beatle1931 | 09.04.2014 19:26 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 09.04.2014
Suchlauf-Zeit: 19:24:36
Logdatei: ProtokollMBAM.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.09.06
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Christina
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 296832
Verstrichene Zeit: 34 Min, 14 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 33
PUP.Optional.SpeedAnalysis3.A, HKLM\SOFTWARE\CLASSES\APPID\{562B9316-C08A-444A-9482-62080DD851AE}, In Quarantäne, [11ef67994fb199678f02da6b09f960a0],
PUP.Optional.SpeedAnalysis3.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{562B9316-C08A-444A-9482-62080DD851AE}, In Quarantäne, [11ef67994fb199678f02da6b09f960a0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [8977ae528c74ba4606bae8260ef41ee2],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2510955137-3378100727-651192638-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [8977ae528c74ba4606bae8260ef41ee2],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2510955137-3378100727-651192638-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [8977ae528c74ba4606bae8260ef41ee2],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane.1, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane.1, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2510955137-3378100727-651192638-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2510955137-3378100727-651192638-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [e51bca36956b18e8e9738eb7f111c937],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [000023dd966a827e461757eea26057a9],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc, In Quarantäne, [bc4434cca35dc33d135cda8adb27946c],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1, In Quarantäne, [cc3406fa8779798781eebba9ce343bc5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [3dc3aa56ba46eb15877f42327b87fe02],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc, In Quarantäne, [06faee1215eb35cb90dfa0c40bf7dd23],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1, In Quarantäne, [be42de2212ee22decaa590d4669c8e72],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\elchiiiejkobdbblfejjkbphbddgmljf, In Quarantäne, [14ec0ff1f907c73984eefb69729040c0],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\Softonic, In Quarantäne, [619f9d638e72cd337ff4ed77c63cc63a],
PUP.Optional.Iminent.A, HKU\S-1-5-21-2510955137-3378100727-651192638-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, In Quarantäne, [4ab6c53b6f919e6234d3c2b2a65c4bb5],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2510955137-3378100727-651192638-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Softonic, In Quarantäne, [e818a35dc63a8977cba5bea6f90904fc],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
Registrierungswerte: 2
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Softonic Toolbar, In Quarantäne, [8977ae528c74ba4606bae8260ef41ee2]
PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [4eb230d00cf433cd1ea2db330002e31d],
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 6
PUP.Optional.OpenCandy, C:\Users\Christina\AppData\Roaming\OpenCandy, In Quarantäne, [1ce4ef11a25ea45c2d95a8af699910f0],
PUP.Optional.OpenCandy, C:\Users\Christina\AppData\Roaming\OpenCandy\6C28965F250E4B4FBB35D43002B81BCC, In Quarantäne, [1ce4ef11a25ea45c2d95a8af699910f0],
PUP.Optional.OpenCandy, C:\Users\Christina\AppData\Roaming\OpenCandy\B960D93A4D11410486700ECB4060070A, In Quarantäne, [1ce4ef11a25ea45c2d95a8af699910f0],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
Dateien: 36
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicTlbr.dll, In Quarantäne, [8977ae528c74ba4606bae8260ef41ee2],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\bh\Softonic.dll, In Quarantäne, [827ef20e7090f10f3c85e42a22e0b24e],
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\OpenCandy\B960D93A4D11410486700ECB4060070A\Setupsft_chr_p1v5.exe, In Quarantäne, [7a86ba46b9475ca414d5b88458a89b65],
PUP.Optional.OpenCandy, C:\Users\Christina\Desktop\PhotoScape_V3-6-5.exe, In Quarantäne, [27d9f10fef11718f9c7244fa4eb6c739],
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\softonic.xml, In Quarantäne, [6e92dd23ad5311ef9fce87dded158c74],
PUP.Optional.OpenCandy, C:\Users\Christina\AppData\Roaming\OpenCandy\6C28965F250E4B4FBB35D43002B81BCC\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [1ce4ef11a25ea45c2d95a8af699910f0],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\softonic.crx, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicApp.dll, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\SoftonicEng.dll, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\Softonic\1.8.21.14\Softonicsrv.exe, In Quarantäne, [c53bb34de31dbc446937322dc73b5ca4],
