lukasmueller | 21.08.2014 23:37 | Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-08-2014 01
Ran by Lukas Müller at 2014-08-21 22:47:50 Run:1
Running from C:\Users\Lukas Müller\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Run: [OjhuxFercu] => regsvr32.exe "
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2870272 2011-02-26] (Microsoft Corporation) <==== ATTENTION
*****************
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\Software\Microsoft\Windows\CurrentVersion\Run\\OjhuxFercu => value deleted successfully.
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully.
==== End of Fixlog ==== Code:
Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Suchlauf Datum: 21.08.2014
Suchlauf-Zeit: 23:30:45
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.21.07
Rootkit Datenbank: v2014.08.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7
CPU: x64
Dateisystem: NTFS
Benutzer: Lukas Müller
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 381138
Verstrichene Zeit: 15 Min, 9 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 2
PUP.Optional.FilesFrog.A, HKU\S-1-5-21-1935541172-1151020566-1174068504-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BI, Löschen bei Neustart, [a19a44852b5064d201ec6bc4010330d0],
PUP.Optional.Somoto.A, HKU\S-1-5-21-1935541172-1151020566-1174068504-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP, Löschen bei Neustart, [8ab1c108c8b3c27428f8210ecc38837d],
Registrierungswerte: 2
PUP.Optional.FilesFrog.A, HKU\S-1-5-21-1935541172-1151020566-1174068504-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BI|ui_path_filesfrog, HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker, Löschen bei Neustart, [a19a44852b5064d201ec6bc4010330d0]
PUP.Optional.Somoto.A, HKU\S-1-5-21-1935541172-1151020566-1174068504-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOMOTO\SDP|affid, mcpatcherpro, Löschen bei Neustart, [8ab1c108c8b3c27428f8210ecc38837d]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 13
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\defaults, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\defaults\preferences, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\userCode, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\locale, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\locale\en-US, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
Dateien: 108
PUP.Optional.Somoto, C:\$Recycle.Bin\S-1-5-21-1935541172-1151020566-1174068504-1000\$R61HZKC\uninstall.exe, In Quarantäne, [65d67752c8b3999d938fa483d32ddd23],
PUP.Optional.ExpressFiles.A, C:\Users\Lukas Müller\Downloads\Majesty_-_Hellforces_2006_(320k)_Power_Metal_downloader_de_99138.exe, In Quarantäne, [56e509c04932ef47007fd65254ac39c7],
Trojan.Miner.RCD, C:\Users\Lukas Müller\Downloads\Ti_nspire_Cas_1_crack.zip, In Quarantäne, [14278f3acdae350195df74ef5da4ce32],
PUP.Optional.YourFileDownloader, C:\Users\Lukas Müller\Downloads\Bodyjar_how_it_works_rar_downloader_de_98842.exe, In Quarantäne, [68d332972358ea4cb684928c837d8d73],
PUP.Optional.Softonic.A, C:\Users\Lukas Müller\Downloads\SoftonicDownloader_fuer_audiosurf.exe, In Quarantäne, [f942e5e4a4d739fdba5a39f305fc47b9],
PUP.Optional.Softonic.A, C:\Users\Lukas Müller\Downloads\SoftonicDownloader_fuer_camstudio.exe, In Quarantäne, [83b8ddecd2a939fd3dd7ca627e8330d0],
PUP.Optional.Softonic.A, C:\Users\Lukas Müller\Downloads\SoftonicDownloader_fuer_doodle-jump.exe, In Quarantäne, [c07b43862754b5810b0981ab54ad0df3],
PUP.Optional.Softonic.A, C:\Users\Lukas Müller\Downloads\SoftonicDownloader_fuer_java-development-kit.exe, In Quarantäne, [d566dfea8dee171f070d03291de47f81],
PUP.Optional.Bandoo, C:\Users\Lukas Müller\Downloads\iLividSetup(1).exe, In Quarantäne, [b88374557803e4522f87987d0001a65a],
PUP.Optional.Bandoo, C:\Users\Lukas Müller\Downloads\iLividSetup(2).exe, In Quarantäne, [112a02c74536a3930babdf361ae752ae],
PUP.Optional.Bandoo, C:\Users\Lukas Müller\Downloads\iLividSetup-r484-n-bf.exe, In Quarantäne, [93a8725797e455e14a6c5abb728f8f71],
PUP.Optional.Bandoo, C:\Users\Lukas Müller\Downloads\iLividSetup.exe, In Quarantäne, [57e411b891ea8da9714563b24ab75da3],
PUP.WirelessKeyView, C:\Users\Lukas Müller\Downloads\WirelessKeyView_1.60.zip, In Quarantäne, [4dee7d4cdd9edb5b80f316d325dfe51b],
PUP.Optional.Softonic.A, C:\Users\Lukas Müller\Downloads\SoftonicDownloader_fuer_soundtap.exe, In Quarantäne, [81ba8742a2d989adfa1ab37970919a66],
PUP.Optional.Bandoo, C:\Users\Lukas Müller\Videos\iLividSetup-r484-n-bu.exe, In Quarantäne, [76c5329785f6310551655eb7778a37c9],
PUP.Optional.YourfileDownloader.A, C:\Windows\System32\Tasks\YourFile DownloaderUpdate, In Quarantäne, [1f1ce2e718635fd7ff6bd91882805da3],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome.manifest, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\install.rdf, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\7286b3b0acacccb9ea4445eb928e9780.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\background.html, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\bb33c928eb89bc3d38c6b1151ffbe95d.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\browser.xul, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\d1345267ebef3a0b9af069875d62e22c.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\dialog.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\e200cc4abcf177c6638453f25f7c64a5.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\e907a53f114218c4148594c0d15527ce.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\options.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\options.xul, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\search_dialog.xul, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\501e6a74db6cb33ab1446636037b1cf7.