doublepack | 22.06.2014 10:51 | Habe alles gemacht nur bei einem programm habe ich keine txt das war bei dem JRT programm sonst habe ich alles.
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2014 01
Ran by Dome&Luke (administrator) on DOMELUKE on 22-06-2014 11:47:35
Running from C:\Users\Dome&Luke\Desktop
Platform: Windows 7 Home Premium Service Pack 3 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\reg.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-06] (AVAST Software)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2014-04-22] (Microsoft Corporation)
HKU\S-1-5-21-1866305474-3056176706-1639482995-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-16] (Glarysoft Ltd)
HKU\S-1-5-21-1866305474-3056176706-1639482995-1000\...\MountPoints2: {e9b43d21-d6a8-11e3-825b-38607782ca6c} - H:\Start.exe
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * BootDefrag.exe
==================== Internet (Whitelisted) ====================
ProxyServer: http=127.0.0.1:8118;https=127.0.0.1:8118
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBE421832705DCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {53CFE9A6-E08E-470A-B414-AA05DCF008CF} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {53CFE9A6-E08E-470A-B414-AA05DCF008CF} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKCU - {53CFE9A6-E08E-470A-B414-AA05DCF008CF} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Dome&Luke\AppData\Roaming\Mozilla\Firefox\Profiles\hqbj5sa2.default
FF SearchEngineOrder.1: Microsoft (Bing)
FF Keyword.URL: hxxp://www.bing.com/search
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 8118
FF NetworkProxy: "ssl", "127.0.0.1"
FF NetworkProxy: "ssl_port", 8118
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Dome&Luke\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Dome&Luke\AppData\Roaming\Mozilla\Firefox\Profiles\hqbj5sa2.default\searchplugins\bing-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: leethax.net extension - C:\Users\Dome&Luke\AppData\Roaming\Mozilla\Firefox\Profiles\hqbj5sa2.default\Extensions\leethax@leethax.net.xpi [2014-05-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-21]
Chrome:
=======
CHR HomePage:
CHR DefaultSearchKeyword: webssearches
CHR DefaultSearchProvider: webssearches
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-01]
CHR Extension: (Google Drive) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-01]
CHR Extension: (YouTube) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-01]
CHR Extension: (Adblock Plus) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-20]
CHR Extension: (Google-Suche) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-01]
CHR Extension: (avast! Online Security) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-06-01]
CHR Extension: (AdBlock Plus) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhlalolcniejfpochachikjfdmfjgbdk [2014-06-20]
CHR Extension: (Google Wallet) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-21]
CHR Extension: (Google Mail) - C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-01]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-04-21]
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-21] (AVAST Software)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-15] (LogMeIn, Inc.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-14] ()
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2014-04-22] (Microsoft Corporation) [File not signed]
S4 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [X]
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-21] ()
R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [17600 2014-06-03] (Glarysoft Ltd)
R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-05-19] (Glarysoft Ltd)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61736 2014-02-28] (NetFilterSDK.com)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42184 2014-03-24] (Anchorfree Inc.)
R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}Gw64.sys [61112 2014-05-16] (StdLib)
S3 OSFMount; \??\C:\Program Files (x86)\Counter-Strike Global Offensive\image\x64\OSFMount.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-22 11:47 - 2014-06-22 11:47 - 00012330 _____ () C:\Users\Dome&Luke\Desktop\FRST.txt
2014-06-22 11:27 - 2014-06-22 11:27 - 00000000 ____D () C:\Windows\ERUNT
2014-06-22 11:26 - 2014-06-22 11:27 - 01016261 _____ (Thisisu) C:\Users\Dome&Luke\Desktop\JRT.exe
2014-06-22 11:25 - 2014-06-22 11:25 - 00006174 _____ () C:\Users\Dome&Luke\Desktop\AdwCleaner[S0].txt
2014-06-22 11:21 - 2014-06-22 11:22 - 00065987 _____ () C:\Users\Dome&Luke\Desktop\MBAM.txt
2014-06-22 11:13 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-22 11:11 - 2014-06-22 11:23 - 00000000 ____D () C:\AdwCleaner
2014-06-22 11:11 - 2014-06-22 11:11 - 01333465 _____ () C:\Users\Dome&Luke\Desktop\adwcleaner_3.212.exe
2014-06-22 11:08 - 2014-06-22 11:09 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 11:08 - 2014-06-22 11:08 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-22 11:08 - 2014-06-22 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-22 11:08 - 2014-06-22 11:08 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 11:08 - 2014-06-22 11:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-22 11:08 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-22 11:08 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-22 11:08 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-22 11:07 - 2014-06-22 11:08 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dome&Luke\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-22 10:53 - 2014-06-22 10:53 - 03007700 _____ () C:\Users\Dome&Luke\Downloads\revouninstaller.zip
2014-06-22 10:53 - 2014-06-22 10:53 - 00000000 ____D () C:\Users\Dome&Luke\Desktop\revouninstaller-portable
2014-06-22 01:19 - 2014-06-22 01:19 - 00961360 _____ (Chip Digital GmbH) C:\Users\Dome&Luke\Desktop\Revo Uninstaller Portable - CHIP-Installer.exe
2014-06-21 12:16 - 2014-06-21 12:16 - 00049838 _____ () C:\Users\Dome&Luke\Downloads\FRST.txt
2014-06-21 10:54 - 2014-06-21 10:55 - 00039286 _____ () C:\Users\Dome&Luke\Desktop\Addition.txt
2014-06-21 10:53 - 2014-06-22 11:47 - 00000000 ____D () C:\FRST
2014-06-21 10:53 - 2014-06-21 10:53 - 02083328 _____ (Farbar) C:\Users\Dome&Luke\Desktop\FRST64.exe
2014-06-21 10:52 - 2014-06-21 10:52 - 01958440 _____ (Farbar) C:\Users\Dome&Luke\Downloads\FRST64.exe
2014-06-21 10:44 - 2014-06-21 10:44 - 01070592 _____ (Farbar) C:\Users\Dome&Luke\Downloads\FRST.exe
2014-06-20 23:35 - 2014-06-20 23:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peggle
2014-06-20 22:56 - 2014-06-20 23:00 - 109068563 _____ () C:\Users\Dome&Luke\Downloads\Pokemon Black.zip
2014-06-20 22:53 - 2014-06-20 22:53 - 01096820 _____ () C:\Users\Dome&Luke\Downloads\desmume-0.9.10-win32.zip
2014-06-20 16:58 - 2014-06-20 17:15 - 00000000 ____D () C:\Users\Dome&Luke\Desktop\Musik(Luke
2014-06-20 16:33 - 2014-06-22 11:24 - 00071950 _____ () C:\Windows\PFRO.log
2014-06-20 16:19 - 2014-06-22 11:25 - 00000336 _____ () C:\Windows\setupact.log
2014-06-20 16:19 - 2014-06-20 16:19 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-18 20:06 - 2014-06-18 20:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-15 13:43 - 2014-06-15 13:50 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-06-15 11:23 - 2014-06-15 11:23 - 00001256 _____ () C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2014-06-15 11:23 - 2014-06-15 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2014-06-15 11:23 - 2014-06-15 11:23 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-06-15 08:57 - 2014-06-15 09:00 - 00737280 _____ (Indigo Rose Corporation) C:\Windows\iun6002.exe