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.admin", false);), Ersetzt,[be427a86eb156d934528c77e32d22cd4]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.aflt", "OC");), Ersetzt,[8d732cd48c748a760865b392ce366e92]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");), Ersetzt,[dc24c937b24e1ee268057cc9bb493dc3]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.autoRvrt", "false");), Ersetzt,[cd338b753ac6f709620bac99bd478c74]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltLng", "de");), Ersetzt,[e61aa759fa0618e86ffedf66f90b0ff1]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dfltSrch", true);), Ersetzt,[2bd535cb728ee8180e5f88bda85c639d]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.dnsErr", true);), Ersetzt,[956b639dbf416c942c418cb9b0543fc1]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.excTlbr", false);), Ersetzt,[b64ad03052aeac540f5ecb7a49bb23dd]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.ffxUnstlRst", false);), Ersetzt,[0cf49769be4207f9bab3da6b39cb8e72]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpg", true);), Ersetzt,[738d6799728e34ccaebfe75ebc48d12f]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=ee28e09d00000000000018f46abeb640");), Ersetzt,[ff0125dbe8182ed2323bd66fc3415aa6]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.id", "ee28e09d00000000000018f46abeb640");), Ersetzt,[d52b629e3ec223dd125b86bfab5922de]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlDay", "15997");), Ersetzt,[3bc5af5125dbbf41402dc58006fe7b85]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.instlRef", "MOY00621");), Ersetzt,[b74929d7e41c897781eceb5a9a6a9868]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTab", true);), Ersetzt,[ed13b94729d7ff011954f74ec143f40c]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=ee28e09d00000000000018f46abeb640");), Ersetzt,[37c9ce32659bca3696d7d07582824ab6]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prdct", "Softonic");), Ersetzt,[887841bf16ea8a760c614df8a163aa56]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.prtnrId", "softonic");), Ersetzt,[1de3d9273ec248b8abc2fe4794708977]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.rvrt", "false");), Ersetzt,[699710f0847c38c816573213768e58a8]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.smplGrp", "none");), Ersetzt,[907037c9a060bf41e885be87b84c0000]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");), Ersetzt,[7b8512ee0cf4be4286e7380dc83c49b7]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrId", "opencandy2013");), Ersetzt,[fe026f919b655ba5501dc085fa0a6799]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=ee28e09d00000000000018f46abeb640&q=");), Ersetzt,[f9076a9652aed52b93da0b3a3acac937]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsn", "1.8.21.14");), Ersetzt,[e51bbb4522deff016d00c5807193f20e]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsnTs", "1.8.21.147:56:59");), Ersetzt,[05fb4ab627d9d22e4825420340c443bd]
PUP.Optional.Softonic.A, C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.vrsni", "1.8.21.14");), Ersetzt,[01ff9d63e0201fe15d10c97cbf452bd5]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 09/04/2014 um 19:37:36
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Christina - CHRISTINA-PC
# Gestartet von : C:\Users\Christina\Desktop\adwcleaner (1).exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : AddonsHelper
Dienst Gelöscht : SearchAnonymizer
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\DNSErrorHelper
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\myfree codec
Ordner Gelöscht : C:\Program Files (x86)\pc speed up
Ordner Gelöscht : C:\Program Files (x86)\Softonic
Ordner Gelöscht : C:\Users\Christina\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\Christina\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\Christina\AppData\Roaming\HELPER
Ordner Gelöscht : C:\Users\Christina\AppData\Roaming\OCS
Datei Gelöscht : C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [dnshelp@dnshelp.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{721061FB-EB79-4568-A03C-3CE26D68DAE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{721061FB-EB79-4568-A03C-3CE26D68DAE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DesktopIconAmazon
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAnonymizer
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\prefs.js ]
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.firetab.org/?type=ds3hp");
Zeile gelöscht : user_pref("iminent.LayoutId", "1");
Zeile gelöscht : user_pref("iminent.ShowThankyouPixel", "0");
Zeile gelöscht : user_pref("iminent.adapters", "{\"adobe\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":2,\"expireTime\":\"1385538424233223713\"},\"allein-erziehend\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"St[...]
