-10 20:27 - 2015-02-03 03:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-10 20:27 - 2014-10-31 23:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-10 20:27 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-10 20:27 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-10 20:26 - 2015-03-06 06:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-10 20:26 - 2015-03-06 06:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-10 20:26 - 2015-03-06 06:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-10 20:26 - 2015-03-06 06:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-10 20:26 - 2015-03-06 06:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-10 20:26 - 2015-03-06 06:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-10 20:26 - 2015-03-06 06:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-10 20:26 - 2015-03-06 06:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-10 20:26 - 2015-03-06 06:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-03-10 20:26 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-03-10 20:26 - 2015-03-06 06:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-03-10 20:26 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-03-10 20:26 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-03-10 20:26 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-03-10 20:26 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-03-10 20:26 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-10 20:26 - 2015-02-13 06:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-10 20:26 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-10 20:26 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-03-10 20:26 - 2015-01-31 00:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-10 20:25 - 2015-02-26 04:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-10 20:25 - 2015-02-03 04:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-10 20:25 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-10 20:25 - 2015-01-17 03:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-10 20:25 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-10 20:24 - 2015-02-24 04:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-10 20:24 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-03-10 20:24 - 2015-02-21 02:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-10 20:24 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-10 20:24 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-03-10 20:24 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-10 20:24 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-10 20:24 - 2015-02-21 00:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-10 20:24 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-10 20:24 - 2015-02-20 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-10 20:24 - 2015-02-20 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-10 20:24 - 2015-02-20 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-10 20:24 - 2015-02-20 03:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-10 20:24 - 2015-02-20 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-10 20:24 - 2015-02-20 03:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-10 20:24 - 2015-02-20 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-10 20:24 - 2015-02-20 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-10 20:24 - 2015-02-20 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-10 20:24 - 2015-02-20 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-10 20:24 - 2015-02-20 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-10 20:24 - 2015-02-20 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-10 20:24 - 2015-02-20 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-10 20:24 - 2015-02-20 03:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-10 20:24 - 2015-02-20 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-10 20:24 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-03-10 20:24 - 2015-02-20 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-10 20:24 - 2015-02-20 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-10 20:24 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-10 20:24 - 2015-02-20 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-10 20:24 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-03-10 20:24 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-10 20:24 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-10 20:24 - 2015-02-20 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-10 20:24 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-10 20:24 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-03-10 20:24 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-03-10 20:24 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-03-10 20:24 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-03-10 20:24 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-03-10 20:24 - 2015-02-20 02:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-10 20:24 - 2015-02-20 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-10 20:24 - 2015-02-20 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-10 20:24 - 2015-02-20 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-10 20:24 - 2015-02-20 02:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-10 20:24 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-10 20:24 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-03-10 20:24 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-10 20:24 - 2015-02-20 02:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-10 20:24 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-10 20:24 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-10 20:24 