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\02384ec02515c324d0f19b97364b7ed2.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\0885bb076f68d65554b95bb8ce871e2f.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\121e8880c8dfef3239babe31ea4274ea.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\1749bf9901dd04d1cf1409cd5aaaa6d7.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\2a5b5baed4a0d7b84c1dff3d7fca1c8d.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\311afd1becc097fd9940b05927cfcb7f.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\3dc919fc0bbfd18654c8bfe20803f2ff.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\484222622463eecf4e9165805e713473.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\5b4ac9bfdcb5c3918fdc94006cdc5c7c.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\659ad50d1ab607b7d92459338960c5ea.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\a0f1f3603f3ecf88ac769c8ddb9680da.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\cf52b31b1a68f9cfc7644c563a55832e.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\d0adf8d1b61d07b00d0cc4af4e03078e.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\e3d5b2af97f0b3173b24d322178bc48f.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\api\fc4751c9d16202fabe1a817f96694c25.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\92532e8bfc023a78c67960f2d18ea09b.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\0a1a8a8217189bc35b94847d7c7e4fc2.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\13e04401904329a7508eb54d5f3195c4.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\2f0ff050f671097d96d94c104434c0dd.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\393e90d3cc4e9bd2ebdf3e9ef27e19e7.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\401aacb951d5f0e04ee05d8bd6144981.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\45d3975e4671aa1b7867695d5f47e093.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\55e2e84bc427d2740a975b37aa338ef1.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\59265d7e8be8a5a2992c2fa57454dddb.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\6a53e349b7c27d41cb41ea797e5d780b.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\7350f1336e15019c682d77b797d5a1b5.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\7a879cf14e3aaeda6be27deba65bb91d.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\81858a5966c621b9979109274d6825c9.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\82fbb97348b59cfd5215ba199e1a9abb.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\b9502e04b3e78535c0613467c48e66a9.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\b9eaa48c0517938aeb807f350a8f76c4.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\e32db7705875df3b715c3c93831eaf75.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\e3d79593491ed8eea84141c9e6e5873a.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\e6f7587ab1ceee85f2698443c28ffe6e.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\f23c233bf6741c2eed06086118968353.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\chrome\content\core\installer.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\defaults\preferences\prefs.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\manifest.xml, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins.json, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\1.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\13.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\14.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\16.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\17.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\177.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\182.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\183.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\207.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\21.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\22.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\246.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\268.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\28.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\4.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\47.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\64.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\72.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\78.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\91.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\plugins\98.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\userCode\background.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\extensionData\userCode\extension.js, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\locale\en-US\translations.dtd, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\button1.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\button2.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\button3.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\button4.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\button5.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\crossrider_statusbar.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\icon128.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\icon16.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\icon24.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\icon48.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\panelarrow-up.png, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\popup.html, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\skin.css, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