Zeile gelöscht : user_pref("iminent.registerToolbarEvent101", "1385460457282");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent102", "1385493051465");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent109", "1385538445369");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent110", "1385538480015");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent111", "1385538445377");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent112", "1385538447070");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent122", "1385538445386");
Zeile gelöscht : user_pref("iminent.registerToolbarEvent140", "1385381880569");
Zeile gelöscht : user_pref("iminent.version", "7.41.2.1");
Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.41.2.1\",\"InstallEventCTime\":1385538344858,\"InstallEvent\":\"True\"}");
*************************
AdwCleaner[R0].txt - [24706 octets] - [07/04/2014 17:54:07]
AdwCleaner[R1].txt - [24678 octets] - [07/04/2014 17:55:54]
AdwCleaner[R2].txt - [24828 octets] - [07/04/2014 18:42:18]
AdwCleaner[R3].txt - [18730 octets] - [09/04/2014 19:36:29]
AdwCleaner[S0].txt - [18030 octets] - [09/04/2014 19:37:36]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18091 octets] ##########
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 27 days old and could be outdated)
Ran by Christina (administrator) on CHRISTINA-PC on 09-04-2014 20:21:36
Running from C:\Users\Christina\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Common Files\Citrix\System32\CdfSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Streaming Client\RadeHlprSvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(PC Tools) C:\Program Files (x86)\ThreatFire\TFService.exe
(Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Streaming Client\RadeSvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
() C:\Windows\PLFSetI.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(CANON INC.) C:\Windows\System32\spool\drivers\x64\3\CNAP2LAK.EXE
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2RPK.EXE
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.313\SSScheduler.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(CANON INC.) C:\Windows\system32\spool\DRIVERS\x64\3\CNAB8SWK.EXE
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(PC Tools) C:\Program Files (x86)\ThreatFire\TFTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\Christina\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
() C:\Program Files (x86)\Opera\20.0.1387.91\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Opera Software) C:\Program Files (x86)\Opera\20.0.1387.91\opera.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11444840 2010-09-21] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [206208 2010-06-09] ()
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated)
HKLM\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\ootag.exe [13856 2010-02-23] (Microsoft)
HKLM\...\Run: [CNAP2 Launcher] - C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [406944 2007-09-06] (CANON INC.)
HKLM\...\Run: [Ocs_SM] - C:\Users\Christina\AppData\Roaming\OCS\SM\SearchAnonymizer.exe
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] ()
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-11-19] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [ThreatFire] - C:\Program Files (x86)\ThreatFire\TFTray.exe [378128 2010-01-14] (PC Tools)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [] - [X]
HKLM-x32\...\Run: [TkBellExe] - c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-06-17] (RealNetworks, Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-08] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2510955137-3378100727-651192638-1000\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKU\S-1-5-21-2510955137-3378100727-651192638-1000\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2510955137-3378100727-651192638-1003\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
Startup: C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Christina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
ProxyServer: :0
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKCU - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0E1B9354-DE9C-49C1-A7E4-35F8FFC2BCDF} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=2e2fd145-1170-471c-a5eb-8304995ba79b&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {A937348E-FC02-4D03-B0D6-501FC7AD6986} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=2e2fd145-1170-471c-a5eb-8304995ba79b&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {C2B5555E-F1C5-4899-A3CC-3A9B227EC623} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=2e2fd145-1170-471c-a5eb-8304995ba79b&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {D1F249D2-F019-42B8-88BB-AB41F28758C8} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=2e2fd145-1170-471c-a5eb-8304995ba79b&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {EF80876B-B9E5-466C-829C-7054D9EE779F} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=2e2fd145-1170-471c-a5eb-8304995ba79b&pid=fotofreeware&mode=bounce&k=0
SearchScopes: HKCU - {F1648EE5-8F60-4F3B-A395-C82B083F8C1B} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=2e2fd145-1170-471c-a5eb-8304995ba79b&pid=fotofreeware&mode=bounce&k=0
BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: No Name - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.313\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll No File
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: DNS Error Helper - {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll No File
BHO-x32: No Name - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default
FF DefaultSearchEngine: Search
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @citrix.com/Citrix Offline Plug-in - C:\Program Files (x86)\Citrix\Streaming Client\nprade.dll ()
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.313\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10174.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\logging.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll ()
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\cf8d8ec1-de0e-4314-b9b1-513c03891765.xml
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\{0217ED0C-16DE-493A-A5C9-E2F4B4E0F5CE}.xml
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\{245A20BC-1232-4A32-8A22-846F7CE75B03}.xml
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\{27112CEE-C08B-4A92-91A9-0726F52CE250}.xml
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\{61DDD81F-B7E2-4C90-94CB-3F75964B5834}.xml
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\{A8536098-01B6-4B66-AEA4-8284FEFAF28A}.xml
FF SearchPlugin: C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\searchplugins\{B6A6BC6E-C953-46DF-A7C6-FA05C5D1D523}.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: WOT - C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-12-12]
FF Extension: Preispilot - C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\0332v9vh.default\Extensions\extension@preispilot.com.xpi [2013-10-24]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-06-17]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-08]
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-25] (Adobe Systems Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-08] (AVAST Software)
R2 CdfSvc; C:\Program Files (x86)\Common Files\Citrix\System32\CdfSvc.exe [321448 2011-05-03] (Citrix Systems, Inc.)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.313\McCHSvc.exe [234776 2012-10-26] (McAfee, Inc.)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 RadeHlprSvc; C:\Program Files (x86)\Citrix\Streaming Client\RadeHlprSvc.exe [210864 2011-07-19] (Citrix Systems, Inc.)