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-10 20:24 - 2015-02-20 02:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-10 20:24 - 2015-02-20 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-10 20:24 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-10 20:24 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-10 20:24 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-10 20:24 - 2015-02-04 04:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-10 20:24 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-09 18:35 - 2015-03-09 19:10 - 1311623334 _____ () C:\Users\xxx\Desktop\Fruehling_im_Herbst_15.03.07_20-15_bay3_90_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-09 18:35 - 2015-03-09 19:06 - 1281478152 _____ () C:\Users\xxx\Desktop\Pitch_Perfect_15.03.08_20-15_rtl_135_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-09 18:35 - 2015-03-09 18:56 - 2164462680 _____ () C:\Users\xxx\Desktop\Utta_Danella_Ploetzlich_ist_es_Liebe_14.06.29_15-00_ard_90_TVOON_DE.mpg.HD.avi.otrkey
2015-03-09 12:53 - 2015-03-09 13:34 - 535696166 _____ () C:\Users\xxx\Desktop\Project_X_15.03.08_22-00_rtl2_105_TVOON_DE.mpg.mp4.otrkey
2015-03-09 12:53 - 2015-03-09 13:23 - 300341393 _____ () C:\Users\xxx\Desktop\Slither_____Voll_auf_den_Schleim_gegangen_15.03.07_01-20_rtl2_90_TVOON_DE.mpg.mp4.otrkey
2015-03-09 12:40 - 2015-03-09 13:47 - 1098308102 _____ () C:\Users\xxx\Desktop\Entscheidung_in_den_Wolken_15.03.08_18-30_sat1gold_105_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-09 12:38 - 2015-03-09 13:29 - 924431624 _____ () C:\Users\xxx\Desktop\Heiter_bis_Wolkig_15.03.07_20-15_sixx_110_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-09 12:34 - 2015-03-09 13:39 - 1095361824 _____ () C:\Users\xxx\Desktop\Eine_Liebe_in_St__Petersburg_15.03.07_14-30_ard_90_TVOON_DE.mpg.HQ.avi.otrkey
2015-03-09 12:31 - 2015-03-09 12:38 - 415151798 _____ () C:\Users\xxx\Desktop\Terminator_Die_Erloesung_15.03.08_22-10_pro7_130_TVOON_DE.mpg.mp4.otrkey
2015-03-07 20:33 - 2015-03-07 20:33 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2015-03-05 14:48 - 2015-03-07 20:44 - 00000000 ____D () C:\Users\xxx\Documents\Elterngeld Famzuschlag
2015-02-26 15:14 - 2015-02-26 15:14 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2015-02-26 00:22 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-26 00:22 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-26 10:23 - 2013-11-27 11:41 - 01988585 _____ () C:\Windows\WindowsUpdate.log
2015-03-26 10:22 - 2009-07-14 05:45 - 00031280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-26 10:22 - 2009-07-14 05:45 - 00031280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-26 10:17 - 2014-01-04 20:16 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-26 10:17 - 2014-01-04 20:15 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-26 10:16 - 2013-11-27 13:35 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-26 10:16 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-26 10:16 - 2009-07-14 05:51 - 00107233 _____ () C:\Windows\setupact.log
2015-03-26 10:15 - 2013-11-27 19:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-26 10:15 - 2010-11-21 04:47 - 00196702 _____ () C:\Windows\PFRO.log
2015-03-26 10:14 - 2013-11-27 12:02 - 00000000 ____D () C:\Users\xxx
2015-03-26 09:38 - 2013-12-03 18:18 - 00000000 ____D () C:\Users\xxx\AppData\Roaming\vlc
2015-03-17 13:38 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-17 10:43 - 2014-01-02 18:58 - 00000000 ____D () C:\Users\xxx\Documents\Conti
2015-03-13 17:50 - 2013-11-27 19:51 - 00000000 ____D () C:\Windows\Minidump
2015-03-13 17:49 - 2013-11-27 19:51 - 484940460 _____ () C:\Windows\MEMORY.DMP
2015-03-12 21:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-03-11 18:06 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-03-11 18:03 - 2009-07-14 05:45 - 00358176 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-11 18:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-03-11 18:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-03-11 00:42 - 2014-03-12 16:18 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-11 00:40 - 2014-03-12 16:18 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-10 21:29 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-03-07 20:33 - 2015-02-10 22:56 - 00000000 ____D () C:\Users\xxx\AppData\Roaming\Canon
2015-03-05 14:18 - 2013-11-28 13:01 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-03-05 14:18 - 2013-11-28 13:01 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-03-05 14:18 - 2013-11-28 13:01 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-03-02 22:17 - 2013-11-27 20:36 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2015-03-02 22:17 - 2013-11-27 20:36 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2015-03-02 22:17 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-01 23:22 - 2014-05-21 21:14 - 00000000 ____D () C:\Users\xxx\AppData\Roaming\BOM
2015-03-01 18:59 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-24 04:17 - 2010-11-21 04:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2014-04-17 12:16 - 2014-04-17 12:16 - 0000624 _____ () C:\Users\xxx\AppData\Roaming\All CPU MeterV3_Settings.ini
2013-12-18 21:39 - 2014-07-19 16:40 - 0000160 _____ () C:\Users\xxx\AppData\Roaming\WB.CFG
2013-12-12 16:16 - 2013-12-12 16:16 - 0000000 _____ () C:\Users\xxx\AppData\Local\{B1541876-83C4-42ED-9536-8C3A136B4F2E}
2014-09-19 22:59 - 2015-01-03 19:53 - 0002215 _____ () C:\ProgramData\hpzinstall.log
Some content of TEMP:
====================
C:\Users\xxx\AppData\Local\Temp\avgnt.exe
C:\Users\xxx\AppData\Local\Temp\Quarantine.exe
C:\Users\xxx\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-15 20:05
==================== End Of Log ============================ --- --- --- |