2014-06-15 07:50 - 2014-06-15 07:50 - 00000000 ____D () C:\Users\Public\Documents\EA Games
2014-06-15 01:41 - 2011-07-28 13:26 - 00000000 ____D () C:\Users\Dome&Luke\Documents\EA Games
2014-06-15 01:26 - 2014-06-15 01:26 - 00000000 ____D () C:\Users\Dome
2014-06-14 20:53 - 2014-06-14 20:56 - 00000000 ____D () C:\Users\Dome&Luke\Documents\BFH.Beta
2014-06-14 17:20 - 2014-06-15 11:19 - 00000000 ____D () C:\wintemp
2014-06-13 13:24 - 2014-06-20 23:35 - 00000000 ____D () C:\ProgramData\PopCap Games
2014-06-12 22:17 - 2014-06-20 14:33 - 00000234 _____ () C:\BackupLoader.ini
2014-06-12 22:17 - 2014-06-03 03:26 - 00118048 _____ (Glarysoft Ltd) C:\Windows\system32\BootDefrag.exe
2014-06-12 22:17 - 2014-06-03 03:05 - 00017600 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\BootDefragDriver.sys
2014-06-10 23:25 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-10 23:25 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-10 23:25 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-10 23:25 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-10 23:25 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-10 23:25 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-10 23:25 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-10 23:25 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-10 23:25 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-10 23:25 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-10 23:25 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-10 23:25 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-10 23:25 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-10 23:25 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-10 23:25 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-10 23:25 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-10 23:25 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-10 23:25 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-10 23:25 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-10 23:25 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-10 23:25 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-10 23:25 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-10 23:25 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-10 23:25 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-10 23:25 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-10 23:25 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-10 23:25 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-10 23:25 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-10 23:25 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-10 23:25 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-10 23:25 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-10 23:25 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-10 23:25 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-10 23:25 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-10 23:25 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-10 23:25 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-10 23:25 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-10 23:25 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-10 23:25 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-10 23:25 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-10 23:25 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-10 23:25 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-10 23:25 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-10 23:25 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-10 23:25 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-10 23:25 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-10 23:25 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-10 23:25 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-10 23:25 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-10 23:25 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-10 23:25 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-10 23:25 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-10 23:04 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-10 23:04 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-10 23:03 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-10 23:03 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-10 23:03 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-10 23:03 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-10 23:03 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-10 23:03 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-10 23:03 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-10 23:03 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-10 23:03 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-10 23:03 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-10 23:03 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-10 23:03 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-10 23:02 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-10 23:02 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-30 14:07 - 2014-06-01 22:25 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-30 14:07 - 2014-05-30 14:07 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Mozilla
2014-05-30 14:06 - 2014-06-19 18:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-27 22:42 - 2014-02-06 20:55 - 00123548 _____ () C:\Users\Dome&Luke\Desktop\dodo monatsbericht2.odt
2014-05-26 23:35 - 2014-06-21 11:32 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\vlc
2014-05-26 23:34 - 2014-05-26 23:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-05-26 13:44 - 2014-05-26 13:44 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-05-26 13:44 - 2014-05-26 13:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-05-26 00:12 - 2014-05-26 00:12 - 00000000 ____D () C:\Windows\SysWOW64\URTTEMP
2014-05-25 23:39 - 2014-05-26 13:44 - 00000000 ____D () C:\Users\Dome&Luke\Documents\GTA San Andreas User Files
2014-05-25 17:32 - 2014-05-25 17:32 - 00000000 ____D () C:\Users\Dome&Luke\Documents\Rockstar Games
2014-05-25 17:27 - 2014-05-25 17:29 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\Rockstar Games
2014-05-25 17:18 - 2014-05-25 17:18 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2014-05-25 16:54 - 2014-05-25 23:05 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-25 16:54 - 2014-05-25 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2014-05-25 16:54 - 2014-05-25 23:05 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2014-05-24 23:48 - 2014-05-24 23:48 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\WorldofTanks
2014-05-24 23:37 - 2014-06-18 21:20 - 538006251 _____ () C:\Windows\MEMORY.DMP
==================== One Month Modified Files and Folders =======
2014-06-22 11:48 - 2014-06-22 11:47 - 00012330 _____ () C:\Users\Dome&Luke\Desktop\FRST.txt
2014-06-22 11:47 - 2014-06-21 10:53 - 00000000 ____D () C:\FRST
2014-06-22 11:32 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-22 11:32 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-22 11:27 - 2014-06-22 11:27 - 00000000 ____D () C:\Windows\ERUNT