R2 RadeSvc; C:\Program Files (x86)\Citrix\Streaming Client\RadeSvc.exe [1034152 2011-07-19] (Citrix Systems, Inc.)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated)
R2 ThreatFire; C:\Program Files (x86)\ThreatFire\TFService.exe [70928 2010-01-14] (PC Tools)
S2 AntiVirWebService; "C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE" [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-08] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-08] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-08] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-08] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-04-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-04-08] ()
R1 cdfdrv; C:\Windows\System32\DRIVERS\cdfdrv.sys [38448 2011-03-01] (Citrix Systems, Inc.)
R1 ctxpidmn; C:\Windows\System32\DRIVERS\ctxpidmn.sys [83288 2011-06-30] (Citrix Systems, Inc.)
R2 CtxSbx; C:\Windows\System32\DRIVERS\CtxSbx.sys [309080 2011-06-30] (Citrix Systems, Inc.)
R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation)
R0 TfFsMon; C:\Windows\System32\drivers\TfFsMon.sys [65072 2010-01-14] (PC Tools)
R3 TfNetMon; C:\Windows\system32\drivers\TfNetMon.sys [41888 2010-01-14] (PC Tools)
R0 TfSysMon; C:\Windows\System32\drivers\TfSysMon.sys [59880 2010-01-14] (PC Tools)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 PCDSRVC{A368CD8C-C4A01D7A-06020101}_0; \??\c:\users\admini~1\appdata\local\temp\afwp5msfnsyt\pcdrdiag\bin\pcdsrvc_x64.pkms [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-09 20:08 - 2014-04-09 20:08 - 00000912 _____ () C:\Users\Christina\Desktop\JRT.txt
2014-04-09 19:44 - 2014-04-09 19:44 - 01016261 _____ (Thisisu) C:\Users\Christina\Desktop\JRT.exe
2014-04-09 19:34 - 2014-04-09 19:35 - 01426178 _____ () C:\Users\Christina\Desktop\adwcleaner (1).exe
2014-04-09 19:31 - 2014-04-09 19:31 - 00015480 _____ () C:\Users\Christina\Desktop\ProtokollMBAM.txt
2014-04-09 15:15 - 2014-04-09 19:30 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-09 15:15 - 2014-04-09 15:15 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-09 15:15 - 2014-04-09 15:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-09 15:15 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-09 15:15 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-09 15:15 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-09 15:00 - 2014-04-09 15:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-04-08 16:07 - 2014-04-08 16:07 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\AVAST Software
2014-04-08 16:06 - 2014-04-09 19:27 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-08 16:06 - 2014-04-08 16:06 - 00001970 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-08 16:04 - 2014-04-08 16:04 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-08 16:04 - 2014-04-08 16:04 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-08 16:03 - 2014-04-08 16:03 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-08 16:02 - 2014-04-08 16:02 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-08 16:01 - 2014-04-08 16:02 - 88551496 _____ (AVAST Software) C:\Users\Christina\Downloads\avast_free_antivirus_setup_9.0.2016.exe
2014-04-08 15:34 - 2014-04-08 15:34 - 00027022 _____ () C:\ComboFix.txt
2014-04-08 14:46 - 2014-04-08 14:46 - 05194596 ____R (Swearware) C:\Users\Christina\Desktop\ComboFix.exe
2014-04-08 07:15 - 2014-04-08 07:15 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-04-08 07:15 - 2014-04-08 07:15 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\Opera Software
2014-04-08 07:15 - 2014-04-08 07:15 - 00000000 ____D () C:\Users\Christina\AppData\Local\Opera Software
2014-04-08 07:15 - 2014-04-08 07:15 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-04-08 07:13 - 2014-04-08 07:14 - 34718824 _____ (Opera Software ASA) C:\Users\Christina\Downloads\Opera_20.0.1387.91_Setup.exe
2014-04-07 17:53 - 2014-04-09 20:10 - 00000000 ____D () C:\AdwCleaner
2014-04-07 17:51 - 2014-04-07 17:51 - 01426178 _____ () C:\Users\Christina\Downloads\adwcleaner.exe
2014-04-07 17:50 - 2014-04-07 17:51 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-07 06:52 - 2014-04-07 06:55 - 00037734 _____ () C:\Users\Christina\Downloads\Addition.txt
2014-04-07 06:49 - 2014-04-09 20:21 - 00024283 _____ () C:\Users\Christina\Downloads\FRST.txt
2014-04-07 06:46 - 2014-04-09 20:21 - 00000000 ____D () C:\FRST