PUP.Optional.CrossRider.A, C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\extensions\2f86d471-1122-4c15-901a-d7fd67316cd9@ca42b8d2-0eb6-47be-84a2-6d95abe186e8.com\skin\update.css, In Quarantäne, [102b2c9d1764dd595a91962b887ab749],
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile: Code:
# AdwCleaner v3.308 - Bericht erstellt am 22/08/2014 um 00:02:49
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium (64 bits)
# Benutzername : Lukas Müller - LUKASMÜLLER-PC
# Gestartet von : C:\Users\Lukas Müller\Downloads\adwcleaner_3.308.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : 70e6ca8c
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\NCH Software
Ordner Gelöscht : C:\Program Files (x86)\NCH Software
Datei Gelöscht : C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\foxydeal.sqlite
***** [ Tasks ] *****
Task Gelöscht : Express FilesUpdate
Task Gelöscht : YourFile DownloaderUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Wow6432Node\BabylonToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422412268}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422412268}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Somoto
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7600.17115
-\\ Mozilla Firefox v31.0 (x86 en-US)
[ Datei : C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [15735 octets] - [03/11/2013 17:06:53]
AdwCleaner[R1].txt - [1386 octets] - [03/11/2013 18:13:50]
AdwCleaner[R2].txt - [2696 octets] - [22/08/2014 00:01:07]
AdwCleaner[S0].txt - [14823 octets] - [03/11/2013 17:07:35]
AdwCleaner[S1].txt - [1345 octets] - [03/11/2013 18:15:40]
AdwCleaner[S2].txt - [2338 octets] - [22/08/2014 00:02:49]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2398 octets] ########## --- --- ---
[/CODE] Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Lukas Mller on 22.08.2014 at 0:14:22,81
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1935541172-1151020566-1174068504-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110211181110}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110211181110}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181110}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup(2)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup(2)_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r484-n-bf_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetup-r484-n-bf_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a2zLyrics-16-chromeinstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a2zLyrics-16-chromeinstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a2zLyrics-16-codedownloader_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a2zLyrics-16-codedownloader_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a2zLyrics-16-updater_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\a2zLyrics-16-updater_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup(2)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup(2)_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r484-n-bf_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetup-r484-n-bf_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\a2zLyrics-16-chromeinstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\a2zLyrics-16-chromeinstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\a2zLyrics-16-codedownloader_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\a2zLyrics-16-codedownloader_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\a2zLyrics-16-updater_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\a2zLyrics-16-updater_RASMANCS
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
Successfully deleted: [Empty Folder] C:\Users\Lukas Mller\appdata\local\{b27a93e9-67fa-cd94-2871-30cac4a5aa84}
~~~ FireFox
Emptied folder: C:\Users\Lukas Mller\AppData\Roaming\mozilla\firefox\profiles\r9rwaggt.default-1369339540531\minidumps [441 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.08.2014 at 0:19:30,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01
Ran by Lukas Müller (administrator) on LUKASMÜLLER-PC on 22-08-2014 00:34:49
Running from C:\Users\Lukas Müller\Desktop
Platform: Windows 7 Home Premium (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Windows\SysWOW64\ASGT.exe
() C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(WeGame.com, Inc.) C:\Program Files (x86)\WeGame\wgclientservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Lukas Müller\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2013-03-01] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [AdaptecDirectCD] => C:\Program Files (x86)\Roxio\WinOnCD 5 PE\DirectCD\DirectCD.exe [655360 2001-10-10] (Roxio)
HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Video_deluxe_15_Premium_Sonderedition\TrayServer.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RemoteControl11] => C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [237120 2013-03-01] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-14] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1753280 2014-07-16] (Valve Corporation)
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Run: [Facebook Update] => C:\Users\Lukas Müller\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-01-03] (Facebook Inc.)
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Run: [Spotify Web Helper] => C:\Users\Lukas Müller\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-07-18] (Spotify Ltd)
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...\Winlogon: [Shell] C:\Windows\Explorer.exe [2870272 2011-02-26] (Microsoft Corporation) <==== ATTENTION
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...0c966feabec1\InprocServer32: [Default-shell32] C:\Users\Lukas Müller\AppData\Local\{b27a93e9-67fa-cd94-2871-30cac4a5aa84}\n. ATTENTION! ====> ZeroAccess/Alureon?
HKU\S-1-5-21-1935541172-1151020566-1174068504-1000\...409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-1935541172-1151020566-1174068504-1000\$b27a93e967facd94287130cac4a5aa84\n. ATTENTION! ====> ZeroAccess?
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
SSODL-x32: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Lukas Müller\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6EA97C034F01CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - c:\Windows\System32\urlmon.dll (Microsoft Corporation)
Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - c:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.7601.17514_none_d1a4c8feac0dfcdb\urlmon.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.2.1 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.2.1 -> C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @esn/esnlaunch,version=1.110.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.118.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.132.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.132.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.140.0 -> C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Lukas Müller\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DownloadHelper - C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-08-08]
FF Extension: ProxTube - C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7}.xpi [2014-07-29]
FF Extension: Adblock Plus - C:\Users\Lukas Müller\AppData\Roaming\Mozilla\Firefox\Profiles\r9rwaggt.default-1369339540531\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-03]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013-05-22]
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1021008 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed]
R2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [85568 2013-03-01] ()
R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [77576 2013-03-11] (CyberLink)
R2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [294664 2013-03-11] (CyberLink)
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-06-29] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WeGameClientService; C:\Program Files (x86)\WeGame\WGClientService.exe [18472 2011-07-28] (WeGame.com, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-11-02] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-16] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S1 Cdr4_XP; C:\Windows\SysWow64\Drivers\Cdr4_XP.sys [55216 2001-09-18] (Roxio) [File not signed]
S1 Cdralw2k; C:\Windows\SysWow64\Drivers\Cdralw2k.sys [23561 2001-09-18] (Roxio) [File not signed]
S1 cdudf_xp; C:\Windows\SysWow64\Drivers\cdudf_xp.sys [233600 2001-10-10] (Roxio) [File not signed]
S3 dvd_2K; C:\Windows\SysWow64\Drivers\dvd_2K.sys [17958 2001-09-10] (Roxio) [File not signed]
S3 hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [111104 2009-02-08] (Guillemot Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-11-02] ()
S3 mmc_2K; C:\Windows\SysWow64\Drivers\mmc_2K.sys [19158 2001-10-10] (Roxio) [File not signed]
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S1 pwd_2K; C:\Windows\SysWow64\Drivers\pwd_2K.sys [79414 2001-10-10] (Roxio) [File not signed]
S3 Secdrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [14368 1999-09-27] () [File not signed]
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3552384 2009-04-22] ()
S3 TASCAM_US122144; C:\Windows\System32\Drivers\tascusb2.sys [419160 2011-04-28] (TASCAM)
S3 TASCAM_US122L_MK2_MIDI; C:\Windows\System32\drivers\tscusb2m.sys [31576 2011-04-28] (TASCAM)
S3 TASCAM_US122L_MK2_WDM; C:\Windows\System32\drivers\tscusb2a.sys [53080 2011-04-28] (TASCAM)
R3 tbs5922vhid; C:\Windows\System32\drivers\tbs5922vhid.sys [23728 2014-03-07] (Windows (R) Win 7 DDK provider)
R2 TBS_TBS5922BDA; C:\Windows\System32\DRIVERS\tbs5922.sys [86064 2014-03-07] (TBS )
S1 UdfReadr_xp; C:\Windows\SysWow64\Drivers\UdfReadr_xp.sys [205440 2001-10-10] (Roxio) [File not signed]
S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [130320 2013-03-11] (CyberLink Corp.)
R4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-22 00:34 - 2014-08-22 00:34 - 00019031 _____ () C:\Users\Lukas Müller\Desktop\FRST.txt
2014-08-22 00:14 - 2014-08-22 00:14 - 01016261 _____ (Thisisu) C:\Users\Lukas Müller\Downloads\JRT.exe
2014-08-22 00:14 - 2014-08-22 00:14 - 00000000 ____D () C:\Windows\ERUNT
2014-08-22 00:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-22 00:00 - 2014-08-22 00:00 - 01364531 _____ () C:\Users\Lukas Müller\Downloads\adwcleaner_3.308.exe
2014-08-21 23:28 - 2014-08-21 23:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 23:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-21 23:27 - 2014-08-21 23:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas Müller\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-21 22:31 - 2014-08-21 22:31 - 00001287 _____ () C:\Users\Lukas Müller\Desktop\Revo Uninstaller.lnk
2014-08-21 22:31 - 2014-08-21 22:31 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-21 22:30 - 2014-08-21 22:30 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lukas Müller\Downloads\revosetup95.exe
2014-08-19 14:32 - 2014-08-19 14:33 - 00043783 _____ () C:\Users\Lukas Müller\Desktop\Addition.txt
2014-08-19 14:28 - 2014-08-22 00:34 - 00000000 ____D () C:\FRST
2014-08-19 14:27 - 2014-08-19 14:27 - 02101760 _____ (Farbar) C:\Users\Lukas Müller\Desktop\FRST64.exe
2014-08-18 20:09 - 2014-08-18 20:09 - 03755599 _____ () C:\Users\Lukas Müller\Downloads\nvoglv32.zip
2014-08-18 19:33 - 2014-08-18 19:33 - 00000052 _____ () C:\Windows\avmcoins.log
2014-08-18 19:04 - 2014-08-18 19:04 - 00000000 ____D () C:\ProgramData\GroupPolicy
2014-08-18 18:48 - 2014-08-18 18:48 - 02350493 _____ () C:\re-regdll.bat
2014-08-18 18:12 - 2014-08-18 18:12 - 00000000 ____D () C:\Windows\pss
2014-08-18 16:47 - 2014-08-18 16:47 - 00282488 _____ () C:\Windows\Minidump\081814-35973-01.dmp
2014-08-18 15:41 - 2014-08-18 17:00 - 00000000 ____D () C:\ProgramData\IvhacVucqu
2014-08-18 15:17 - 2014-08-21 23:52 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-18 15:17 - 2014-08-18 17:21 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-18 15:15 - 2014-08-18 17:00 - 00000000 ____D () C:\Users\Lukas Müller\Desktop\mbar
2014-08-18 15:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-18 15:05 - 2014-08-18 15:06 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Lukas Müller\Desktop\mbar-1.07.0.1012.exe
2014-08-18 02:18 - 2014-08-18 16:20 - 00000000 ____D () C:\ProgramData\AfivkArxum
2014-08-18 00:52 - 2014-08-18 00:55 - 00000000 ____D () C:\ProgramData\OjhuxFercu
2014-08-18 00:05 - 2014-08-18 16:10 - 00000000 ____D () C:\ProgramData\OjyisHanat
2014-08-18 00:05 - 2014-08-18 02:18 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-14 22:06 - 2014-08-17 20:37 - 00001482 _____ () C:\Users\Lukas Müller\AppData\Local\RecConfig.xml
2014-08-14 22:06 - 2014-08-14 22:06 - 00001042 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2014-08-14 22:06 - 2014-08-14 22:06 - 00001030 _____ () C:\Users\Public\Desktop\Audacity.lnk
2014-08-14 22:02 - 2014-08-14 22:02 - 00001071 _____ () C:\Users\Lukas Müller\Desktop\No23 Recorder.lnk
2014-08-14 22:02 - 2014-08-14 22:02 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
2014-08-14 22:02 - 2014-08-14 22:02 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Local\No23 Recorder
2014-08-14 22:01 - 2014-08-14 22:01 - 02497825 _____ (No23) C:\Users\Lukas Müller\Downloads\No23Recorder2103.exe
2014-08-10 16:12 - 2014-08-10 16:12 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Local\SKIDROW
2014-08-10 15:04 - 2014-08-10 15:28 - 00000000 ____D () C:\Users\Lukas Müller\Downloads\Tony Hawk's Pro Skater HD
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-22 00:35 - 2014-08-22 00:34 - 00019031 _____ () C:\Users\Lukas Müller\Desktop\FRST.txt
2014-08-22 00:34 - 2014-08-19 14:28 - 00000000 ____D () C:\FRST
2014-08-22 00:23 - 2013-11-23 20:23 - 00000000 ____D () C:\Users\Lukas Müller\Desktop\riffs
2014-08-22 00:14 - 2014-08-22 00:14 - 01016261 _____ (Thisisu) C:\Users\Lukas Müller\Downloads\JRT.exe
2014-08-22 00:14 - 2014-08-22 00:14 - 00000000 ____D () C:\Windows\ERUNT
2014-08-22 00:12 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-22 00:12 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-22 00:08 - 2009-07-14 19:58 - 00719388 _____ () C:\Windows\system32\perfh007.dat
2014-08-22 00:08 - 2009-07-14 19:58 - 00159988 _____ () C:\Windows\system32\perfc007.dat
2014-08-22 00:08 - 2009-07-14 07:13 - 01712474 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-22 00:05 - 2012-10-31 19:28 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-22 00:04 - 2011-12-30 22:46 - 00000012 _____ () C:\ProgramData\DirectCDUserName.txt
2014-08-22 00:04 - 2011-11-02 19:48 - 00432136 _____ () C:\Windows\PFRO.log
2014-08-22 00:04 - 2011-11-02 15:53 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-22 00:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-22 00:04 - 2009-07-14 06:51 - 00211744 _____ () C:\Windows\setupact.log
2014-08-22 00:03 - 2011-11-02 15:18 - 02066760 _____ () C:\Windows\WindowsUpdate.log
2014-08-22 00:02 - 2013-11-03 17:06 - 00000000 ____D () C:\AdwCleaner
2014-08-22 00:00 - 2014-08-22 00:00 - 01364531 _____ () C:\Users\Lukas Müller\Downloads\adwcleaner_3.308.exe
2014-08-21 23:52 - 2014-08-18 15:17 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-21 23:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\security
2014-08-21 23:28 - 2014-08-21 23:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-21 23:28 - 2014-08-21 23:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lukas Müller\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-21 23:28 - 2013-11-03 17:21 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-21 23:28 - 2013-11-03 17:21 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Malwarebytes
2014-08-21 23:28 - 2013-11-03 17:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-21 22:42 - 2011-12-25 16:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-08-21 22:31 - 2014-08-21 22:31 - 00001287 _____ () C:\Users\Lukas Müller\Desktop\Revo Uninstaller.lnk
2014-08-21 22:31 - 2014-08-21 22:31 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-21 22:30 - 2014-08-21 22:30 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lukas Müller\Downloads\revosetup95.exe
2014-08-21 22:19 - 2013-01-03 20:14 - 00000956 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1935541172-1151020566-1174068504-1000UA.job
2014-08-21 19:19 - 2013-01-03 20:14 - 00000934 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1935541172-1151020566-1174068504-1000Core.job
2014-08-19 15:19 - 2012-07-10 17:22 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Skype
2014-08-19 14:33 - 2014-08-19 14:32 - 00043783 _____ () C:\Users\Lukas Müller\Desktop\Addition.txt
2014-08-19 14:27 - 2014-08-19 14:27 - 02101760 _____ (Farbar) C:\Users\Lukas Müller\Desktop\FRST64.exe
2014-08-18 20:09 - 2014-08-18 20:09 - 03755599 _____ () C:\Users\Lukas Müller\Downloads\nvoglv32.zip
2014-08-18 19:33 - 2014-08-18 19:33 - 00000052 _____ () C:\Windows\avmcoins.log
2014-08-18 19:04 - 2014-08-18 19:04 - 00000000 ____D () C:\ProgramData\GroupPolicy
2014-08-18 19:02 - 2014-05-12 19:37 - 01611120 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-08-18 18:48 - 2014-08-18 18:48 - 02350493 _____ () C:\re-regdll.bat
2014-08-18 18:12 - 2014-08-18 18:12 - 00000000 ____D () C:\Windows\pss
2014-08-18 17:21 - 2014-08-18 15:17 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-18 17:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\TAPI
2014-08-18 17:00 - 2014-08-18 15:41 - 00000000 ____D () C:\ProgramData\IvhacVucqu
2014-08-18 17:00 - 2014-08-18 15:15 - 00000000 ____D () C:\Users\Lukas Müller\Desktop\mbar
2014-08-18 16:47 - 2014-08-18 16:47 - 00282488 _____ () C:\Windows\Minidump\081814-35973-01.dmp
2014-08-18 16:47 - 2011-11-05 18:00 - 00000000 ____D () C:\Windows\Minidump
2014-08-18 16:20 - 2014-08-18 02:18 - 00000000 ____D () C:\ProgramData\AfivkArxum
2014-08-18 16:10 - 2014-08-18 00:05 - 00000000 ____D () C:\ProgramData\OjyisHanat
2014-08-18 15:06 - 2014-08-18 15:05 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Lukas Müller\Desktop\mbar-1.07.0.1012.exe
2014-08-18 02:18 - 2014-08-18 00:05 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-18 00:55 - 2014-08-18 00:52 - 00000000 ____D () C:\ProgramData\OjhuxFercu
2014-08-17 20:51 - 2014-03-22 17:43 - 00000000 ____D () C:\Users\Lukas Müller\Desktop\Neuer Ordner
2014-08-17 20:37 - 2014-08-14 22:06 - 00001482 _____ () C:\Users\Lukas Müller\AppData\Local\RecConfig.xml
2014-08-17 20:29 - 2012-10-23 20:37 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Spotify
2014-08-17 14:54 - 2011-12-25 16:50 - 00000000 ____D () C:\Users\Lukas Müller\Documents\DVDVideoSoft
2014-08-15 23:00 - 2013-09-08 14:39 - 00001064 _____ () C:\Users\Lukas Müller\Desktop\Dropbox.lnk
2014-08-15 23:00 - 2013-09-08 14:35 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-15 23:00 - 2012-06-14 22:32 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Dropbox
2014-08-15 20:36 - 2013-11-18 19:37 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Audacity
2014-08-14 22:06 - 2014-08-14 22:06 - 00001042 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2014-08-14 22:06 - 2014-08-14 22:06 - 00001030 _____ () C:\Users\Public\Desktop\Audacity.lnk
2014-08-14 22:06 - 2013-11-18 19:37 - 00000000 ____D () C:\Program Files (x86)\Audacity
2014-08-14 22:02 - 2014-08-14 22:02 - 00001071 _____ () C:\Users\Lukas Müller\Desktop\No23 Recorder.lnk
2014-08-14 22:02 - 2014-08-14 22:02 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No23 Recorder
2014-08-14 22:02 - 2014-08-14 22:02 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Local\No23 Recorder
2014-08-14 22:01 - 2014-08-14 22:01 - 02497825 _____ (No23) C:\Users\Lukas Müller\Downloads\No23Recorder2103.exe
2014-08-13 22:39 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-12 23:00 - 2012-01-15 16:31 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Roaming\uTorrent
2014-08-12 03:54 - 2012-10-23 20:38 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Local\Spotify
2014-08-11 14:19 - 2012-07-10 17:21 - 00000000 ____D () C:\ProgramData\Skype
2014-08-10 16:12 - 2014-08-10 16:12 - 00000000 ____D () C:\Users\Lukas Müller\AppData\Local\SKIDROW
2014-08-10 16:12 - 2011-12-19 15:42 - 00000000 ____D () C:\Users\Lukas Müller\Documents\My Games
2014-08-10 15:28 - 2014-08-10 15:04 - 00000000 ____D () C:\Users\Lukas Müller\Downloads\Tony Hawk's Pro Skater HD
2014-08-08 22:35 - 2014-07-06 15:52 - 00001873 _____ () C:\Users\Lukas Müller\Desktop\virtual dj.txt
2014-08-01 00:16 - 2013-06-22 13:06 - 00000000 ____D () C:\Users\Lukas Müller\Documents\Flight Simulator X-Dateien
2014-07-30 17:10 - 2013-05-22 18:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
ZeroAccess:
C:\Users\Lukas Müller\AppData\Local\{b27a93e9-67fa-cd94-2871-30cac4a5aa84}
C:\Users\Lukas Müller\AppData\Local\{b27a93e9-67fa-cd94-2871-30cac4a5aa84}\@
C:\Users\Lukas Müller\AppData\Local\{b27a93e9-67fa-cd94-2871-30cac4a5aa84}\U\00000001.@
C:\Users\Lukas Müller\AppData\Local\{b27a93e9-67fa-cd94-2871-30cac4a5aa84}\U\800000cb.@
Files to move or delete:
====================
C:\Users\Lukas Müller\jagex_cl_runescape_LIVE.dat
C:\Users\Lukas Müller\random.dat
C:\Users\Lukas Müller\AppData\Roaming\skype.ini
Some content of TEMP:
====================
C:\Users\Lukas Müller\AppData\Local\Temp\avgnt.exe
C:\Users\Lukas Müller\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-18 19:30
==================== End Of Log ============================ --- --- ---
--- --- ---
[/CODE] |