2014-06-22 11:27 - 2014-06-22 11:26 - 01016261 _____ (Thisisu) C:\Users\Dome&Luke\Desktop\JRT.exe
2014-06-22 11:26 - 2014-05-19 22:08 - 00000342 _____ () C:\Windows\Tasks\GlaryInitialize 5.job
2014-06-22 11:25 - 2014-06-22 11:25 - 00006174 _____ () C:\Users\Dome&Luke\Desktop\AdwCleaner[S0].txt
2014-06-22 11:25 - 2014-06-20 16:19 - 00000336 _____ () C:\Windows\setupact.log
2014-06-22 11:25 - 2014-05-19 22:08 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2014-06-22 11:25 - 2014-04-21 16:45 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-22 11:25 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-22 11:24 - 2014-06-20 16:33 - 00071950 _____ () C:\Windows\PFRO.log
2014-06-22 11:24 - 2014-04-21 16:15 - 01410381 _____ () C:\Windows\WindowsUpdate.log
2014-06-22 11:23 - 2014-06-22 11:11 - 00000000 ____D () C:\AdwCleaner
2014-06-22 11:23 - 2014-04-27 15:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-22 11:22 - 2014-06-22 11:21 - 00065987 _____ () C:\Users\Dome&Luke\Desktop\MBAM.txt
2014-06-22 11:11 - 2014-06-22 11:11 - 01333465 _____ () C:\Users\Dome&Luke\Desktop\adwcleaner_3.212.exe
2014-06-22 11:11 - 2014-05-20 20:23 - 00000000 ____D () C:\temp
2014-06-22 11:09 - 2014-06-22 11:08 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 11:08 - 2014-06-22 11:08 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-22 11:08 - 2014-06-22 11:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-22 11:08 - 2014-06-22 11:08 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 11:08 - 2014-06-22 11:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-22 11:08 - 2014-06-22 11:07 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Dome&Luke\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-22 11:07 - 2014-04-21 16:45 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-22 10:53 - 2014-06-22 10:53 - 03007700 _____ () C:\Users\Dome&Luke\Downloads\revouninstaller.zip
2014-06-22 10:53 - 2014-06-22 10:53 - 00000000 ____D () C:\Users\Dome&Luke\Desktop\revouninstaller-portable
2014-06-22 01:19 - 2014-06-22 01:19 - 00961360 _____ (Chip Digital GmbH) C:\Users\Dome&Luke\Desktop\Revo Uninstaller Portable - CHIP-Installer.exe
2014-06-21 12:16 - 2014-06-21 12:16 - 00049838 _____ () C:\Users\Dome&Luke\Downloads\FRST.txt
2014-06-21 11:32 - 2014-05-26 23:35 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\vlc
2014-06-21 10:55 - 2014-06-21 10:54 - 00039286 _____ () C:\Users\Dome&Luke\Desktop\Addition.txt
2014-06-21 10:53 - 2014-06-21 10:53 - 02083328 _____ (Farbar) C:\Users\Dome&Luke\Desktop\FRST64.exe
2014-06-21 10:52 - 2014-06-21 10:52 - 01958440 _____ (Farbar) C:\Users\Dome&Luke\Downloads\FRST64.exe
2014-06-21 10:44 - 2014-06-21 10:44 - 01070592 _____ (Farbar) C:\Users\Dome&Luke\Downloads\FRST.exe
2014-06-21 10:29 - 2014-04-21 20:06 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\DiskDefrag
2014-06-21 01:30 - 2014-04-22 01:58 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Spotify
2014-06-20 23:57 - 2014-05-10 20:50 - 00000000 ____D () C:\ProgramData\Origin
2014-06-20 23:35 - 2014-06-20 23:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Peggle
2014-06-20 23:35 - 2014-06-13 13:24 - 00000000 ____D () C:\ProgramData\PopCap Games
2014-06-20 23:35 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-20 23:34 - 2014-05-10 22:01 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-06-20 23:33 - 2014-05-10 20:49 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-20 23:14 - 2014-04-28 14:11 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-20 23:00 - 2014-06-20 22:56 - 109068563 _____ () C:\Users\Dome&Luke\Downloads\Pokemon Black.zip
2014-06-20 22:57 - 2014-04-21 17:45 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\uTorrent
2014-06-20 22:53 - 2014-06-20 22:53 - 01096820 _____ () C:\Users\Dome&Luke\Downloads\desmume-0.9.10-win32.zip
2014-06-20 17:15 - 2014-06-20 16:58 - 00000000 ____D () C:\Users\Dome&Luke\Desktop\Musik(Luke
2014-06-20 16:51 - 2014-04-21 17:28 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\.minecraft
2014-06-20 16:33 - 2014-05-08 17:19 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\LogMeIn Hamachi
2014-06-20 16:19 - 2014-06-20 16:19 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-20 14:39 - 2014-05-07 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InterActual
2014-06-20 14:39 - 2014-05-07 13:20 - 00000000 ____D () C:\Program Files\InterActual
2014-06-20 14:36 - 2014-04-21 23:30 - 00000000 ____D () C:\Windows\Minidump
2014-06-20 14:36 - 2014-04-21 16:37 - 00000000 ____D () C:\Users\Dome&Luke\Desktop\Games
2014-06-20 14:33 - 2014-06-12 22:17 - 00000234 _____ () C:\BackupLoader.ini
2014-06-20 14:33 - 2014-05-19 22:08 - 00002988 _____ () C:\Windows\System32\Tasks\GU5SkipUAC
2014-06-20 14:33 - 2014-05-19 22:08 - 00002662 _____ () C:\Windows\System32\Tasks\GlaryInitialize 5
2014-06-20 14:33 - 2014-05-19 22:08 - 00001098 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2014-06-20 14:33 - 2014-05-19 22:08 - 00001086 _____ () C:\Users\Public\Desktop\Glary Utilities 5.lnk
2014-06-19 18:46 - 2014-04-21 19:59 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-19 18:45 - 2014-05-30 14:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-18 21:20 - 2014-05-24 23:37 - 538006251 _____ () C:\Windows\MEMORY.DMP
2014-06-18 20:06 - 2014-06-18 20:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-18 13:33 - 2014-04-21 17:32 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Skype
2014-06-17 02:02 - 2014-04-21 16:45 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-17 02:02 - 2014-04-21 16:45 - 00003868 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-16 20:27 - 2014-04-22 01:58 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\Spotify
2014-06-15 17:16 - 2014-04-25 13:27 - 00000000 ____D () C:\Users\Dome&Luke\Desktop\Musik
2014-06-15 17:08 - 2014-04-21 16:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-15 16:08 - 2014-05-05 23:54 - 00000000 ____D () C:\Program Files (x86)\NosTale(DE)
2014-06-15 15:43 - 2014-05-11 13:54 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-06-15 15:43 - 2014-05-11 05:59 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-06-15 15:43 - 2014-05-11 05:59 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-06-15 14:55 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-06-15 13:50 - 2014-06-15 13:43 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-06-15 11:23 - 2014-06-15 11:23 - 00001256 _____ () C:\Users\Public\Desktop\Virtual CloneDrive.lnk
2014-06-15 11:23 - 2014-06-15 11:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2014-06-15 11:23 - 2014-06-15 11:23 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-06-15 11:19 - 2014-06-14 17:20 - 00000000 ____D () C:\wintemp
2014-06-15 09:00 - 2014-06-15 08:57 - 00737280 _____ (Indigo Rose Corporation) C:\Windows\iun6002.exe
2014-06-15 07:50 - 2014-06-15 07:50 - 00000000 ____D () C:\Users\Public\Documents\EA Games
2014-06-15 07:46 - 2014-05-15 22:40 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-06-15 01:26 - 2014-06-15 01:26 - 00000000 ____D () C:\Users\Dome
2014-06-14 20:56 - 2014-06-14 20:53 - 00000000 ____D () C:\Users\Dome&Luke\Documents\BFH.Beta
2014-06-14 20:53 - 2014-05-11 13:29 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-06-14 20:23 - 2014-05-11 05:59 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-06-14 20:23 - 2014-04-21 17:54 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-14 19:55 - 2014-05-08 15:49 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\DAEMON Tools Lite
2014-06-14 17:23 - 2009-07-14 19:58 - 00709706 _____ () C:\Windows\system32\perfh007.dat
2014-06-14 17:23 - 2009-07-14 19:58 - 00154142 _____ () C:\Windows\system32\perfc007.dat
2014-06-14 17:23 - 2009-07-14 07:13 - 01648684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-13 14:28 - 2014-05-14 07:16 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Opera Software
2014-06-13 14:28 - 2014-05-14 07:16 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\Opera Software
2014-06-13 14:28 - 2014-05-14 07:16 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-13 14:27 - 2014-04-24 18:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2014-06-13 13:08 - 2014-04-21 20:11 - 00000000 ___RD () C:\Users\Dome&Luke\Dropbox
2014-06-12 23:08 - 2014-04-27 15:05 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-12 23:08 - 2014-04-27 15:04 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-12 23:08 - 2014-04-27 15:04 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 03:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-11 03:04 - 2014-04-21 19:59 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 03:02 - 2014-04-21 19:59 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-11 03:00 - 2014-04-24 22:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-09 03:56 - 2014-05-01 12:07 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-06-08 11:13 - 2014-06-10 23:02 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-10 23:02 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-03 03:26 - 2014-06-12 22:17 - 00118048 _____ (Glarysoft Ltd) C:\Windows\system32\BootDefrag.exe
2014-06-03 03:05 - 2014-06-12 22:17 - 00017600 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\BootDefragDriver.sys
2014-06-01 22:25 - 2014-05-30 14:07 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-30 14:07 - 2014-05-30 14:07 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Mozilla
2014-05-30 12:21 - 2014-06-10 23:25 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-10 23:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-10 23:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-10 23:25 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-10 23:25 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-10 23:25 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-10 23:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-10 23:25 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-10 23:25 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-10 23:25 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-10 23:25 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-10 23:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-10 23:25 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-10 23:25 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-10 23:25 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-10 23:25 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-10 23:25 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-10 23:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-10 23:25 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-10 23:25 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-10 23:25 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-10 23:25 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-10 23:25 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-10 23:25 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-10 23:25 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:39 - 2014-04-21 17:32 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-30 10:39 - 2014-04-21 17:31 - 00000000 ____D () C:\ProgramData\Skype
2014-05-30 10:38 - 2014-06-10 23:25 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-10 23:25 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-10 23:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-10 23:25 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-10 23:25 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-10 23:25 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-10 23:25 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-10 23:25 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-10 23:25 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-10 23:25 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-10 23:25 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-10 23:25 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-10 23:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-10 23:25 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-10 23:25 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-10 23:25 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-10 23:25 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-10 23:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-10 23:25 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-10 23:25 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-10 23:25 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-10 23:25 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-10 23:25 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-10 23:25 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-10 23:25 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-10 23:25 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-10 23:25 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-29 21:54 - 2014-05-10 21:59 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\Origin
2014-05-29 20:55 - 2014-05-10 21:59 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Origin
2014-05-26 23:34 - 2014-05-26 23:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-05-26 23:34 - 2014-05-05 17:57 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-05-26 16:54 - 2014-04-21 16:35 - 00001427 _____ () C:\Users\Dome&Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-26 13:44 - 2014-05-26 13:44 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-05-26 13:44 - 2014-05-26 13:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-05-26 13:44 - 2014-05-25 23:39 - 00000000 ____D () C:\Users\Dome&Luke\Documents\GTA San Andreas User Files
2014-05-26 13:32 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2014-05-26 00:13 - 2014-04-21 17:59 - 01675046 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-05-26 00:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Registration
2014-05-26 00:12 - 2014-05-26 00:12 - 00000000 ____D () C:\Windows\SysWOW64\URTTEMP
2014-05-25 23:05 - 2014-05-25 16:54 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-25 23:05 - 2014-05-25 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2014-05-25 23:05 - 2014-05-25 16:54 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2014-05-25 21:20 - 2014-05-15 21:54 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Roaming\dvdcss
2014-05-25 17:32 - 2014-05-25 17:32 - 00000000 ____D () C:\Users\Dome&Luke\Documents\Rockstar Games
2014-05-25 17:29 - 2014-05-25 17:27 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\Rockstar Games
2014-05-25 17:18 - 2014-05-25 17:18 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2014-05-24 23:48 - 2014-05-24 23:48 - 00000000 ____D () C:\Users\Dome&Luke\AppData\Local\WorldofTanks
Some content of TEMP:
====================
C:\Users\Dome&Luke\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-18 00:24
==================== End Of Log ============================ --- --- --- Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.06.2014
Suchlauf-Zeit: 11:09:47
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.22.01
Rootkit Datenbank: v2014.06.20.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 3
CPU: x64
Dateisystem: NTFS
Benutzer: Dome&Luke
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 268157
Verstrichene Zeit: 9 Min, 35 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1648, , [85f4d5a61c5ff83e8ef42d2dd9287d83]
Module: 1
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, , [3b3e7ffc9cdf9f97deb5f495c63b6997],
Registrierungsschlüssel: 45
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, , [85f4d5a61c5ff83e8ef42d2dd9287d83],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6CA2A4DE-483E-456B-8634-6445460D7097}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C321541F-B22D-4593-AC1A-9634812A4E40}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A8018C54-B702-4D52-9ACC-8CA78911E633}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C6A846C5-D67F-48B4-8552-C22354E56966}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A8018C54-B702-4D52-9ACC-8CA78911E633}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C6A846C5-D67F-48B4-8552-C22354E56966}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C321541F-B22D-4593-AC1A-9634812A4E40}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{6CA2A4DE-483E-456B-8634-6445460D7097}, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [c9b06714265593a312f700471ae8f50b],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [c9b06714265593a312f700471ae8f50b],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, , [c9b06714265593a312f700471ae8f50b],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, , [c9b06714265593a312f700471ae8f50b],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, , [651488f3d0abc670b3cf3f777c86936d],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0054246.BHO, , [76037407f3884ee855669f418083df21],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0054246.BHO.1, , [4c2d720925563ef81e9d845cad56cc34],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, , [8aef9cdf0873ae8881b61ca127db27d9],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [6f0a95e6fd7ef640cbc58962e2216997],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{813BA625-B0FA-48D8-9B75-59759C88C219}, , [3643b5c6a6d5c571fc033e74986a47b9],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, , [fd7c3d3ed0ab81b531e7ead348ba768a],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0054246.BHO, , [0b6eb6c5a7d48babcaf16f71db28be42],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0054246.BHO.1, , [bfba2a51ccafbf777f3c845ce61da858],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21636, , [ea8f2c4f0c6f68ceff386e4faf53a55b],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [6b0eb1ca5229171fa3ed628922e14bb5],
PUP.Optional.ScanTack.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update ScanTack, , [50296813c9b292a45496f6ca8d758779],
PUP.Optional.FlowSurf.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF, , [d1a8c2b934470234b7e45b9f976c4cb4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [0277e893f08bb185a0aa1ada62a1fc04],
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, , [eb8e80fb4932fa3c48fcbdffd72b53ad],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, , [86f3740783f8f046bfc95066e220cf31],
PUP.Optional.FlowSurf.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF, , [433696e52952de58613a17e3ad5607f9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, , [c8b1c8b3accf41f5c2763d80c04223dd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Freeven, , [a5d4651698e3261000930bb5b84a13ed],
PUP.Optional.Qone8, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, , [5326b0cba9d23501f9969d4e4fb4dd23],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511421146}, , [99e0205b08732d095f7ea4e05ea619e7],
PUP.Optional.CrossRider.M, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511421146}, , [99e0205b08732d095f7ea4e05ea619e7],
PUP.Optional.CrossRider.M, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110511421146}, , [99e0205b08732d095f7ea4e05ea619e7],
PUP.Optional.CrossRider.M, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110511421146}, , [99e0205b08732d095f7ea4e05ea619e7],
Registrierungswerte: 5
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|jid1-tofUlNEIFlkUIA@jetpack, C:\Program Files (x86)\Flowsurf\jid1-tofUlNEIFlkUIA@jetpack, , [bfbad6a52d4ea5914bf7398210f2db25]
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Dome&Luke\AppData\Roaming\Mozilla\Firefox\Profiles\0qwaz6w5.default\extensions\quick_start@gmail.com, , [4732adce0d6ec86e8253e5d8669c5ea2]
PUP.Optional.FlowSurf.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF|chrid, oglkiljdmflopemijdadoiepkhcaodjn, , [d1a8c2b934470234b7e45b9f976c4cb4]
PUP.Optional.FlowSurf.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF|chrid, oglkiljdmflopemijdadoiepkhcaodjn, , [433696e52952de58613a17e3ad5607f9]
PUP.Optional.QuickStart.A, HKU\S-1-5-21-1866305474-3056176706-1639482995-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, , [3f3a7209a3d81422197d6e38d230e51b]
Registrierungsdaten: 7
PUP.Optional.Skytech.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~2.DLL),,[88f12853b7c478befb98a4e59d64c43c]
PUP.Optional.Skytech.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~1.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~1.DLL),,[4c2dd1aa62195bdb4d46731608f9c23e]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX),,[7affa4d73348003600aa4433659ff20e]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX&q={searchTerms}),,[4732493284f71d193c65a7d09c6857a9]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX),,[1f5a205ba3d8da5c415e354239cb2bd5]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX),,[1168e49737445fd7b3f05c1bbf4543bd]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1400608248&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX),,[d4a518637209e55135751e59010331cf]
Ordner: 60
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, , [5722b1ca13681f178501e8def2101de3],
Stolen.Data, C:\Users\Dome&Luke\AppData\Roaming\dclogs, , [1f5a23586615de58737d59413fc40cf4],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf, , [4b2e0f6cb7c4ff37f6a262985aa9a060],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\log, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\userCode, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\icons, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\icons\actions, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\popupResource, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_majjphhgppkndjjkmhhnbgafooenebhd_0, , [75042952681365d1fbcd445148ba52ae],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\SSL, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\backup, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, , [1465f2894e2df4420d7c7d2720e25ba5],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, , [1465f2894e2df4420d7c7d2720e25ba5],
PUP.Optional.SearchProtect.A, C:\Users\Dome&Luke\AppData\Local\SearchProtect, , [e4954b30047774c293f76b39bd451be5],
PUP.Optional.SearchProtect.A, C:\Users\Dome&Luke\AppData\Local\SearchProtect\Logs, , [e4954b30047774c293f76b39bd451be5],
Dateien: 294
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, , [85f4d5a61c5ff83e8ef42d2dd9287d83],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, , [3b3e7ffc9cdf9f97deb5f495c63b6997],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, , [88f12853b7c478befb98a4e59d64c43c],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, , [4c2dd1aa62195bdb4d46731608f9c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, , [a9d05e1d681346f02d700c3a24de1fe1],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\flowsurf.dll, , [4c2d7a01b5c615212601c08531d1e020],
PUP.Optional.Skytech.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\UninstallManager.exe, , [bbbe95e6285374c21a79286157aa867a],
PUP.Optional.MediaPlayerplus.A, C:\$Recycle.Bin\S-1-5-21-1866305474-3056176706-1639482995-1000\$REQ8E1F\b0625433-0826-4d86-9af6-bc28310b6329-3.exe, , [83f6bfbc90eb5dd91fd6432c857c7987],
PUP.Optional.MediaPlayerplus.A, C:\$Recycle.Bin\S-1-5-21-1866305474-3056176706-1639482995-1000\$REQ8E1F\MediaPlayerplus-bho.dll, , [4a2fbac1f6855dd9b243323d867bdb25],
PUP.Optional.MediaPlayerplus.A, C:\$Recycle.Bin\S-1-5-21-1866305474-3056176706-1639482995-1000\$REQ8E1F\MediaPlayerplus-bho64.dll, , [18610e6d9cdf6bcbdd18f67925dccf31],
PUP.Optional.AdPeak.A, c:\temp\t.msi, , [7efb83f82457f83e51a0cda4a65ec040],
PUP.Optional.InstallCore, C:\Users\Dome&Luke\Downloads\CR_Downloader_fuer_pokemon-black.exe, , [0673b6c5bac166d009ddc0aff41029d7],
PUP.Optional.OptimumInstaller.A, C:\Users\Dome&Luke\Downloads\Player-Chrome.exe, , [55248bf0d0abdc5a27b62a27d130936d],
PUP.Optional.Somoto, C:\Windows\Installer\3b2fae.msi, , [9ddcbcbf5e1de650595f6012ab5954ac],
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\b0625433-0826-4d86-9af6-bc28310b6329-3, , [fa7f1962c7b44aec292d466003ffb24e],
PUP.Optional.Ciuvo.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, , [5e1bbebd45363ff766fe9b0e62a011ef],
PUP.Optional.Ciuvo.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, , [3f3a98e356251b1bf56f5653c33f6a96],
PUP.Optional.BetterDeals.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, , [3346c2b93e3ddd591b2b6645b949f709],
PUP.Optional.BetterDeals.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, , [4336cdaea8d3c96da1a507a48e7446ba],
PUP.Optional.SelectNGo.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, , [1960b4c76516ac8aaca694190af8c13f],
PUP.Optional.SelectNGo.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, , [accdde9db4c77abc84cef2bbf70be31d],
PUP.Optional.LiveLyrics.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.livelyrics00.live-lyrics.com_0.localstorage, , [34455229ff7c96a01f948e200101a25e],
PUP.Optional.LiveLyrics.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.livelyrics00.live-lyrics.com_0.localstorage-journal, , [4e2b6a110f6cdd599122981644be827e],
PUP.Optional.Superfish.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [1762c9b229523afcef0a9a16d23047b9],
PUP.Optional.Superfish.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [e891fc7f69122f0709f0a50b90729b65],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\b0625433-0826-4d86-9af6-bc28310b6329-3.job, , [215806755f1c82b44a7398232dd5cb35],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_majjphhgppkndjjkmhhnbgafooenebhd_0.localstorage, , [1c5d5625c1ba53e39188bc0041c1dd23],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_majjphhgppkndjjkmhhnbgafooenebhd_0.localstorage-journal, , [7ffae3988eed3006d5448c30ab570af6],
PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, , [8ced5823304b23136eac625b8b7749b7],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, , [1663a1daeb904ee8cce38043ca38837d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, , [5722b1ca13681f178501e8def2101de3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, , [5722b1ca13681f178501e8def2101de3],
Stolen.Data, C:\Users\Dome&Luke\AppData\Roaming\dclogs\2014-05-05-2.dc, , [1f5a23586615de58737d59413fc40cf4],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\install.ico, , [4b2e0f6cb7c4ff37f6a262985aa9a060],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\atl110.dll, , [4b2e0f6cb7c4ff37f6a262985aa9a060],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\fsupd.exe, , [4b2e0f6cb7c4ff37f6a262985aa9a060],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\msvcr110.dll, , [4b2e0f6cb7c4ff37f6a262985aa9a060],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\119.json, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\MessageBox.xml, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\uninstallDlg2.xml, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\bg.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\bg1.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\bk_shadow.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\button.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\button1.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\checkbox.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\checkbox_select.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\checked.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\close.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\loading_bg.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\loading_light.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\min.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\scrollbar.bmp, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\Thumbs.db, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\unchecked.png, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\code1.jpg, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\code2.jpg, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\code3.jpg, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\code4.jpg, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\code5.jpg, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\code6.jpg, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\images\code\Thumbs.db, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\log\UninstallManager_2014-05-26[16-52-50-918].log, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\webssearches\log\UninstallManager_2014-05-26[16-53-15-355].log, , [c3b6e19a502bcc6ad2866b2a28dae818],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\background.html, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\chromeCoreFilesIndex.txt, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\crossriderManifest.json, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\manifest.json, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\popup.html, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\manifest.xml, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins.json, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\1.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\102.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\103.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\104.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\13.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\14.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\155.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\17.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\177.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\182.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\183.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\184.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\19.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\190.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\191.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\195.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\207.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\21.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\211.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\22.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\220.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\226.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\233.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\242.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\246.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\28.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\4.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\47.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\64.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\7.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\72.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\78.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\80.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\9.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\91.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\93.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\plugins\97.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\userCode\background.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\extensionData\userCode\extension.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\icons\icon128.png, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\icons\icon16.png, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\icons\icon48.png, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\icons\actions\1.png, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\background.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\main.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\platformVersion.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api\chrome.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api\cookie.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api\message.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api\monitor.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api\pageAction.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\api\pageActionBG.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\app_api.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\bg_app_api.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\consts.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\cookie_store.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\crossriderAPI.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\delegate.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\events.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\extensionDataStore.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\installer.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\logFile.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\logging.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\onBGDocumentLoad.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\reports.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\storageWrapper.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\updateManager.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\util.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\xhr.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\popupResource\newPopup.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\1.26.27_0\js\lib\popupResource\popup.js, , [f683ff7cbebd71c555539ff655ad738d],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_majjphhgppkndjjkmhhnbgafooenebhd_0\3, , [75042952681365d1fbcd445148ba52ae],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_majjphhgppkndjjkmhhnbgafooenebhd_0\3-journal, , [75042952681365d1fbcd445148ba52ae],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\000571.ldb, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\000573.ldb, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\000594.ldb, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\000597.ldb, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\000598.log, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\CURRENT, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\LOCK, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\LOG, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\LOG.old, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.CrossRider.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\majjphhgppkndjjkmhhnbgafooenebhd\MANIFEST-000596, , [fc7da3d8b3c8181e31a36a2b8e745ca4],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Installbat64.dll, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Microsoft.Deployment.WindowsInstaller.dll, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Microsoft.Deployment.WindowsInstaller.xml, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfapi.dll, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfregdrv.exe, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\ProtocolFilters.dll, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\sample.dll, , [7aff0477ceadc76f37fd4951f40e3ec2],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\Installer.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\InstallerLibrary.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.InstallState, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\Newtonsoft.Json.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe.config, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\SQLite.Interop.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\System.Data.SQLite.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\win32.reg, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe.config, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\backup\InstallerLibrary.dll, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\backup\uninstall.exe, , [85f43348116a0a2ca26b9c0555ad57a9],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\AUTHORS.txt, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\config.txt, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\default.action, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\default.filter, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\LICENSE.txt, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\match-all.action, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\mgwz.dll, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.exe, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.log, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy_uninstall.exe, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\README.txt, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\trust.txt, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.action, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.action_empty, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.filter, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.filter_old, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\p_doc.css, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\coding.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\cvs.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\documentation.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\index.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\introduction.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\newrelease.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\testing.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\webserver-update.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\configuration.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\contact.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\copyright.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\general.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\index.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\installation.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\misc.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\trouble.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images\files-in-use.jpg, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images\proxy_setup.jpg, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\actions-file.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\appendix.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\config.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\configuration.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\contact.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\copyright.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\files-in-use.jpg, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\filter-file.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\index.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\installation.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\introduction.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\proxy2.jpg, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\proxy_setup.jpg, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\p_doc.css, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\quickstart.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\seealso.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\startup.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\templates.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\whatsnew.html, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\cgi-style.css, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\connect-failed, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-local-help, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-support-and-service, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-title, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-unstable-warning, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\no-such-domain, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\url-info-osd.xml, , [7702ff7c6d0e191d808ec3de30d250b0],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, , [1465f2894e2df4420d7c7d2720e25ba5],
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://istart.webssearches.com/?type=hppp&ts=1401709633&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX" ],), ,[df9a156639423bfb411ca50a47bdb14f]
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://istart.webssearches.com/?type=hppp&ts=1401709633&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX",), ,[67124833d9a2d75fc29c8a2500049a66]
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "search_url": "hxxp://istart.webssearches.com/web/?type=dspp&ts=1401709633&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX&q={searchTerms}",), ,[3a3fadce7b003afcbfa098177292a35d]
PUP.Optional.WebsSearches.A, C:\Users\Dome&Luke\AppData\Roaming\Mozilla\Firefox\Profiles\hqbj5sa2.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hppp&ts=1401709633&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX");), ,[1d5c3c3f2259d1654c0e604fea1aca36]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.212 - Bericht erstellt am 22/06/2014 um 11:23:29
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 3 (64 bits)
# Benutzername : Dome&Luke - DOMELUKE
# Gestartet von : C:\Users\Dome&Luke\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : IePluginServices
[#] Dienst Gelöscht : Update ScanTack
[#] Dienst Gelöscht : Util ScanTack
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\IePluginServices
Ordner Gelöscht : C:\ProgramData\Registry Helper
Ordner Gelöscht : C:\ProgramData\AlawarWrapper
Ordner Gelöscht : C:\Program Files (x86)\MSR
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Program Files (x86)\ScanTack
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Ordner Gelöscht : C:\Program Files\002
Ordner Gelöscht : C:\Users\DOME&L~1\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Dome&Luke\AppData\Local\Freesofttoday
Ordner Gelöscht : C:\Users\Dome&Luke\AppData\Local\Genesis
Ordner Gelöscht : C:\Users\Dome&Luke\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Dome&Luke\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Public\Documents\AlawarWrapper
[!] Ordner Gelöscht : C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Dome&Luke\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Datei Gelöscht : C:\Windows\System32\Tasks\fsupdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [InetStat]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Schlüssel Gelöscht : HKCU\Software\anchorfree
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\Registry Helper
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Dome&Luke\AppData\Roaming\Mozilla\Firefox\Profiles\hqbj5sa2.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "webssearches");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "webssearches");
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Dome&Luke\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={C8CFC73E-9BBE-11E2-A2F9-FB60159D735F}&crg=3.1010006.10037&st=23
Gelöscht [Search Provider] : hxxp://searchab.com/?aff=7&uid=3d6984e4-783e-11e2-8aa6-38607782ca6c&q={searchTerms}
Gelöscht [Search Provider] : hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPDTDF
Gelöscht [Search Provider] : hxxp://start.iminent.com/?appId=69D2C467-460E-4315-AB0F-2A65952B01E0&ref=toolbox&q={searchTerms}
Gelöscht [Search Provider] : hxxp://search.easylifeapp.com/?q={searchTerms}&pid=798&src=ch2&r=2013/03/29&hid=3816331264&lg=EN&cc=DE
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&affID=119816&babsrc=SP_ss&mntrId=FAC838607782CA6C
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3317933&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP1C810998-F2F0-49E9-B385-48F7B860CB9A&q={searchTerms}&SSPV=
Gelöscht [Search Provider] : hxxp://www.sm.de/?q={searchTerms}
Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1401709633&from=amt&uid=HitachiXHDS723020BLA642_MN1240F32X4DPD2X4DPDX&q={searchTerms}
Gelöscht [Extension] : majjphhgppkndjjkmhhnbgafooenebhd
*************************
AdwCleaner[R0].txt - [11923 octets] - [22/06/2014 11:12:46]
AdwCleaner[S0].txt - [5994 octets] - [22/06/2014 11:23:29]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6054 octets] ########## Mit Freundlichen Grüßen
doublepack |