2014-04-07 06:45 - 2014-04-07 06:45 - 02157056 _____ (Farbar) C:\Users\Christina\Downloads\FRST64.exe
2014-03-26 21:41 - 2014-03-26 21:41 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\hps-install
2014-03-26 21:41 - 2014-03-26 21:41 - 00000000 ____D () C:\Program Files\dm
2014-03-19 17:23 - 2014-03-19 17:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-15 09:16 - 2014-03-15 09:16 - 00000268 ___RH () C:\Users\Christina\AppData\Roaming\Tables
2014-03-15 09:16 - 2014-03-15 09:16 - 00000268 ___RH () C:\ProgramData\Themes
2014-03-15 09:16 - 2014-03-15 09:16 - 00000020 ____H () C:\ProgramData\PKP_DLex.DAT
2014-03-15 09:16 - 2014-03-15 09:16 - 00000000 ____D () C:\Users\Christina\AppData\Local\Nikon
2014-03-15 09:16 - 2014-03-15 09:16 - 00000000 ____D () C:\ProgramData\Ultima_T15
2014-03-15 09:16 - 2014-03-15 09:16 - 00000000 ____D () C:\ProgramData\EnterNHelp
2014-03-14 13:02 - 2014-03-14 13:02 - 00000975 _____ () C:\Users\Public\Desktop\SaalDesignSoftware.lnk
2014-03-14 13:02 - 2014-03-14 13:02 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\SaalDesignSoftware
2014-03-14 13:02 - 2014-03-14 13:02 - 00000000 ____D () C:\Program Files (x86)\SaalDesignSoftware
2014-03-14 10:58 - 2014-03-14 10:59 - 00000000 ____D () C:\Program Files\Common Files\Nikon
2014-03-14 10:58 - 2014-03-14 10:58 - 00002083 _____ () C:\Users\Public\Desktop\Capture NX-D.lnk
2014-03-14 10:58 - 2014-03-14 10:58 - 00000000 ____D () C:\Program Files\Nikon
2014-03-13 08:31 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 08:31 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 08:31 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 08:31 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 08:31 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 08:31 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 08:31 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 08:31 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 08:31 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 08:31 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 08:31 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 08:31 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 08:31 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 08:31 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 08:31 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 08:31 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 08:31 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 08:31 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 08:31 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 08:31 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 08:31 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 08:31 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 08:31 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 08:31 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 08:31 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 08:31 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 08:31 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 08:31 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 08:31 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 08:31 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 08:31 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 08:31 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 08:31 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 08:31 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 08:31 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 08:31 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 08:31 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 08:31 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 08:31 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 08:31 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 08:31 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 08:31 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 08:31 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 08:31 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 08:30 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 08:30 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 08:30 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-13 08:30 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
==================== One Month Modified Files and Folders =======
2014-04-09 20:22 - 2014-04-07 06:49 - 00024283 _____ () C:\Users\Christina\Downloads\FRST.txt
2014-04-09 20:21 - 2014-04-07 06:46 - 00000000 ____D () C:\FRST
2014-04-09 20:20 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-09 20:20 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-09 20:13 - 2012-12-16 22:44 - 00000000 ___RD () C:\Users\Christina\Dropbox
2014-04-09 20:13 - 2012-12-16 22:42 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\Dropbox
2014-04-09 20:11 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-09 20:11 - 2009-07-14 06:51 - 00071534 _____ () C:\Windows\setupact.log
2014-04-09 20:10 - 2014-04-07 17:53 - 00000000 ____D () C:\AdwCleaner
2014-04-09 20:10 - 2011-12-13 20:46 - 01058492 _____ () C:\Windows\WindowsUpdate.log
2014-04-09 20:08 - 2014-04-09 20:08 - 00000912 _____ () C:\Users\Christina\Desktop\JRT.txt
2014-04-09 19:50 - 2011-12-29 10:46 - 00000000 ____D () C:\Program Files (x86)\ThreatFire
2014-04-09 19:44 - 2014-04-09 19:44 - 01016261 _____ (Thisisu) C:\Users\Christina\Desktop\JRT.exe
2014-04-09 19:36 - 2012-07-17 21:30 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-09 19:35 - 2014-04-09 19:34 - 01426178 _____ () C:\Users\Christina\Desktop\adwcleaner (1).exe
2014-04-09 19:33 - 2011-12-14 05:38 - 09891016 _____ () C:\Windows\system32\perfh007.dat
2014-04-09 19:33 - 2011-12-14 05:38 - 03110760 _____ () C:\Windows\system32\perfc007.dat
2014-04-09 19:33 - 2009-07-14 07:13 - 00006504 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-09 19:31 - 2014-04-09 19:31 - 00015480 _____ () C:\Users\Christina\Desktop\ProtokollMBAM.txt
2014-04-09 19:30 - 2014-04-09 15:15 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-09 19:27 - 2014-04-08 16:06 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-09 19:25 - 2012-05-25 20:58 - 00000000 ____D () C:\Windows\Sun
2014-04-09 19:25 - 2011-12-13 20:43 - 00269150 _____ () C:\Windows\PFRO.log
2014-04-09 15:15 - 2014-04-09 15:15 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-09 15:15 - 2014-04-09 15:15 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-09 15:15 - 2013-06-13 21:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-09 15:00 - 2014-04-09 15:00 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-04-09 11:57 - 2012-06-24 21:19 - 00000000 ____D () C:\Users\Christina\Documents\G
2014-04-08 16:38 - 2012-09-26 20:04 - 00000000 ____D () C:\Users\Christina\AppData\Local\Google
2014-04-08 16:38 - 2012-09-26 20:04 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-08 16:37 - 2011-06-24 15:38 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-08 16:07 - 2014-04-08 16:07 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\AVAST Software
2014-04-08 16:06 - 2014-04-08 16:06 - 00001970 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-08 16:04 - 2014-04-08 16:04 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-08 16:04 - 2014-04-08 16:04 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-08 16:04 - 2014-04-08 16:04 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-08 16:03 - 2014-04-08 16:03 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-08 16:02 - 2014-04-08 16:02 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-08 16:02 - 2014-04-08 16:01 - 88551496 _____ (AVAST Software) C:\Users\Christina\Downloads\avast_free_antivirus_setup_9.0.2016.exe
2014-04-08 15:35 - 2013-06-15 10:41 - 00000000 ____D () C:\Qoobox
2014-04-08 15:34 - 2014-04-08 15:34 - 00027022 _____ () C:\ComboFix.txt
2014-04-08 15:24 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-08 14:53 - 2013-06-13 19:16 - 00000000 ____D () C:\ProgramData\Avira
2014-04-08 14:46 - 2014-04-08 14:46 - 05194596 ____R (Swearware) C:\Users\Christina\Desktop\ComboFix.exe
2014-04-08 14:42 - 2013-06-13 21:34 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-08 07:22 - 2011-12-29 11:07 - 00000000 ____D () C:\Users\Ctx_StreamingSvc
2014-04-08 07:21 - 2014-02-16 13:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-08 07:21 - 2012-04-30 17:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-08 07:21 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-08 07:15 - 2014-04-08 07:15 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-04-08 07:15 - 2014-04-08 07:15 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\Opera Software
2014-04-08 07:15 - 2014-04-08 07:15 - 00000000 ____D () C:\Users\Christina\AppData\Local\Opera Software
2014-04-08 07:15 - 2014-04-08 07:15 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-04-08 07:14 - 2014-04-08 07:13 - 34718824 _____ (Opera Software ASA) C:\Users\Christina\Downloads\Opera_20.0.1387.91_Setup.exe
2014-04-07 17:51 - 2014-04-07 17:51 - 01426178 _____ () C:\Users\Christina\Downloads\adwcleaner.exe
2014-04-07 17:51 - 2014-04-07 17:50 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-07 06:55 - 2014-04-07 06:52 - 00037734 _____ () C:\Users\Christina\Downloads\Addition.txt
2014-04-07 06:45 - 2014-04-07 06:45 - 02157056 _____ (Farbar) C:\Users\Christina\Downloads\FRST64.exe
2014-04-03 09:51 - 2014-04-09 15:15 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-09 15:15 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-09 15:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2011-12-13 21:51 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-26 21:57 - 2012-04-16 20:59 - 00000000 ____D () C:\ProgramData\tmp
2014-03-26 21:46 - 2012-04-16 20:45 - 00000000 ____D () C:\Program Files (x86)\dm
2014-03-26 21:41 - 2014-03-26 21:41 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\hps-install
2014-03-26 21:41 - 2014-03-26 21:41 - 00000000 ____D () C:\Program Files\dm
2014-03-19 17:47 - 2014-03-19 17:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-03-18 21:56 - 2013-08-17 12:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 21:53 - 2012-01-12 13:01 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-15 09:16 - 2014-03-15 09:16 - 00000268 ___RH () C:\Users\Christina\AppData\Roaming\Tables
2014-03-15 09:16 - 2014-03-15 09:16 - 00000268 ___RH () C:\ProgramData\Themes
2014-03-15 09:16 - 2014-03-15 09:16 - 00000020 ____H () C:\ProgramData\PKP_DLex.DAT
2014-03-15 09:16 - 2014-03-15 09:16 - 00000000 ____D () C:\Users\Christina\AppData\Local\Nikon
2014-03-15 09:16 - 2014-03-15 09:16 - 00000000 ____D () C:\ProgramData\Ultima_T15
2014-03-15 09:16 - 2014-03-15 09:16 - 00000000 ____D () C:\ProgramData\EnterNHelp
2014-03-15 09:06 - 2009-07-14 06:45 - 01803656 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-15 09:04 - 2013-03-14 08:50 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-15 09:04 - 2013-03-14 08:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-15 08:16 - 2012-01-28 12:37 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-14 13:02 - 2014-03-14 13:02 - 00000975 _____ () C:\Users\Public\Desktop\SaalDesignSoftware.lnk
2014-03-14 13:02 - 2014-03-14 13:02 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\SaalDesignSoftware
2014-03-14 13:02 - 2014-03-14 13:02 - 00000000 ____D () C:\Program Files (x86)\SaalDesignSoftware
2014-03-14 10:59 - 2014-03-14 10:58 - 00000000 ____D () C:\Program Files\Common Files\Nikon
2014-03-14 10:58 - 2014-03-14 10:58 - 00002083 _____ () C:\Users\Public\Desktop\Capture NX-D.lnk
2014-03-14 10:58 - 2014-03-14 10:58 - 00000000 ____D () C:\Program Files\Nikon
2014-03-14 10:58 - 2011-06-24 15:38 - 00000000 ____D () C:\Windows\Downloaded Installations
2014-03-14 10:57 - 2014-01-20 21:03 - 00000000 ____D () C:\Users\Christina\AppData\Local\Downloaded Installations
2014-03-14 10:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-12 12:36 - 2012-07-17 21:30 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 12:36 - 2012-04-17 07:23 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 12:36 - 2011-12-29 16:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-10 18:22 - 2013-10-11 11:16 - 00000000 ____D () C:\Users\Christina\Documents\Buch Narzissmus
Files to move or delete:
====================
C:\ProgramData\PKP_DLex.DAT
Some content of TEMP:
====================
C:\Users\Christina\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 16:11
==================== End Of Log ============================ --- --- --- Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Christina on 09.04.2014 at 19:54:05,33
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D408B88D-A2A8-43E4-904A-3C814558E0A6}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Christina\AppData\Roaming\mozilla\firefox\profiles\0332v9vh.default\minidumps [23 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.04.2014 at 20:08:09,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |