Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Es erscheint beim Starten die meldung: Die Ausnahme "unknown software exception" (0 (https://www.trojaner-board.de/165946-erscheint-beim-starten-meldung-ausnahme-unknown-software-exception-0-a.html)

daggimaus 09.04.2015 14:43

Es erscheint beim Starten die meldung: Die Ausnahme "unknown software exception" (0
 
Liste der Anhänge anzeigen (Anzahl: 1)
Gu:rofl:ten Tag,

ich habe das Betriebssystem Windows 7 und seit einigen Tagen riesige Probleme. Wenn ich den All-in-One-Computer vom Energie-Sparmodus wieder hochfahren möchte, geht es sehr häufig nicht und ich muss ihn direkt am Schalter anschalten. Dann wird ab und zu nachgefragt, ob ich die Starhilfe benutzen möchte. Wenn ich das bestätige, läuft alles wieder es erscheint allerdings die Meldung, die ich Ihnen als Dateianhang mitschicke.

Auf Ihren Hilfeseiten habe ich mich nun schlau gemacht und das Programm Malwarebytes downgeloadet. Dies habe ich dann genau nach Ihrer Anleitung eingesetzt. Folgende Datei erhalten Sie zu Ihrer Information. Ich habe den Computr auch eine Systemwiederherstellung auf eine frühere Version vorgenommen. Es hilft aber alles nichts.
Es wäre schön, wenn Sie mir helfen könnten.
Mit freundlichen Grüßen

schrauber 09.04.2015 14:55

Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.
Ich kann auf Arbeit keine Anhänge öffnen, danke.

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

daggimaus 09.04.2015 17:46

Folgende Meldungen kommen, wenn ich den Computer neu starte: Die Ausnhme "unknown software exception" (0x0000409) ist in der Anwendung an der Stelle 0x5e7242ef aufgetreten. Klicken Sie auf "OK", um das Programm zu beenden.
Folgende Meldung kam auchg einmal: C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll ist entweder nicht für die Ausführung unter Windows vorgesehen oder enthält einen Fehler. Installieren Sie das Programm mit den Originalinstallationsmedien erneut, oder wenden Sie sich an den Systemadministrator oder Softwarelieferanten, um Unterstützung zu erhalten.
Nachfolgend die Meldung des Programms
Malwarebytes
CODE]Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software

Suchlauf Datum: 09.04.2015
Suchlauf-Zeit: 11:21:38
Logdatei: Malwaare.txt
Administrator: Ja

Version: 2.01.4.1018
Malware Datenbank: v2015.04.09.03
Rootkit Datenbank: v2015.03.31.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7
CPU: x86
Dateisystem: NTFS
Benutzer: Dadmar Petri

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 470681
Verstrichene Zeit: 12 Min, 48 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente gefunden)

Module: 0
(Keine schädliche Elemente gefunden)

Registrierungsschlüssel: 53
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, , [66213931761479bd531fed4fc43fef11],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [55326604e5a565d13418680cf211f709],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, , [55326604e5a565d13418680cf211f709],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, , [55326604e5a565d13418680cf211f709],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, , [bfc83c2ebad0ff3767ed2d4356ad3dc3],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, , [bfc83c2ebad0ff3767ed2d4356ad3dc3],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, , [bfc83c2ebad0ff3767ed2d4356ad3dc3],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, , [bfc83c2ebad0ff3767ed2d4356ad3dc3],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, , [bfc83c2ebad0ff3767ed2d4356ad3dc3],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, , [bfc83c2ebad0ff3767ed2d4356ad3dc3],
PUP.Optional.SupTab.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [3651df8b860421153ca1211a58abd927],
PUP.Optional.SupTab.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [3651df8b860421153ca1211a58abd927],
PUP.Optional.SupTab.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [3651df8b860421153ca1211a58abd927],
PUP.Optional.SupTab.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [3651df8b860421153ca1211a58abd927],
PUP.Optional.SupTab.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [3651df8b860421153ca1211a58abd927],
PUP.Optional.SupTab.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [3651df8b860421153ca1211a58abd927],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004

Code:

PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.WordProser.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3EBB5099-9732-48AE-B032-58B702D86EEC}, , [a1e661095b2ffa3cd29c45ef58ab2cd4],
PUP.Optional.CinemaxMe.A, HKLM\SOFTWARE\CinemaxMe-version2.0, , [7413adbd7e0c989e9f021cb7857e1ce4],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\HQ Pro Video 1.6V19.11, , [0c7b16542e5c73c306c2993afd06f10f],
PUP.Optional.MBot.A, HKLM\SOFTWARE\MYBESTOFFERSTODAY, , [cfb89dcd444624128848d10faf54a65a],
PUP.Optional.SpeedChecker.A, HKLM\SOFTWARE\Speedchecker Limited, , [96f10c5e2c5e6bcb73b000ce06fd649c],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\webssearchesSoftware, , [b3d4bcaebdcd9a9c09998e71649f9e62],
PUP.Optional.WordProser.A, HKLM\SOFTWARE\WordProser_1.10.0.2, , [8ef9a4c65238231330c816bf52b1639d],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, , [a9de6bff4c3e171fe084f94aa362bb45],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, , [8ef971f9dfab80b684e1e45fba4b2ad6],
PUP.Optional.WordProser.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wpnfd_1_10_0_2, , [6e19bdad701ac076e5126c69aa59b44c],
PUP.Optional.CinemaxMe.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\CinemaxMe-version2.0, , [177093d78a00ba7c5251b023a55e3fc1],
PUP.Optional.CrossRider.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\HQ Pro Video 1.6V19.11, , [0c7b90daf6949a9ca129f1e2689bb44c],
PUP.Optional.ClicUp.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\clicup, , [4641d1995436fc3a67bd7b4d22e1e11f],
PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\StormWatchApp, , [35529fcb84065fd73d1ea036867d8d73],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\SupHpUISoft, , [cabdb7b3256551e5c1568c55a95a867a],
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\TutoTag, , [cdbaf773137756e04b3f58eb8f765aa6],
PUP.Optional.CinemaxMe.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\APPDATALOW\SOFTWARE\CinemaxMe-version2.0, , [32551e4caedcc175faa9686b669d13ed],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, , [1a6d5614f89278be9ce3e35b2bda1be5],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\APPDATALOW\SOFTWARE\HQ Pro Video 1.6V19.11, , [97f0a9c102880333dbef04cfe71c41bf],
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, , [3552acbecfbba88ebfb1d1e97e8517e9],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [e3a42a40cfbb68ceefa5000b04007a86],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLCORE, , [8dfabdad830778be95d25ac774913ac6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, , [087f39317f0bcb6b1abd3d9e51b28e72],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\31163, , [b2d57eec96f4bb7bf3e4c51629da33cd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQ VideoV19.11, , [addad1994743979fd2dd88485da66f91],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\SBG, , [3453402a8a00bc7aae7939865ca74db3],
PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\SMARTBAR, , [8502eb7fe5a5b581f918241e71944bb5],
PUP.Optional.CinemaxMe.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\APPDATALOW\SOFTWARE\CinemaxMe-version2.0, , [1c6b056508824beb2d762da62ad99d63],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [43441654543690a6d5aab67f29dc9d63],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\APPDATALOW\SOFTWARE\HQ Pro Video 1.6V19.11, , [aadd84e6068484b23694fad956aded13],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [98ef4723c2c85dd93da81387748fcf31],
PUP.Optional.ClicUp.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\clicup, , [96f13b2f9eec8ea8d936e4cef0132bd5],

Registrierungswerte: 9
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, , [4b3c61096327f73fcf80d40ae221bf41]
PUP.Optional.MBot.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mbot_de_292, , [afd84a20800ac571517e7c6417eca35d],
PUP.Optional.WordProser.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{d9a96531-b093-4d07-9e4c-9704a365c441}, C:\Program Files\Mozilla Firefox\extensions\{d9a96531-b093-4d07-9e4c-9704a365c441}, , [553294d6602a9f97f351bc16c63de61a]
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, Firefox, , [3552acbecfbba88ebfb1d1e97e8517e9]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\INSTALLCORE|tb, 0N2X1N, , [8dfabdad830778be95d25ac774913ac6]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [71160e5c0e7cff3787759e4815ee2ad6]
PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\SMARTBAR|publisher, ShoppingHelper, , [8502eb7fe5a5b581f918241e71944bb5]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [a4e393d78dfd072f2bd130b6986b22de]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [64235d0d6d1df046f804e105758e2bd5]

Registrierungsdaten: 11
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}),,[454276f42d5df83ee2ad559ca85df20e]
PUP.Optional.WebsSearches, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126),,[6522ed7d8901bd798867eb05e32242be]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}),,[56313931296175c1ff911fd2679e44bc]
PUP.Optional.WebsSearches, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126),,[bacd0e5c375369cd7877a24e4bba857b]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}),,[e6a1402ae2a8cf674948f0013cc93cc4]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}),,[afd8fd6d39515dd9256b4ca535d05ea2]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,),,[17703f2b85056dc9f39eb63b986df010]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}),,[6e19ea8037530c2ae3ae59989273f907]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}),,[2463f2783852ca6ca3ee04ed26df50b0]
PUP.Optional.WebsSearches, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126),,[e89fc5a542483afcfcf330c08085d12f]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}),,[13743c2e236790a66927628f9b6a26da]

Ordner: 196
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\userCode, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\locale, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\locale\en-US, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode, , [cabd8cde57336dc9b8c22b8edf2455ab],

Code:

aming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\skin, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\chrome, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\chrome\content, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\extensionData, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\locale, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\locale\en-US, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\skin, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\chrome, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\chrome\content, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\extensionData, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\locale, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\locale\en-US, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch, , [50375f0b4d3d32044939894542c16f91],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\locales, , [50375f0b4d3d32044939894542c16f91],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\plugin, , [50375f0b4d3d32044939894542c16f91],
PUP.Optional.AdPeak.A, C:\temp, , [abdc0367305aa3939de667888a7925db],
PUP.Optional.InetStat.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat, , [454259118cfecf67d3a832171aeb1fe1],
Rogue.Multiple, C:\ProgramData\4001812108, , [d8afa5c54743e551dfa976fffc0720e0],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\Firefox, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\Firefox\chrome, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\Firefox\chrome\content, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\IE, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\protect, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\protect\files, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.ValueAppsplugin.A, C:\Users\Dagmar\AppData\Local\Conduit\ValueApps, , [7413a5c596f4bd79dcecb6d0fc075ba5],
PUP.Optional.ValueAppsplugin.A, C:\Users\Dagmar\AppData\Local\Conduit\ValueApps\IE, , [7413a5c596f4bd79dcecb6d0fc075ba5],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf, , [5b2c21493852bf77043adfa8fe0519e7],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0, , [5b2c21493852bf77043adfa8fe0519e7],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\extensionData, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\extensionData\plugins, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\extensionData\userCode, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js\api, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js\lib, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js\lib\popupResource, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\extensionData, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\extensionData\plugins, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\extensionData\userCode, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js\api, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js\lib, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js\lib\popupResource, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\extensionData, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\extensionData\plugins, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\extensionData\userCode, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js\api, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js\lib, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js\lib\popupResource, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\api, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\core, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults\preferences, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\plugins, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\userCode, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\api, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\core, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults\preferences, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\plugins, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\userCode, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\api, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\core, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults\preferences, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\plugins, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\userCode, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\defaults, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\defaults\preferences, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\extensionData, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\extensionData\plugins, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\api, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\core, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults\preferences, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\plugins, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\userCode, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content\browser, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content\external, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content\newtab, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\defaults, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\defaults\preferences, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin\plugins, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin\plugins\images, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin\plugins\images\info, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\defaults, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\defaults\preferences, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\addon-kit, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\addon-kit\lib, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\event, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\addon, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\content, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\dom, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\events, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\private-browsing, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\system, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\tabs, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\traits, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\utils, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\window, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\windows, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\SavingsBull, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\SavingsBull\lib, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SystemSpeedup, C:\Users\Dagmar\AppData\Roaming\Systweak\ssd, , [5b2c39317d0d7cbafa0e6535f60da15f],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.438_0, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.438_0\libraries, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.438_0\resources, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.GlobalUpdate.A, C:\Users\Dadmar Petri\AppData\Local\Temp\comh.211717, , [98ef4723c2c85dd93da81387748fcf31],
PUP.Optional.GlobalUpdate.A, C:\Users\Dadmar Petri\AppData\Local\Temp\comh.343706, , [087f4129cbbfbc7a8d585a40768d9c64],
PUP.Optional.GlobalUpdate.A, C:\Users\Dadmar Petri\AppData\Local\Temp\comh.73275, , [177059119af03cfa37ae3e5c41c2d32d],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC, , [7d0aef7b2664d85e2abb9e07659e20e0],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_d4mojvjqeqnf3ie1sd0zw2zjiklefrb4, , [7d0aef7b2664d85e2abb9e07659e20e0],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_d4mojvjqeqnf3ie1sd0zw2zjiklefrb4\1.5.0.0, , [7d0aef7b2664d85e2abb9e07659e20e0],
PUP.Optional.WordProser.A, C:\Program Files\WordProser_1.10.0.5, , [a7e016541674181e7f8e41668f748c74],
PUP.Optional.WordProser.A, C:\Program Files\WordProser_1.10.0.5\3rd Party Licenses, , [a7e016541674181e7f8e41668f748c74],
PUP.Optional.CinemaxMe.A, C:\Program Files\CinemaxMe-version2.0, , [99ee6a00810956e0520cb8f08e7517e9],
PUP.Optional.VOPackage.A, C:\Users\Dagmar\AppData\Roaming\VOPackage, , [4a3d3733fa9012240012ae027291ab55],
PUP.Optional.ClicUp.A, C:\Users\Dadmar Petri\AppData\Local\clicup, , [96f13b2f9eec8ea8d936e4cef0132bd5],

Dateien: 1125
PUP.Optional.NationZoom.A, C:\Users\Dagmar\AppData\Roaming\nationzoom\nationzoom.exe, , [711686e4fe8c3204029af6390af605fb],
PUP.Optional.SkyTech.A, C:\Users\Dagmar\AppData\Roaming\nationzoom\UpDate.dll, , [3d4acaa014761e18c5ac24e105fd21df],
PUP.Optional.Conduit.A, C:\Users\Dagmar\AppData\Roaming\ValueApps\CH\TBVerifier.dll, , [22655f0bed9d59dd0ac8f84c43bd7090],
PUP.Optional.SilenceInstall, C:\Users\Dagmar\AppData\Roaming\VOPackage\Uninstall.exe, , [9aed0b5f0d7d2016ac4e310b857bb14f],
PUP.Optional.CrossRider.A, C:\Program Files\CinemaxMe-version2.0\utils.exe, , [483fe98199f16fc7296bea6024dc0af6],
PUP.Optional.Netfilter, C:\temp\InstallFilter32.msi, , [aaddf377f496989e8493c0ab728e7a86],
PUP.Optional.Clara.A, C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\bobrowser_3010-10494ef2.exe, , [89fe2941484240f6e203f8e948b9a15f],
PUP.Optional.Wajam.A, C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\WIE_2.18.1.8.exe, , [2d5abdad008a6cca5389b7afb24ec33d],
PUP.Optional.Bundle, C:\Users\Dadmar Petri\AppData\Local\Temp\D197tmp\lly_omiga-plus.exe, , [3255dd8d7614e65069f2c933d031c040],
PUP.Optional.ShoppingHelper.A, C:\Users\Dadmar Petri\AppData\Local\Temp\4E90tmp\shoppinhelper2_setup2c2.3.11.exe, , [b6d1a6c46228b5817576331a4ab626da],
PUP.Optional.ShoppingHelper.A, C:\Users\Dadmar Petri\AppData\Local\Temp\DA3Ctmp\shoppinhelper2_setup2c2.3.11.exe, , [bdcaf4767e0cc274bf2c2e1fec14e51b],
PUP.Optional.InstallCore.SID.A, C:\Users\Dadmar Petri\Downloads\avira-free-antivirus_setup.exe, , [315612589ceee551051cbe79a95d15eb],
PUP.Optional.RegCleanPro, C:\Users\Dagmar\Downloads\rcpsetupmarm1_marm1203911984de_aotest.exe, , [32559bcffa90280e3c7c32047b8515eb],
PUP.Optional.RegCleanerPro, C:\Users\Dagmar\Downloads\rcpsetup_ad_de_8044_ad_de_8044 (1).exe, , [3d4a165498f232040fc151e94ab77987],
PUP.Optional.RegCleanerPro, C:\Users\Dagmar\Downloads\rcpsetup_ad_de_8044_ad_de_8044 (2).exe, , [8007bfab246675c13a964af0b8499f61],
PUP.Optional.RegCleanerPro, C:\Users\Dagmar\Downloads\rcpsetup_ad_de_8044_ad_de_8044.exe, , [9deaa3c74347d85ea12fb783c23f7987],
PUP.Optional.RegCleanPro, C:\Users\Dagmar\Downloads\rcpsetup_chip_de_chip_de.exe, , [c5c2323801897cbad7e18babde22a25e],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormUpdater.exe, , [c6c1e189d2b8a591ca7f3cae58a99e62],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatch.exe, , [22654d1d54365cda5d1c193ee21ef30d],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchApp.exe, , [45428edc35557abceb8e97c0a25e08f8],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchappuninstall.exe, , [05821b4fa2e866d089f086d13ac6a55b],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchBrowser.exe, , [1b6cdb8fd4b61c1a8eebe671728ee719],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\AnyProtectScannerSetup.exe, , [cdbada904a4086b04a8296a044c21fe1],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsa76A9.tmp, , [f59259118efc70c6c80439fdfe0802fe],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsd4C2C.tmp, , [f09751194e3cb87e795392a44db935cb],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsf87D7.tmp, , [a5e27ded8802003607c5be78020442be],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsn204F.tmp, , [abdc630721692412b21ae353dc2a0000],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\crossrider_statusbar.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button1.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button2.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button3.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button4.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button5.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon128.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon16.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon24.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon48.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\panelarrow-up.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\popup.html, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\skin.css, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\update.css, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\install.rdf, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\background.html, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\browser.xul, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\ffCoreFilesIndex.txt, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\options.xul, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\search_dialog.xul, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\manifest.xml, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\plugins.json, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\locale\en-US\translations.dtd, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png, , [6e190664bdcd80b6c2b8c9f08c778c74],


daggimaus 09.04.2015 17:47

Code:

aming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\skin, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\chrome, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\chrome\content, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\extensionData, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\locale, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\DTYMKB5583855@IMJS61442498.com\locale\en-US, , [b1d634368307ad89f4865e5be81b837d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\skin, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\chrome, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\chrome\content, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\extensionData, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\locale, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\PSFUZ20278470@LYMGVWA85453608.com\locale\en-US, , [d8af68028505c571e4962792b94a936d],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch, , [50375f0b4d3d32044939894542c16f91],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\locales, , [50375f0b4d3d32044939894542c16f91],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\plugin, , [50375f0b4d3d32044939894542c16f91],
PUP.Optional.AdPeak.A, C:\temp, , [abdc0367305aa3939de667888a7925db],
PUP.Optional.InetStat.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat, , [454259118cfecf67d3a832171aeb1fe1],
Rogue.Multiple, C:\ProgramData\4001812108, , [d8afa5c54743e551dfa976fffc0720e0],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\Firefox, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\Firefox\chrome, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\Firefox\chrome\content, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\IE, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\protect, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.OKitSpace.A, C:\Users\Dagmar\AppData\Roaming\okitspace\protect\files, , [a9de5812d2b860d63a40aadbba49bb45],
PUP.Optional.ValueAppsplugin.A, C:\Users\Dagmar\AppData\Local\Conduit\ValueApps, , [7413a5c596f4bd79dcecb6d0fc075ba5],
PUP.Optional.ValueAppsplugin.A, C:\Users\Dagmar\AppData\Local\Conduit\ValueApps\IE, , [7413a5c596f4bd79dcecb6d0fc075ba5],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf, , [5b2c21493852bf77043adfa8fe0519e7],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0, , [5b2c21493852bf77043adfa8fe0519e7],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\extensionData, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\extensionData\plugins, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\extensionData\userCode, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js\api, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js\lib, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpgndjnkkajlccmbhmbefihiflpahbmf\1.26.8_0\js\lib\popupResource, , [4344e585e3a74aece5597611fb0823dd],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\extensionData, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\extensionData\plugins, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\extensionData\userCode, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js\api, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js\lib, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.69_0\js\lib\popupResource, , [fd8a3f2b058571c54e8aee99d52e40c0],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\extensionData, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\extensionData\plugins, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\extensionData\userCode, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js\api, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js\lib, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb\1.26.14_0\js\lib\popupResource, , [acdb1e4cb2d8c175e9432e5adc27758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\api, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\core, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults\preferences, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\plugins, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\userCode, , [3255e684b2d861d506de3752d92a758b],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\api, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\core, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults\preferences, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\plugins, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\userCode, , [3e49f3776f1b082e786c62270bf89b65],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\api, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\core, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\defaults\preferences, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\plugins, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\userCode, , [147361098a002c0a36ae0a7f7e857a86],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\defaults, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\defaults\preferences, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\extensionData, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\15d84a30-fc9d-4fca-80a7-e5797da621a2@b2cb2d04-e262-4863-aee7-9d0e4333b550.com\extensionData\plugins, , [4344e189abdf5cda1ec647427b888d73],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\api, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\chrome\content\core, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\defaults\preferences, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\plugins, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com\extensionData\userCode, , [95f2beac2e5c7db9c61efd8cd92ac040],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content\browser, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content\external, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\content\newtab, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\defaults, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\defaults\preferences, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin\plugins, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin\plugins\images, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.MySearchDial.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}\skin\plugins\images\info, , [483f9bcfb3d71c1ab15b3456ca390ef2],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\defaults, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\defaults\preferences, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\addon-kit, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\addon-kit\lib, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\event, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\addon, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\content, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\dom, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\events, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\l10n, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\private-browsing, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\system, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\tabs, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\traits, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\utils, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\window, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\api-utils\lib\windows, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\SavingsBull, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SavingsBull.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\SavingsBull@jetpack\resources\SavingsBull\lib, , [89fee882dbafd561e83546443dc6c23e],
PUP.Optional.SystemSpeedup, C:\Users\Dagmar\AppData\Roaming\Systweak\ssd, , [5b2c39317d0d7cbafa0e6535f60da15f],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.438_0, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.438_0\libraries, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.Vbates.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip\2.0.0.438_0\resources, , [57302b3fe7a3e6505435cdcdad569868],
PUP.Optional.GlobalUpdate.A, C:\Users\Dadmar Petri\AppData\Local\Temp\comh.211717, , [98ef4723c2c85dd93da81387748fcf31],
PUP.Optional.GlobalUpdate.A, C:\Users\Dadmar Petri\AppData\Local\Temp\comh.343706, , [087f4129cbbfbc7a8d585a40768d9c64],
PUP.Optional.GlobalUpdate.A, C:\Users\Dadmar Petri\AppData\Local\Temp\comh.73275, , [177059119af03cfa37ae3e5c41c2d32d],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC, , [7d0aef7b2664d85e2abb9e07659e20e0],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_d4mojvjqeqnf3ie1sd0zw2zjiklefrb4, , [7d0aef7b2664d85e2abb9e07659e20e0],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_d4mojvjqeqnf3ie1sd0zw2zjiklefrb4\1.5.0.0, , [7d0aef7b2664d85e2abb9e07659e20e0],
PUP.Optional.WordProser.A, C:\Program Files\WordProser_1.10.0.5, , [a7e016541674181e7f8e41668f748c74],
PUP.Optional.WordProser.A, C:\Program Files\WordProser_1.10.0.5\3rd Party Licenses, , [a7e016541674181e7f8e41668f748c74],
PUP.Optional.CinemaxMe.A, C:\Program Files\CinemaxMe-version2.0, , [99ee6a00810956e0520cb8f08e7517e9],
PUP.Optional.VOPackage.A, C:\Users\Dagmar\AppData\Roaming\VOPackage, , [4a3d3733fa9012240012ae027291ab55],
PUP.Optional.ClicUp.A, C:\Users\Dadmar Petri\AppData\Local\clicup, , [96f13b2f9eec8ea8d936e4cef0132bd5],

Dateien: 1125
PUP.Optional.NationZoom.A, C:\Users\Dagmar\AppData\Roaming\nationzoom\nationzoom.exe, , [711686e4fe8c3204029af6390af605fb],
PUP.Optional.SkyTech.A, C:\Users\Dagmar\AppData\Roaming\nationzoom\UpDate.dll, , [3d4acaa014761e18c5ac24e105fd21df],
PUP.Optional.Conduit.A, C:\Users\Dagmar\AppData\Roaming\ValueApps\CH\TBVerifier.dll, , [22655f0bed9d59dd0ac8f84c43bd7090],
PUP.Optional.SilenceInstall, C:\Users\Dagmar\AppData\Roaming\VOPackage\Uninstall.exe, , [9aed0b5f0d7d2016ac4e310b857bb14f],
PUP.Optional.CrossRider.A, C:\Program Files\CinemaxMe-version2.0\utils.exe, , [483fe98199f16fc7296bea6024dc0af6],
PUP.Optional.Netfilter, C:\temp\InstallFilter32.msi, , [aaddf377f496989e8493c0ab728e7a86],
PUP.Optional.Clara.A, C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\bobrowser_3010-10494ef2.exe, , [89fe2941484240f6e203f8e948b9a15f],
PUP.Optional.Wajam.A, C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\WIE_2.18.1.8.exe, , [2d5abdad008a6cca5389b7afb24ec33d],
PUP.Optional.Bundle, C:\Users\Dadmar Petri\AppData\Local\Temp\D197tmp\lly_omiga-plus.exe, , [3255dd8d7614e65069f2c933d031c040],
PUP.Optional.ShoppingHelper.A, C:\Users\Dadmar Petri\AppData\Local\Temp\4E90tmp\shoppinhelper2_setup2c2.3.11.exe, , [b6d1a6c46228b5817576331a4ab626da],
PUP.Optional.ShoppingHelper.A, C:\Users\Dadmar Petri\AppData\Local\Temp\DA3Ctmp\shoppinhelper2_setup2c2.3.11.exe, , [bdcaf4767e0cc274bf2c2e1fec14e51b],
PUP.Optional.InstallCore.SID.A, C:\Users\Dadmar Petri\Downloads\avira-free-antivirus_setup.exe, , [315612589ceee551051cbe79a95d15eb],
PUP.Optional.RegCleanPro, C:\Users\Dagmar\Downloads\rcpsetupmarm1_marm1203911984de_aotest.exe, , [32559bcffa90280e3c7c32047b8515eb],
PUP.Optional.RegCleanerPro, C:\Users\Dagmar\Downloads\rcpsetup_ad_de_8044_ad_de_8044 (1).exe, , [3d4a165498f232040fc151e94ab77987],
PUP.Optional.RegCleanerPro, C:\Users\Dagmar\Downloads\rcpsetup_ad_de_8044_ad_de_8044 (2).exe, , [8007bfab246675c13a964af0b8499f61],
PUP.Optional.RegCleanerPro, C:\Users\Dagmar\Downloads\rcpsetup_ad_de_8044_ad_de_8044.exe, , [9deaa3c74347d85ea12fb783c23f7987],
PUP.Optional.RegCleanPro, C:\Users\Dagmar\Downloads\rcpsetup_chip_de_chip_de.exe, , [c5c2323801897cbad7e18babde22a25e],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormUpdater.exe, , [c6c1e189d2b8a591ca7f3cae58a99e62],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatch.exe, , [22654d1d54365cda5d1c193ee21ef30d],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchApp.exe, , [45428edc35557abceb8e97c0a25e08f8],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchappuninstall.exe, , [05821b4fa2e866d089f086d13ac6a55b],
PUP.Optional.StormWatch.A, C:\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchBrowser.exe, , [1b6cdb8fd4b61c1a8eebe671728ee719],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\AnyProtectScannerSetup.exe, , [cdbada904a4086b04a8296a044c21fe1],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsa76A9.tmp, , [f59259118efc70c6c80439fdfe0802fe],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsd4C2C.tmp, , [f09751194e3cb87e795392a44db935cb],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsf87D7.tmp, , [a5e27ded8802003607c5be78020442be],
PUP.Optional.AnyProtect.A, C:\Users\Dagmar\AppData\Local\nsn204F.tmp, , [abdc630721692412b21ae353dc2a0000],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\crossrider_statusbar.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button1.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button2.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button3.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button4.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\button5.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon128.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon16.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon24.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\icon48.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\panelarrow-up.png, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\popup.html, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\skin.css, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\skin\update.css, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\install.rdf, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\background.html, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\browser.xul, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\ffCoreFilesIndex.txt, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\options.xul, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\chrome\content\search_dialog.xul, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\manifest.xml, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\extensionData\plugins.json, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\078a430f-036c-465f-b0e6-ba51c9cab658@a99fe3f5-753b-4a88-9018-e91d1a05fccd.com\locale\en-US\translations.dtd, , [bec904664f3b1c1aa6d47841a261b14f],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png, , [6e190664bdcd80b6c2b8c9f08c778c74],

Code:

f-b2da-1425ac7300ac.com\skin\button3.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\manifest.xml, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins.json, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US\translations.dtd, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button3.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome.manifest, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\baseObject.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\dialog.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\main.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\platformVersion.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\asyncDB.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\background.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\browserAction.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\contextMenu.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dbManager.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dom_bg.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\fileManager.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefox.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxNotifications.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxOmnibox.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\message.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\pageAction.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\request.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\tabs.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\webRequest.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\windowsMessagingHandler.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\addressBarChangeObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\console.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\consts.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\delegate.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\extensionDataStore.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\folderIOWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\httpObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\IDBWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\installer.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\logFile.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\prefs.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\progressListenerObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\registry.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\reloadObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\reports.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\requestObject.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\searchSettings.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\uninstallObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\updateManager.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\utils.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\xhr.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences\prefs.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\manifest.xml, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins.json, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\13_CrossriderAppUtils.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\14_CrossriderUtils.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\16_FFAppAPIWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\177_crossriderDashboard.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\17_jQuery.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\182_openUrl.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\183_tabsWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\184_noproblemppc_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\195_icm_convertmedia_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\1_base.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\207_dbWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\21_debug.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\220_icm_base_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\22_resources.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\28_initializer.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\47_resources_background.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\4_jquery_1_7_1.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\64_appApiMessage.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\72_appApiValidation.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\78_CrossriderInfo.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\7_hooks.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\98_omniCommands.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\9_search_engine_hook.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode\background.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode\extension.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US\translations.dtd, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button3.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome.manifest, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\baseObject.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\dialog.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\main.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\platformVersion.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\asyncDB.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\background.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\browserAction.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\contextMenu.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dbManager.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dom_bg.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\fileManager.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefox.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxNotifications.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxOmnibox.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\message.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\pageAction.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],


daggimaus 09.04.2015 17:48

Code:

f-b2da-1425ac7300ac.com\skin\button3.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\manifest.xml, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins.json, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US\translations.dtd, , [6e190664bdcd80b6c2b8c9f08c778c74],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button3.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome.manifest, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\baseObject.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\dialog.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\main.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\platformVersion.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\asyncDB.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\background.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\browserAction.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\contextMenu.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dbManager.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dom_bg.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\fileManager.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefox.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxNotifications.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxOmnibox.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\message.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\pageAction.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\request.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\tabs.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\webRequest.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\windowsMessagingHandler.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\addressBarChangeObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\console.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\consts.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\delegate.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\extensionDataStore.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\folderIOWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\httpObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\IDBWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\installer.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\logFile.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\prefs.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\progressListenerObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\registry.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\reloadObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\reports.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\requestObject.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\searchSettings.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\uninstallObserver.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\updateManager.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\utils.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\core\xhr.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\defaults\preferences\prefs.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\manifest.xml, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins.json, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\102_dealply_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\103_intext_5_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\104_jollywallet_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\13_CrossriderAppUtils.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\14_CrossriderUtils.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\155_ibario_pops_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\16_FFAppAPIWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\177_crossriderDashboard.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\17_jQuery.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\182_openUrl.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\183_tabsWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\184_noproblemppc_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\190_pops_5_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\191_ciuvo_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\195_icm_convertmedia_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\1_base.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\207_dbWrapper.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\21_debug.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\220_icm_base_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\22_resources.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\28_initializer.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\47_resources_background.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\4_jquery_1_7_1.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\64_appApiMessage.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\72_appApiValidation.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\78_CrossriderInfo.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\7_hooks.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\91_monetizationLoader.js.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\93_superfish_no_coupons_m.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\98_omniCommands.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\plugins\9_search_engine_hook.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode\background.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\extensionData\userCode\extension.js, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\locale\en-US\translations.dtd, , [cabd8cde57336dc9b8c22b8edf2455ab],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\crossrider_statusbar.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button1.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button2.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button3.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button4.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\button5.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon128.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon16.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon24.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\icon48.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\panelarrow-up.png, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\popup.html, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\skin.css, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\skin\update.css, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome.manifest, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\install.rdf, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\background.html, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\baseObject.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\browser.xul, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\dialog.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\ffCoreFilesIndex.txt, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\main.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\options.xul, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\platformVersion.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\search_dialog.xul, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\asyncDB.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\background.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\browserAction.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\contextMenu.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dbManager.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\dom_bg.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\fileManager.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefox.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxNotifications.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\firefoxOmnibox.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\message.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],
PUP.Optional.CrossRider.A, C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\extensions\0c822a17-a68f-4066-9257-d229458d21ca@9c178d17-dc61-4aaf-b2da-1425ac7300ac.com\chrome\content\api\pageAction.js, , [bfc8eb7f81094fe71c5e12a7a063c33d],


schrauber 10.04.2015 07:47

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


daggimaus 10.04.2015 10:44

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by Dadmar Petri (administrator) on DAGMAR on 10-04-2015 10:59:29
Running from C:\Users\Dadmar Petri\Downloads
Loaded Profiles: Dadmar Petri & Hans Leo & UpdatusUser (Available profiles: Dadmar Petri & Hans Leo & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium  (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

Code:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe

Code:

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [384800 2012-12-04] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\MountPoints2: {1114a94f-70d1-11e4-8c49-806e6f6e6963} - E:\setup.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [InetStat] => C:\Users\Hans Leo\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [clicup-Agent] => C:\Users\Hans Leo\AppData\Local\clicup\chrmndr.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
Startup: C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1001 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [260384] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

Code:

FireFox:
========
FF ProfilePath: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default
FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml
FF Homepage: hxxp://www.spiegel.de/
FF Keyword.URL: hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-31] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\searchplugins\google-images.xml [2015-02-20]
FF SearchPlugin: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\searchplugins\google-maps.xml [2015-02-20]
FF SearchPlugin: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\searchplugins\ixquick-https---deutsch.xml [2015-04-10]
FF SearchPlugin: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\searchplugins\mozilla-hilfe.xml [2015-04-03]
FF SearchPlugin: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\searchplugins\search-provided-by-yahoo.xml [2015-03-31]
FF Extension: YouTube™ Flash® Player - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2015-03-31]
FF Extension: {7018936b-8c23-40c7-8f06-f6dc0d059544} - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\Extensions\{7018936b-8c23-40c7-8f06-f6dc0d059544}.xpi [2015-04-01]
FF Extension: Adblock Plus - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-13]
FF HKLM\...\Firefox\Extensions: [{d9a96531-b093-4d07-9e4c-9704a365c441}] - C:\Program Files\Mozilla Firefox\extensions\{d9a96531-b093-4d07-9e4c-9704a365c441}
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com

Chrome:
=======
CHR Profile: C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-29]
CHR Extension: (Google Docs) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-29]
CHR Extension: (Google Drive) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-29]
CHR Extension: (YouTube) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-29]
CHR Extension: (Google Search) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-29]
CHR Extension: (Google Sheets) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-29]
CHR Extension: (Google Wallet) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-29]
CHR Extension: (Gmail) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

Code:

Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [85280 2012-12-04] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [109344 2012-12-04] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [565024 2012-12-04] (Avira Operations GmbH & Co. KG)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83944 2012-11-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [134336 2012-11-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36552 2012-11-22] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-04-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-11-20] (Avira GmbH)
R3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S1 wpnfd_1_10_0_2; system32\drivers\wpnfd_1_10_0_2.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-10 10:59 - 2015-04-10 10:59 - 00020853 _____ () C:\Users\Dadmar Petri\Downloads\FRST.txt
2015-04-10 10:58 - 2015-04-10 10:59 - 00000000 ____D () C:\FRST
2015-04-10 10:57 - 2015-04-10 10:57 - 01135104 _____ (Farbar) C:\Users\Dadmar Petri\Downloads\FRST.exe
2015-04-09 16:25 - 2015-04-09 16:25 - 00001120 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2015-04-09 15:39 - 2015-04-09 15:39 - 00021917 _____ () C:\Users\Dadmar Petri\Desktop\Malware.zip
2015-04-09 15:39 - 2015-04-09 15:39 - 00000000 ____D () C:\Users\Dadmar Petri\Desktop\Malware
2015-04-09 12:05 - 2015-04-09 12:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(2).exe
2015-04-09 11:38 - 2015-04-09 11:38 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(1).exe
2015-04-09 11:36 - 2015-04-09 11:36 - 00342765 _____ () C:\Users\Dadmar Petri\Desktop\Malwaare.txt
2015-04-09 11:20 - 2015-04-10 08:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-09 11:19 - 2015-04-09 11:39 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-09 11:19 - 2015-04-09 11:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-09 11:19 - 2015-04-09 11:39 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 11:19 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-09 11:19 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-09 11:19 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

Code:

1:18 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 09:35 - 2015-04-08 17:34 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimService
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimCleaner Plus
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc
2015-04-07 13:42 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\DriverUpdate
2015-04-07 13:42 - 2015-04-07 17:51 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc
2015-04-01 08:56 - 2015-04-01 08:56 - 00000002 _____ () C:\$UpgDrv$
2015-04-01 08:56 - 2015-04-01 08:56 - 00000000 ____D () C:\$WINDOWS.~LS
2015-04-01 08:42 - 2015-04-01 08:42 - 00000000 ____D () C:\$UPGRADE.~OS
2015-04-01 08:41 - 2015-04-01 08:41 - 00000000 ____D () C:\$WINDOWS.~BT
2015-04-01 00:59 - 2015-04-01 01:09 - 00002562 _____ () C:\Windows\diagwrn.xml
2015-04-01 00:59 - 2015-04-01 01:09 - 00001908 _____ () C:\Windows\diagerr.xml
2015-04-01 00:54 - 2015-04-01 00:54 - 00001156 _____ () C:\Users\UpdatusUser\Desktop\Goodgame Empire.lnk
2015-04-01 00:54 - 2015-04-01 00:54 - 00001156 _____ () C:\Users\Hans Leo\Desktop\Goodgame Empire.lnk
2015-04-01 00:53 - 2015-04-01 00:53 - 00394480 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis(1).exe
2015-04-01 00:49 - 2015-04-01 00:49 - 00005168 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis.log
2015-04-01 00:47 - 2015-04-01 00:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Dadmar Petri\Downloads\HijackThis.exe
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\OkayFreedom
2015-03-31 23:09 - 2015-04-01 01:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos VPN
2015-03-31 23:09 - 2015-03-31 23:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos
2015-03-31 23:09 - 2015-03-31 23:09 - 105603488 _____ () C:\Users\Dadmar Petri\Downloads\avira-free-antivirus.exe
2015-03-31 23:09 - 2015-03-31 23:09 - 00001031 _____ () C:\Users\Public\Desktop\OkayFreedom.lnk
2015-03-31 23:09 - 2015-03-31 23:09 - 00000000 ____D () C:\Program Files\Common Files\Steganos
2015-03-31 23:08 - 2015-03-31 23:08 - 00729832 _____ (Program ) C:\Users\Dadmar Petri\Downloads\avira-free-antivirus_setup.exe
2015-03-31 23:01 - 2015-03-31 23:01 - 04625104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dadmar Petri\Downloads\avira_de_av_5962866439__ws.exe
2015-03-31 21:52 - 2015-04-10 10:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-31 21:52 - 2015-04-09 22:16 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 21:52 - 2015-04-09 22:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 21:52 - 2015-03-31 21:52 - 01055936 _____ (Adobe) C:\Users\Dadmar Petri\Downloads\install_flashplayer17x32_mssd_aaa_aih.exe
2015-03-31 21:08 - 2015-03-31 21:08 - 00243576 _____ () C:\Users\Dadmar Petri\Downloads\Firefox Setup Stub 37.0.exe
2015-03-30 23:41 - 2015-03-31 21:45 - 00000000 ____D () C:\Program Files\Learn to Play Bridge 2
2015-03-30 23:41 - 2015-03-30 23:41 - 02062482 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb2setup.exe
2015-03-30 11:33 - 2015-03-31 21:45 - 00286720 _____ (Indigo Rose Corporation) C:\Windows\iun506.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 01865951 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb1setup.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\UpdatusUser\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Hans Leo\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Dadmar Petri\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\Program Files\Learn to Play Bridge
2015-03-30 11:24 - 2015-03-30 11:24 - 00698138 _____ () C:\Users\Dadmar Petri\Downloads\bbo_shortcut.exe
2015-03-30 00:14 - 2015-03-20 15:27 - 25808896 _____ () C:\Users\Dadmar Petri\Documents\Büro_2015_24.03.15.mdb
2015-03-29 23:36 - 2015-03-29 23:38 - 165283560 _____ () C:\Users\Dadmar Petri\Downloads\avira_free_antivirus_de_656.exe
2015-03-29 11:31 - 2015-03-29 11:31 - 00088626 _____ () C:\Users\Dadmar Petri\Downloads\avira_registry_cleaner_de.zip
2015-03-26 18:08 - 2015-03-26 18:08 - 00462552 _____ () C:\Windows\Minidump\032615-20139-01.dmp
2015-03-23 16:06 - 2015-03-26 17:15 - 00000000 ____D () C:\e79d95644af82acfec248548e1a8067b

Code:

2015-03-23 16:05 - 2015-03-23 16:09 - 373578968 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe
2015-03-23 16:05 - 2015-03-23 16:07 - 08676128 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 40888512 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows-KB890830-V5.22.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 39074536 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\FileFormatConverters(1).exe
2015-03-23 13:57 - 2015-03-23 13:57 - 00462936 _____ () C:\Windows\Minidump\032315-32775-01.dmp
2015-03-23 12:24 - 2015-03-23 12:24 - 00031282 _____ () C:\Users\Dadmar Petri\Documents\Die Uhus.dotx
2015-03-23 10:50 - 2015-03-23 10:50 - 00463416 _____ () C:\Windows\Minidump\032315-21309-01.dmp
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-16 13:42 - 2015-03-16 13:42 - 00462864 _____ () C:\Windows\Minidump\031615-20280-01.dmp
2015-03-15 01:14 - 2015-03-15 01:14 - 00475440 _____ () C:\Windows\Minidump\031515-20030-01.dmp
2015-03-11 10:06 - 2015-03-11 10:06 - 07169624 _____ () C:\Users\Dadmar Petri\Downloads\HPPSdr(1).exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-10 10:56 - 2014-11-19 16:32 - 01688111 _____ () C:\Windows\WindowsUpdate.log
2015-04-10 10:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-04-10 09:57 - 2014-11-20 01:17 - 00002446 _____ () C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-5_user.job
2015-04-10 09:57 - 2014-11-20 01:17 - 00002446 _____ () C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-5.job
2015-04-10 09:57 - 2014-11-20 01:16 - 00003128 _____ () C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-1.job
2015-04-10 09:57 - 2014-11-20 01:16 - 00002110 _____ () C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-2.job
2015-04-10 09:57 - 2014-11-20 01:15 - 00004840 _____ () C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-11.job
2015-04-10 09:57 - 2014-11-20 01:15 - 00004494 _____ () C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-4.job
2015-04-10 09:57 - 2014-11-20 01:15 - 00002450 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-5_user.job
2015-04-10 09:57 - 2014-11-20 01:15 - 00002450 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-5.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00005188 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-11.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00004498 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-4.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00003136 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-1.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00002114 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-2.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00001458 _____ () C:\Windows\Tasks\d7ab22e9-4a04-494e-a824-7c0e59c14f88.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00001368 _____ () C:\Windows\Tasks\UTLKMTU.job
2015-04-10 09:57 - 2014-11-20 01:14 - 00000654 _____ () C:\Windows\Tasks\ad3efa10-5ca0-40ff-a731-6065ac7d176a.job
2015-04-10 09:57 - 2014-11-20 01:13 - 00004162 _____ () C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-3.job
2015-04-10 09:57 - 2014-11-20 01:13 - 00001366 _____ () C:\Windows\Tasks\FUPWXF.job
2015-04-10 08:36 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-10 08:36 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-10 08:33 - 2014-11-19 17:52 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-10 08:29 - 2014-11-20 15:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-04-10 08:29 - 2014-11-19 22:59 - 00000432 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-04-10 08:29 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-10 08:29 - 2009-07-14 06:39 - 00001981 _____ () C:\Windows\setupact.log
2015-04-09 22:16 - 2014-11-20 01:41 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Adobe
2015-04-09 19:02 - 2014-11-20 00:26 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\StormWatch
2015-04-09 17:16 - 2014-11-19 23:40 - 00453414 _____ () C:\Windows\PFRO.log
2015-04-09 16:24 - 2014-11-20 01:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira

Code:

2015-04-09 16:24 - 2014-11-20 01:18 - 00000000 ____D () C:\ProgramData\Avira
2015-04-09 16:24 - 2014-11-20 01:18 - 00000000 ____D () C:\Program Files\Avira
2015-04-08 19:56 - 2014-12-30 10:50 - 00271360 _____ () C:\Users\Hans Leo\Documents\Kontakte.pst
2015-04-08 19:09 - 2014-11-20 02:42 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\ProgramData\Netzmanager
2015-04-08 09:59 - 2014-11-20 01:42 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-08 09:59 - 2014-11-20 00:09 - 00000000 ____D () C:\Users\Hans Leo
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-08 09:58 - 2014-11-21 11:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Mozilla
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-08 09:58 - 2014-11-20 00:52 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Mozilla
2015-04-08 09:57 - 2014-01-18 12:16 - 00000000 __RHD () C:\MSOCache
2015-04-08 09:13 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri
2015-04-01 19:27 - 2014-12-01 09:52 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\Avira
2015-04-01 19:22 - 2014-11-20 13:46 - 00065464 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 01:02 - 2009-07-14 06:39 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-01 00:54 - 2014-11-29 14:48 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\dlg
2015-04-01 00:48 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\VirtualStore
2015-03-31 23:09 - 2014-11-20 02:42 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-31 22:11 - 2009-07-14 06:33 - 00303112 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-31 21:40 - 2014-11-20 02:42 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-31 20:37 - 2014-11-19 23:59 - 00065464 _____ () C:\Users\Dadmar Petri\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-31 20:14 - 2014-11-23 20:04 - 00000000 ____D () C:\Users\Dadmar Petri\Documents\DIE UHUS
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-31 19:17 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-29 20:54 - 2015-01-12 20:57 - 00000000 ____D () C:\Windows\pss
2015-03-29 20:11 - 2015-01-02 13:41 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-29 09:03 - 2015-01-02 13:42 - 00000000 ____D () C:\Program Files\Bonjour
2015-03-28 19:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-26 18:08 - 2015-01-03 16:50 - 321192056 _____ () C:\Windows\MEMORY.DMP
2015-03-26 18:08 - 2015-01-03 16:50 - 00000000 ____D () C:\Windows\Minidump
2015-03-26 17:15 - 2015-01-03 16:48 - 00000000 ____D () C:\NVIDIA
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 17:15 - 2014-11-28 23:40 - 00000000 ____D () C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2015-03-23 17:00 - 2014-12-01 01:39 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Avira
2015-03-11 19:48 - 2014-11-20 00:53 - 119837704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-11 10:37 - 2015-02-03 14:04 - 00001962 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk

==================== Files in the root of some directories =======

2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Dadmar Petri\AppData\Roaming\FUPWXF
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Dadmar Petri\AppData\Roaming\UTLKMTU
2014-12-20 10:45 - 2014-12-20 10:45 - 0000057 _____ () C:\ProgramData\Ament.ini

Code:

Some content of TEMP:
====================
C:\Users\Dadmar Petri\AppData\Local\Temp\AskSLib.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\avgnt.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\BackupSetup.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\MSNEE75.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\ose00000.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\setup_337.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is3FAE.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is8574.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is9A89.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-25 10:42

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by Dadmar Petri at 2015-04-10 11:00:26
Running from C:\Users\Dadmar Petri\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Desktop (Disabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 15.0.9.504 - Avira)
Canon PhotoRecord (HKLM\...\{37A54340-6655-4FFC-BC4C-0B945764DA4B}) (Version: 02.02.04002 - Cisra)
Canon Utilities Anleitung zum CP-Drucker (HKLM\...\InstallShield_{B4A6DE2E-5E84-4F1D-B26A-EAB0D42ED932}) (Version: 5.0.0 - Canon)
Canon Utilities Easy-PhotoPrint (HKLM\...\Easy-PhotoPrint) (Version:  - )
Cisco EAP-FAST Module (HKLM\...\{BF53252E-4AB2-4C7F-A0FD-6100755745E3}) (Version: 2.0.26 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{76F9CF97-FC4B-4E20-B363-D127C888448F}) (Version: 1.0.11 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{4E5386F5-C0F6-4532-A54A-374865AEAB71}) (Version: 1.0.12 - Cisco Systems, Inc.)
clicup (HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\clicup) (Version: 1.0 - Ad Businness Crown Solutions)
clicup (HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\clicup) (Version: 1.0 - Ad Businness Crown Solutions)
clicup (HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\clicup) (Version: 1.0 - Ad Businness Crown Solutions)
Cliqz (HKLM\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.55 - Cliqz.com)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
CP Printer Guide (Version: 5.0.0 - Canon) Hidden
eturboTouchKit (HKLM\...\{1D1D8C17-A605-4FBB-9DB8-E79B58C28D96}) (Version: 4.2.3.2 - )
HP Deskjet 1050 J410 series - Grundlegende Software für das Gerät (HKLM\...\{9C31FFDC-E796-4884-B990-41B9A5B2A647}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Hilfe (HKLM\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife)
HP Support Solutions Framework (HKLM\...\{E35601C0-BA8E-4F32-919A-C7EF4CA81F67}) (Version: 11.51.0048 - Hewlett-Packard Company)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Learn to Play Bridge (HKLM\...\Learn_to_Play_Bridge) (Version:  - )
Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office Standard 2007 (HKLM\...\STANDARD) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 37.0.1 (x86 de) (HKLM\...\Mozilla Firefox 37.0.1 (x86 de)) (Version: 37.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 37.0 - Mozilla)
Netzmanager (HKLM\...\Netzmanager) (Version: 1.081 - Deutsche Telekom AG)
Netzmanager (Version: 1.081 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.7 - NVIDIA Corporation)
NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation)
OkayFreedom (HKLM\...\{3F3FB10C-7175-4D38-9335-3488B89C12AF}) (Version: 1.4.3 - Steganos Software GmbH)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
Realtek 8136 8168 8169 Ethernet Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0005 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5892 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM\...\{9D3D8C60-A55F-4fed-B2B9-173F09590E16}) (Version: 1.00.0117 - REALTEK Semiconductor Corp.)
Studie zur Verbesserung von HP Deskjet 1050 J410 series Produkten (HKLM\...\{4FC5C255-8157-404F-9C91-2C479A62E4EE}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)

==================== Custom CLSID (selected items): ==========================

Code:

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

29-03-2015 09:03:05 Removed Bonjour
29-03-2015 09:05:52 Removed Apple Application Support (32-Bit)
29-03-2015 09:10:07 Removed iTunes
29-03-2015 20:03:23 Removed iTunes
29-03-2015 20:11:25 Removed iTunes
01-04-2015 01:16:50 Windows-Sicherung
08-04-2015 10:19:58 Geplanter Prüfpunkt

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {02C9A0F7-9CC8-414E-BA62-AF9C042B82D6} - System32\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-5 => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-5.exe <==== ATTENTION
Task: {03F500C6-ED15-475D-A88F-8B8DD5C3D861} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-2 => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-2.exe <==== ATTENTION
Task: {06D7496B-64FE-40D5-8FDB-0FA528281630} - System32\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-1 => C:\Program Files\CinemaxMe-version2.0\CinemaxMe-version2.0-codedownloader.exe <==== ATTENTION
Task: {1299E286-C6E5-42C5-A776-9C75417BF2B4} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-5_user => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-5.exe <==== ATTENTION
Task: {16E7B74B-DA2A-45DA-9E5B-6B143CE12AD0} - System32\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-11 => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-11.exe <==== ATTENTION
Task: {28625554-0C6D-4A5D-9C32-BDC71BD3879B} - System32\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-2 => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-2.exe <==== ATTENTION
Task: {35F691F8-BBD3-4772-916D-A92577A3E5DF} - System32\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-5_user => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-5.exe <==== ATTENTION
Task: {39AFB8A0-1EC6-46E6-89B6-026559E8116B} - System32\Tasks\LaunchApp => C:\Program Files\MyPC Backup\MyPC Backup.exe <==== ATTENTION
Task: {586CBF29-6DEA-4E1F-980A-358197340AE8} - System32\Tasks\{6D828C5A-7D60-49BF-999D-7211DA5E1962} => pcalua.exe -a "C:\Program Files\Avira\AntiVir Desktop\setup.exe" -c /REMOVE
Task: {63475781-68FF-4CE6-8710-82E29234F51D} - System32\Tasks\FUPWXF => C:\Users\Dadmar Petri\AppData\Roaming\FUPWXF.exe <==== ATTENTION
Task: {757B9319-491F-4572-9034-06FBF39D45BB} - System32\Tasks\ad3efa10-5ca0-40ff-a731-6065ac7d176a => C:\Program Files\HQ Pro Video 1.6V19.11\ad3efa10-5ca0-40ff-a731-6065ac7d176a.exe <==== ATTENTION
Task: {75BC9FEC-4B77-473C-BAE5-C1541FFEA569} - System32\Tasks\d7ab22e9-4a04-494e-a824-7c0e59c14f88 => C:\Program Files\HQ Pro Video 1.6V19.11\d7ab22e9-4a04-494e-a824-7c0e59c14f88.exe <==== ATTENTION
Task: {7DB90FD3-AFB6-4B4C-995C-C7CEA047AB0D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {7E4C3FB6-741F-4A9D-9E43-56DB73176134} - System32\Tasks\UTLKMTU => C:\Users\Dadmar Petri\AppData\Roaming\UTLKMTU.exe <==== ATTENTION
Task: {92C22232-FEFE-44A0-8369-20BD42822B79} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-11 => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-11.exe <==== ATTENTION
Task: {945E90C8-B93F-4B37-8DD1-8284361D71DC} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-3 => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-3.exe <==== ATTENTION
Task: {A36C5663-FB62-4DEF-A9E7-970EE5316749} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.)
Task: {B2740AA7-B0AA-4848-A913-73A5BA248C3C} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {B8010947-2516-47E5-BABD-3463E4A13054} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-4 => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-4.exe <==== ATTENTION
Task: {BE365CC1-3402-4CED-A934-81D0510068F0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-09] (Adobe Systems Incorporated)
Task: {C9EF57FC-698E-4D51-9F5C-763B616832BF} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-1 => C:\Program Files\HQ Pro Video 1.6V19.11\HQ Pro Video 1.6V19.11-codedownloader.exe <==== ATTENTION
Task: {E725F73D-B32C-4070-8FE5-A2E3B9B7B44C} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {F0DC5250-F859-47B1-9AA4-865FD4D805ED} - System32\Tasks\{363C1B94-B206-40D4-8C0D-BB5874417483} => C:\Program Files\Canon\Easy-PhotoPrint\BJEZPRN.EXE [2005-04-27] (CANON INC.)
Task: {F2DE4238-DBB5-41EE-B901-3F51465E87DC} - System32\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-5 => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-5.exe <==== ATTENTION
Task: {F8A64685-E999-4EDC-8EF6-F03B69CC4D4E} - System32\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-4 => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-4.exe <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-1.job => C:\Program Files\CinemaxMe-version2.0\CinemaxMe-version2.0-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-11.job => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-2.job => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-4.job => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-5.job => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\24852ac1-7ce1-47a1-be11-fd5c12287df3-5_user.job => C:\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-1.job => C:\Program Files\HQ Pro Video 1.6V19.11\HQ Pro Video 1.6V19.11-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-11.job => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-2.job => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-3.job => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-4.job => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-5.job => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\5c88e756-5715-4945-8876-5ac5b1c5a119-5_user.job => C:\Program Files\HQ Pro Video 1.6V19.11\5c88e756-5715-4945-8876-5ac5b1c5a119-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\ad3efa10-5ca0-40ff-a731-6065ac7d176a.job => C:\Program Files\HQ Pro Video 1.6V19.11\ad3efa10-5ca0-40ff-a731-6065ac7d176a.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\d7ab22e9-4a04-494e-a824-7c0e59c14f88.job => C:\Program Files\HQ Pro Video 1.6V19.11\d7ab22e9-4a04-494e-a824-7c0e59c14f88.exe/agentregpath='HQ Pro Video 1.6V19.11' /appid=65777 /srcid='001874' /subid='0' /zdata='0' /bic=1EB4ECB5B4914407A17ED099487400B3IE /verifier=859fbb3fd0af55042d090632bee0a533 /installerversion=1_35_09_29 /installationtime=1416438926 /statsdomain=http:/stats.newonlinedemoserv.com /errorsdomain=http:/errors.newonlinedemoserv.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http:/logs.newonlinedemoserv.com <==== ATTENTION
Task: C:\Windows\Tasks\FUPWXF.job => C:\Users\Dadmar Petri\AppData\Roaming\FUPWXF.exe <==== ATTENTION
Task: C:\Windows\Tasks\UTLKMTU.job => C:\Users\Dadmar Petri\AppData\Roaming\UTLKMTU.exe <==== ATTENTION

Code:

==================== Loaded Modules (whitelisted) ==============

2014-11-20 01:18 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
2010-10-19 09:31 - 2010-10-19 09:31 - 00159744 _____ () C:\Program Files\Netzmanager\NMInfraIS2\driver\SoftplugLib.DLL

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\Dagmar\AppData\Roaming\Kommagetrennte Werte (Windows).EML:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dadmar Petri\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^Dadmar Petri^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Netzmanager.lnk => C:\Windows\pss\Netzmanager.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dadmar Petri^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^StormWatch.lnk => C:\Windows\pss\StormWatch.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dadmar Petri^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^StormWatchApp.lnk => C:\Windows\pss\StormWatchApp.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Dadmar Petri^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Tintenwarnungen überwachen - HP Deskjet 1050 J410 series.lnk => C:\Windows\pss\Tintenwarnungen überwachen - HP Deskjet 1050 J410 series.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: avgnt => "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
MSCONFIG\startupreg: Avira Systray => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
MSCONFIG\startupreg: clicup-Agent => C:\Users\Dadmar Petri\AppData\Local\clicup\chrmndr.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: InetStat => C:\Users\Dadmar Petri\AppData\Roaming\InetStat\inetstat.exe
MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

Code:

==================== Accounts: =============================

Administrator (S-1-5-21-941624961-3290542821-2423505712-500 - Administrator - Disabled)
Dadmar Petri (S-1-5-21-941624961-3290542821-2423505712-1000 - Administrator - Enabled) => C:\Users\Dadmar Petri
Gast (S-1-5-21-941624961-3290542821-2423505712-501 - Limited - Disabled)
Hans Leo (S-1-5-21-941624961-3290542821-2423505712-1001 - Limited - Enabled) => C:\Users\Hans Leo
HomeGroupUser$ (S-1-5-21-941624961-3290542821-2423505712-1003 - Limited - Enabled)
UpdatusUser (S-1-5-21-941624961-3290542821-2423505712-1004 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Faulty Device Manager Devices =============

Name: wpnfd_1_10_0_2
Description: wpnfd_1_10_0_2
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: wpnfd_1_10_0_2
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/10/2015 11:00:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0xb98
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 11:00:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x1568
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Code:

Error: (04/10/2015 10:59:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x103c
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 10:59:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x1414
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 10:59:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x1360
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 10:58:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x1230
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 10:58:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x5cc
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 10:58:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0xc5c
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Error: (04/10/2015 10:57:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x564
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3

Code:

Error: (04/10/2015 10:57:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Name des fehlerhaften Moduls: OkayFreedomClient.exe, Version: 1.4.3.11221, Zeitstempel: 0x54e4746b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003a440
ID des fehlerhaften Prozesses: 0x12bc
Startzeit der fehlerhaften Anwendung: 0xOkayFreedomClient.exe0
Pfad der fehlerhaften Anwendung: OkayFreedomClient.exe1
Pfad des fehlerhaften Moduls: OkayFreedomClient.exe2
Berichtskennung: OkayFreedomClient.exe3


System errors:
=============
Error: (04/10/2015 10:21:31 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht.

Error: (04/10/2015 10:21:31 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

Error: (04/10/2015 08:29:52 AM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 192.168.2.104192.168.137.0255.255.255.0

Error: (04/10/2015 08:29:52 AM) (Source: ipnathlp) (EventID: 1233) (User: )
Description:

Error: (04/10/2015 08:29:51 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
wpnfd_1_10_0_2

Error: (04/10/2015 08:29:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Avira Web Protection" ist vom Dienst "Avira Real-Time Protection" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1066

Error: (04/10/2015 08:29:47 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Avira Real-Time Protection" wurde mit folgendem dienstspezifischem Fehler beendet: %%303.

Error: (04/10/2015 08:29:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (04/10/2015 08:29:46 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Apple Mobile Device erreicht.

Error: (04/10/2015 08:29:44 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎10.‎04.‎2015 um 08:04:22 unerwartet heruntergefahren.


Microsoft Office Sessions:
=========================
Error: (01/29/2015 11:13:37 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time.  This session ended with a crash.


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz
Percentage of memory in use: 37%
Total physical RAM: 3327.24 MB
Available physical RAM: 2089.03 MB
Total Pagefile: 6652.75 MB
Available Pagefile: 4732.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1863.25 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:540.79 GB) (Free:404.59 GB) NTFS
Drive d: (Volume) (Fixed) (Total:390.62 GB) (Free:370.11 GB) NTFS
Drive e: (MEDHPDEU32) (CDROM) (Total:2.31 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F20FDE76)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=540.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=390.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Das sind die beiden Dateien. Vielen Dank für Ihre Mühe.Ich hoffe, Sie können mir helfen.

schrauber 10.04.2015 18:49

hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


daggimaus 10.04.2015 21:13

+Ich habe ComboFix über den angegebenen Link heruntergeladen. Wenn ich die exe.Datei anklicke, kommt folgende Meldung:

ComboFix is not meant to rum in 'Compatibility Mode! The pgrogram shall not exit.

schrauber 11.04.2015 10:37

Häh? Du hast laut Log Windows 7, das muss laufen.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

daggimaus 11.04.2015 12:47

Code:

AdwCleaner v4.106 - Bericht erstellt am 03/01/2015 um 13:41:08
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Local]
# Betriebssystem : Windows 7 Home Premium  (32 bits)
# Benutzername : Dadmar Petri - DAGMAR
# Gestartet von : C:\Users\Hans Leo\Downloads\adwcleaner_4.106.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : CltMngSvc

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\2308189059
Ordner Gelöscht : C:\ProgramData\WindowsMangerProtect
Ordner Gelöscht : C:\ProgramData\Kromtech
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
Ordner Gelöscht : C:\Program Files\predm
Ordner Gelöscht : C:\Program Files\Probit Software
Ordner Gelöscht : C:\Program Files\SearchProtect
Ordner Gelöscht : C:\Program Files\Search Extensions
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\clicup
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\StormWatch
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\BoBrowser
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Vosteran
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Dadmar Petri\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\SaveSenseLive
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\SoftwareUpdater
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Tuguu_SL
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\CrashRpt
Ordner Gelöscht : C:\Users\Dagmar\AppData\LocalLow\buenosearch LTD
Ordner Gelöscht : C:\Users\Dagmar\AppData\LocalLow\GutscheinCodes
Ordner Gelöscht : C:\Users\Dagmar\AppData\LocalLow\IminentToolbar
Ordner Gelöscht : C:\Users\Dagmar\AppData\LocalLow\iRobinHood
Ordner Gelöscht : C:\Users\Dagmar\AppData\LocalLow\Mysearchdial
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\iSafe
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\newnext.me
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\okitspace
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Optimizer Elite Max
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\SaveSense
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\speedtest127
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\speedypc software
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\sweet-page
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\ValueApps
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\VOPackage
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Windows Net Data
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Allmyapps
Ordner Gelöscht : C:\Users\Dagmar\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Dagmar\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Dagmar\Documents\PC Health Kit
Ordner Gelöscht : C:\Users\Dagmar\Documents\PC Speed Maximizer
Ordner Gelöscht : C:\Users\Hans Leo\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\LocalLow\IminentToolbar
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\LocalLow\Mysearchdial
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\iSafe

Code:

Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Ordner Gelöscht : C:\Users\Hans Leo\AppData\Roaming\Mozilla\Firefox\Profiles\9las2i8b.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\Extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\rz7o2274.default-1403122915722\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcjbopemebdnolilndkpjfmhakccapkh
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjdjfkkmlgacmnenfhafmkldaogiglb
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Dagmar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Public\Desktop\Media Downloader.lnk
Datei Gelöscht : C:\Users\Dagmar\AppData\Local\AnyProtectScannerSetup.exe
Datei Gelöscht : C:\Users\Dagmar\AppData\Local\mysearchdial-speeddial.crx
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\rz7o2274.default-1403122915722\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\searchplugins\conduit-search.xml
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\searchplugins\Mysearchdial.xml
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\user.js
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\rz7o2274.default-1403122915722\user.js
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\user.js
Datei Gelöscht : C:\Users\Hans Leo\AppData\Roaming\Mozilla\Firefox\Profiles\9las2i8b.default\user.js
Datei Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\user.js
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\searchplugins\Vosteran.xml
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\rz7o2274.default-1403122915722\searchplugins\Vosteran.xml
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\searchplugins\Vosteran.xml
Datei Gelöscht : C:\Users\Hans Leo\AppData\Roaming\Mozilla\Firefox\Profiles\9las2i8b.default\searchplugins\Vosteran.xml
Datei Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\searchplugins\Vosteran.xml
Datei Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal

***** [ Tasks ] *****

Task Gelöscht : LaunchApp
Task Gelöscht : LaunchSignup
Task Gelöscht : RocketTab Update Task
Task Gelöscht : RocketTab
Task Gelöscht : WSE_Vosteran
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-1
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-11
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-2
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-4
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-5
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-5_user
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-1
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-11
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-2
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-3
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-4
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-5
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-5_user
Task Gelöscht : ad3efa10-5ca0-40ff-a731-6065ac7d176a
Task Gelöscht : d7ab22e9-4a04-494e-a824-7c0e59c14f88

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{d9a96531-b093-4d07-9e4c-9704a365c441}]
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [clicup-Agent]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [InetStat]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\inetstat.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622112295}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572277}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655115595}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575577}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666116695}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576677}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644114495}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644574477}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EBB5099-9732-48AE-B032-58B702D86EEC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2299856A-6506-42E3-A34F-CD35A47C1B19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3EBB5099-9732-48AE-B032-58B702D86EEC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2299856A-6506-42E3-A34F-CD35A47C1B19}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}
Schlüssel Gelöscht : HKCU\Software\Boost
Schlüssel Gelöscht : HKCU\Software\clicup
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\RocketTabInstalled
Schlüssel Gelöscht : HKCU\Software\Search Extensions
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\SupHpUISoft
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\Easy Speed Check
Schlüssel Gelöscht : HKCU\Software\StormWatchApp
Schlüssel Gelöscht : HKCU\Software\BoBrowser
Schlüssel Gelöscht : HKCU\Software\StormWatch
Schlüssel Gelöscht : HKCU\Software\CoinisRS
Schlüssel Gelöscht : HKCU\Software\Vosteran Browser
Schlüssel Gelöscht : HKCU\Software\Cores
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Boost
Schlüssel Gelöscht : HKLM\SOFTWARE\EZ Software Updater
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\RocketTab
Schlüssel Gelöscht : HKLM\SOFTWARE\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\supWindowsMangerProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\webssearchesSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\WordProser_1.10.0.2
Schlüssel Gelöscht : HKLM\SOFTWARE\Clara
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RocketTab
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - _C:\PROGRA~1\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vosteran.com

[CODE]***** [ Browser ] *****

-\\ Internet Explorer v8.0.7600.16385

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

-\\ Mozilla Firefox v34.0 (x86 de)

[d1bpz2dw.default-1394125433030\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Vosteran");
[d1bpz2dw.default-1394125433030\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://Vosteran.com/?f=1&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1[...]
[rz7o2274.default-1403122915722\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Vosteran");
[rz7o2274.default-1403122915722\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://Vosteran.com/?f=1&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3324330&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP5558849D-C47D-47B4-B6C1-4A2F30A4CEC2");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("browser.search.order.1", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Vosteran");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://Vosteran.com/?f=1&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.crossrider.bic", "1442ab9a2c3c4eaa10db741e40a19457");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "cmi0301ff");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StD0AtCyD0FtDtCyBtGy B0D0E0BtGtAz[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.cr", "1051409894");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "0901-a");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.AL", 2);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.aflt", "cmi0301ff");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StD0AtCyD0FtDtCyBtGy B0D0E0BtGt[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.cntry", "DE");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.cr", "1051409894");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128 ,18285[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.hdrMd5", "31F6BB7992144B45E70A4D328B90FE86");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=cmi0301ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtC[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.id", "4061860B4E4FF19C");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.instlDay", "16132");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "0901-a");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0103aw&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByByCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutB[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.016:10:32");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=cmi0301ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytD[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.sg", "none");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=cmi0301ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzy[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.016:10:32");
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultenginename", "Vosteran");
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Vosteran");
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://Vosteran.com/?f=1&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1[...]
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.hmpgUrl", "hxxp://Vosteran.com/?f=1&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDy[...]
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.newTabUrl", "hxxp://Vosteran.com/?f=2&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzyt[...]
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.prtnrId", "WSE_Vosteran");
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.srchPrvdr", "Vosteran");
[9las2i8b.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.tlbrSrchUrl", "hxxp://Vosteran.com/?f=3&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBz[...]
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://Vosteran.com/?f=1&a=vst_coinis_14_49_ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtDyCyDtN1L2XzutAtFyCtFyCtFtDtN1L1CzutCyEtBzytDyD1V1[...]
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.crossrider.bic", "143aa01cf69d9ae61d9017ca8104b440");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.enabledAddons", "15d84a30-fc9d-4fca-80a7-e5797da621a2%40b2cb2d04-e262-4863-aee7-9d0e4333b550.com:0.93.24,ffxtlbr%40mysearchdial.com:1.6.0,%7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%[...]
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.aflt", "sft0102");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutDzytDtC0B");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.cr", "222425761");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.irmysearch.instlRef", "");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.AL", 2);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.aflt", "sft0102");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutDzytDtC0B");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.cr", "222425761");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=sft0102&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutDzy[...]
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.id", "4061860B4E4FF19C");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.instlDay", "16118");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=sft0102&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutD[...]
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=sft0102&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu[...]
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.018:51:50");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Vosteran");
[nrh2betl.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");

-\\ Google Chrome v

[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103aw&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByByCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Cz utBtAtDtC1N1R&cr=386325945&ir=
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : lekgiimbfodefdaoofhlckefjbgpeilo
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : ljmibnagodajacnnbifpamhggcohblip
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : kpjdjfkkmlgacmnenfhafmkldaogiglb
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : lekgiimbfodefdaoofhlckefjbgpeilo
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : lekgiimbfodefdaoofhlckefjbgpeilo
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : kpjdjfkkmlgacmnenfhafmkldaogiglb
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : lekgiimbfodefdaoofhlckefjbgpeilo
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Homepage] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0103aw&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByByCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=386325945& ir=
[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Startup_URLs] : hxxp://start.mysearchdial.com/?f=1&a=irmsd0103&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByCyCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=2039138040&i r=

-\\ Opera v0.0.0.0

[C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0103aw&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByByCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Cz utBtAtDtC1N1R&cr=386325945&ir=

*************************

AdwCleaner[R0].txt - [34086 octets] - [03/01/2015 12:51:57]
AdwCleaner[R1].txt - [34147 octets] - [03/01/2015 13:38:20]
AdwCleaner[S0].txt - [34303 octets] - [03/01/2015 13:41:08]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [34364 octets] ##########AdwCleaner Logfile:
Code:

# AdwCleaner v4.201 - Bericht erstellt 11/04/2015 um 12:31:39
# Aktualisiert 08/04/2015 von Xplode
# Datenbank : 2015-04-08.1 [Server]
# Betriebssystem : Windows 7 Home Premium  (x86)
# Benutzername : Dadmar Petri - DAGMAR
# Gestarted von : C:\Users\Dadmar Petri\Desktop\AdwCleaner_4.201.exe
# Option : Löschen

Code:

***** [ Dienste ] *****

[#] Dienst Gelöscht : globalUpdatem
[#] Dienst Gelöscht : wpnfd_1_10_0_2

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
Ordner Gelöscht : C:\Program Files\wordproser_1.10.0.5
Ordner Gelöscht : C:\Program Files\CinemaxMe-version2.0
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\clicup
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\StormWatch
Ordner Gelöscht : C:\Users\Dadmar Petri\AppData\Local\Weather_Protector_LLC
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\SoftwareUpdater
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\Tuguu_SL
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\DriverTuner
Ordner Gelöscht : C:\Users\Dagmar\AppData\Local\DriverToolkit
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\iSafe
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\okitspace
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\ValueApps
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\VOPackage
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\DriverFinder
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\iSafe
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}
Ordner Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\Extensions\46bccaaa-4500-481e-8908-9384802e175a@89a8fdd1-d807-4096-8025-a41093fce600.com
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\Extensions\PSFUZ20278470@LYMGVWA85453608.com
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
Ordner Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip
Datei Gelöscht : C:\Users\Dagmar\AppData\Local\AnyProtectScannerSetup.exe
Datei Gelöscht : C:\Users\Hans Leo\Desktop\Goodgame Empire.lnk
Datei Gelöscht : C:\Users\UpdatusUser\Desktop\Goodgame Empire.lnk
Datei Gelöscht : C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\user.js
Datei Gelöscht : C:\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\user.js
Datei Gelöscht : C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\searchplugins\search-provided-by-yahoo.xml
Datei Gelöscht : C:\Users\Hans Leo\AppData\Roaming\Mozilla\Firefox\Profiles\9las2i8b.default\searchplugins\search-provided-by-yahoo.xml

***** [ Geplante Tasks ] *****

Task Gelöscht : LaunchApp
Task Gelöscht : LaunchSignup
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-1
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-11
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-2
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-4
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-5
Task Gelöscht : 24852ac1-7ce1-47a1-be11-fd5c12287df3-5_user
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-1
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-11
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-2
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-3
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-4
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-5
Task Gelöscht : 5c88e756-5715-4945-8876-5ac5b1c5a119-5_user
Task Gelöscht : ad3efa10-5ca0-40ff-a731-6065ac7d176a
Task Gelöscht : d7ab22e9-4a04-494e-a824-7c0e59c14f88

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{d9a96531-b093-4d07-9e4c-9704a365c441}]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\inetstat.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622112295}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572277}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655115595}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575577}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666116695}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576677}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644114495}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644574477}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EBB5099-9732-48AE-B032-58B702D86EEC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3EBB5099-9732-48AE-B032-58B702D86EEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{67a81b9e-17dd-4fdf-bc4e-d60a42457c7d}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{aa1c8529-29c3-4ba9-be3b-0a2a0092afb1}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}
Schlüssel Gelöscht : HKCU\Software\clicup
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\SecuredDownload
Schlüssel Gelöscht : HKCU\Software\SupHpUISoft
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\StormWatchApp
Schlüssel Gelöscht : HKCU\Software\StormWatch
Schlüssel Gelöscht : HKCU\Software\CoinisRS
Schlüssel Gelöscht : HKCU\Software\Cores
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\CinemaxMe-version2.0
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\MyBestOffersToday
Schlüssel Gelöscht : HKLM\SOFTWARE\Speedchecker Limited
Schlüssel Gelöscht : HKLM\SOFTWARE\webssearchesSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\WordProser_1.10.0.2
Schlüssel Gelöscht : HKLM\SOFTWARE\CinemaxMe-version2.0
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\clicup
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\webssearches.com

Code:

***** [ Internetbrowser ] *****

-\\ Internet Explorer v8.0.7600.16385

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

-\\ Mozilla Firefox v

[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a2766e15f58d04887a1e82c7d6e3bac00a7ac7e9047c683f498com65777.65777.internaldb.__ICM_AJILLION__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C[...]
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a2766e15f58d04887a1e82c7d6e3bac00a7ac7e9047c683f498com65777.65777.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22a[...]
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a2766e15f58d04887a1e82c7d6e3bac00a7ac7e9047c683f498com65777.65777.internaldb.__ICM_LITE__fifty_test_rules.value", "%7B%22BR%22%3A%7B%22ALL%22%3A%5B%22tam.com.br%22%2C%22gol.com.b[...]
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a2766e15f58d04887a1e82c7d6e3bac00a7ac7e9047c683f498com65777.65777.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D[...]
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a9d2db1ce83264e61a7ee63d4ff932995ed00643899218cf824d695com61195.61195.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%2[...]
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "149ca5b69bb3d0a3ae9dea7dffabe92e");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.Visibility", false);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.backPageCapacity", 3);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.backPageCounter", 0);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.backPageDay", 20);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.backPageLastEvent", "1416266440557");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.backPageMinInterval", 15);
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.barcodeid", "148594");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.countryiso", "de");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.downloadprovider", "ob_119_ch");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\",\\\"sidecubes.com\\\",\\\"only-apartments.\\\",\\\"uk.search.yahoo.com\\\"],\\\[...]
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.fromautoupdate", "false");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.installationid", "1a296415-5188-89f5-2944-d5abf09ce9ce");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.installdate", "19/11/2014");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.iswinxp", "false");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1416439228");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1416439776182");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.helperbar.publisher", "shoppinghelper");
[3cdxsn3p.default\prefs.js] - Zeile Gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8v[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3324330&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP5558849D-C47D-47B4-B6C1-4A2F30A4CEC2");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "1442ab9a2c3c4eaa10db741e40a19457");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.aflt", "cmi0301ff");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StD0AtCyD0FtDtCyBtGyB0D0E0BtGtAz[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.cr", "1051409894");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.instlRef", "0901-a");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.AL", 2);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.aflt", "cmi0301ff");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtCtG1TtN1L1G1B1V1N2Y1L1Qzu2StD0AtCyD0FtDtCyBtGyB0D0E0BtGt[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cntry", "DE");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cr", "1051409894");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hdrMd5", "31F6BB7992144B45E70A4D328B90FE86");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=cmi0301ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytDtC[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.id", "4061860B4E4FF19C");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.instlDay", "16132");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.instlRef", "0901-a");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=irmsd0103aw&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByByCtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutB[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.016:10:32");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=cmi0301ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzytD[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"90\",\"lastVrsn\":\"90\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.sg", "none");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=cmi0301ff&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0CyBzytAtN1L2XzutBtFtCyBtFtDtFtCtN1L1CzutDzy[...]
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[sowx4lyk.default-1392247579485\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.016:10:32");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "143aa01cf69d9ae61d9017ca8104b440");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.enabledAddons", "15d84a30-fc9d-4fca-80a7-e5797da621a2%40b2cb2d04-e262-4863-aee7-9d0e4333b550.com:0.93.24,ffxtlbr%40mysearchdial.com:1.6.0,%7Bad9a41d2-9a49-4fa6-a79e-71a0785364c8%[...]
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.aflt", "sft0102");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutDzytDtC0B");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.cr", "222425761");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.irmysearch.instlRef", "");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.AL", 2);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.aflt", "sft0102");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutDzytDtC0B");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.cr", "222425761");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.dnsErr", true);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.excTlbr", false);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hmpg", true);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=sft0102&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutDzy[...]
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.id", "4061860B4E4FF19C");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.instlDay", "16118");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.instlRef", "");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=sft0102&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutD[...]
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=sft0102&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0SyByBzytN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1Czu[...]
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.21.0");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.21.0");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.hmpg", true);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.018:51:50");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial");
[nrh2betl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");

-\\ Google Chrome v


-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [58787 Bytes] - [03/01/2015 13:51:57]
AdwCleaner[R1].txt - [34147 Bytes] - [03/01/2015 14:38:20]
AdwCleaner[S0].txt - [59375 Bytes] - [03/01/2015 14:41:08]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [59435  Bytes] ##########

--- --- ---


Hier nun die log-Datei
Code:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.3 (04.07.2015:1)
OS: Windows 7 Home Premium x86
Ran by Dadmar Petri on 11.04.2015 at 13:45:42,94
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110611111195}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110611571177}



~~~ Files

Successfully deleted: [File] C:\Windows\prefetch\APNSTUB.EXE-2A8F922D.pf
Successfully deleted: [File] "C:\Windows\wininit.ini"



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.04.2015 at 13:47:14,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


schrauber 12.04.2015 07:05


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)

daggimaus 12.04.2015 08:26

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.3 (04.07.2015:1)
OS: Windows 7 Home Premium x86
Ran by Dadmar Petri on 12.04.2015 at  9:23:58,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [File] C:\user.js



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.04.2015 at  9:25:55,54
End of JRT log


schrauber 12.04.2015 10:19

dann noch obiges bitte :)

daggimaus 12.04.2015 10:46

FRST lo
 
Sorry, wo kann ich das Tool FRST herunterladen?
Danke für hilfe

schrauber 12.04.2015 17:49

Du hast es in Post #6 schon geladen :)

daggimaus 12.04.2015 19:33

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-04-2015
Ran by Dadmar Petri (administrator) on DAGMAR on 12-04-2015 19:23:23
Running from C:\Users\Dadmar Petri\Desktop
Loaded Profiles: Dadmar Petri & UpdatusUser (Available profiles: Dadmar Petri & Hans Leo & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium  (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-11] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\MountPoints2: {1114a94f-70d1-11e4-8c49-806e6f6e6963} - E:\setup.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
Startup: C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\nt2ty56p.Hans Leo
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-31] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-29]
CHR Extension: (Google Docs) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-29]
CHR Extension: (Google Drive) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-29]
CHR Extension: (YouTube) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-29]
CHR Extension: (Google Search) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-29]
CHR Extension: (Google Sheets) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-29]
CHR Extension: (Google Wallet) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-29]
CHR Extension: (Gmail) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-17] (Avira Operations GmbH & Co. KG)
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-03-17] (Avira GmbH)
S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-12 19:22 - 2015-04-12 19:22 - 00020262 _____ () C:\Users\Dadmar Petri\Desktop\Addition.txt
2015-04-12 19:21 - 2015-04-12 19:23 - 00016482 _____ () C:\Users\Dadmar Petri\Desktop\FRST.txt
2015-04-12 19:12 - 2015-04-12 19:12 - 01135616 _____ (Farbar) C:\Users\Dadmar Petri\Desktop\FRST.exe
2015-04-12 12:03 - 2015-04-12 12:06 - 00001022 _____ () C:\Windows\comsetup.log
2015-04-12 11:53 - 2015-04-12 11:53 - 00000000 ____D () C:\$WINDOWS.~LS
2015-04-12 11:51 - 2015-04-12 11:51 - 00000000 ____D () C:\$WINDOWS.~BT
2015-04-12 09:34 - 2015-04-12 09:34 - 00000632 _____ () C:\Users\Dadmar Petri\Desktop\JRT.txt
2015-04-12 09:20 - 2015-04-12 09:20 - 02686959 _____ (Thisisu) C:\Users\Dadmar Petri\Desktop\JRT.exe
2015-04-11 19:49 - 2015-04-11 19:49 - 40676944 _____ () C:\Users\Dadmar Petri\Desktop\Firefox_Setup_37.0.1.exe
2015-04-11 14:45 - 2015-04-11 14:45 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Avira
2015-04-11 14:41 - 2015-03-17 13:02 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-11 14:38 - 2015-04-11 14:38 - 00001165 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-11 14:37 - 2015-04-11 15:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-11 14:37 - 2015-04-11 14:37 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-11 14:34 - 2015-04-11 14:34 - 04625104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dadmar Petri\Desktop\avira_de_av_5529133b5619d__wsm.exe
2015-04-11 14:24 - 2015-04-11 14:51 - 00000000 ____D () C:\Program Files\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:38 - 00000000 ____D () C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:24 - 105603488 _____ () C:\Users\Dadmar Petri\Downloads\avira-antivirus.exe
2015-04-11 14:24 - 2015-04-11 14:24 - 00000000 ____D () C:\Program Files\Assist Point
2015-04-11 13:45 - 2015-04-11 13:45 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DAGMAR-Windows-7-Home-Premium-(32-bit).dat
2015-04-11 13:45 - 2015-04-11 13:45 - 00000000 ____D () C:\RegBackup
2015-04-11 11:50 - 2015-04-11 11:50 - 02217984 _____ () C:\Users\Dadmar Petri\Desktop\AdwCleaner_4.201.exe
2015-04-10 11:00 - 2015-04-10 11:00 - 00029620 _____ () C:\Users\Dadmar Petri\Downloads\Addition.txt
2015-04-10 10:59 - 2015-04-10 11:00 - 00038002 _____ () C:\Users\Dadmar Petri\Downloads\FRST.txt
2015-04-10 10:58 - 2015-04-12 19:23 - 00000000 ____D () C:\FRST
2015-04-10 10:57 - 2015-04-10 10:57 - 01135104 _____ (Farbar) C:\Users\Dadmar Petri\Downloads\FRST.exe
2015-04-09 15:39 - 2015-04-09 15:39 - 00000000 ____D () C:\Users\Dadmar Petri\Desktop\Malware
2015-04-09 12:05 - 2015-04-09 12:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(2).exe
2015-04-09 11:38 - 2015-04-09 11:38 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(1).exe
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 11:18 - 2015-04-09 11:18 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 09:35 - 2015-04-12 19:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimService
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimCleaner Plus
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc
2015-04-07 13:42 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\DriverUpdate
2015-04-07 13:42 - 2015-04-07 17:51 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc
2015-04-01 00:59 - 2015-04-12 11:37 - 00002542 _____ () C:\Windows\diagwrn.xml
2015-04-01 00:59 - 2015-04-12 11:37 - 00001890 _____ () C:\Windows\diagerr.xml
2015-04-01 00:53 - 2015-04-01 00:53 - 00394480 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis(1).exe
2015-04-01 00:49 - 2015-04-01 00:49 - 00005168 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis.log
2015-04-01 00:47 - 2015-04-01 00:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Dadmar Petri\Downloads\HijackThis.exe
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\OkayFreedom
2015-03-31 23:09 - 2015-04-01 01:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos VPN
2015-03-31 23:09 - 2015-03-31 23:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos
2015-03-31 23:09 - 2015-03-31 23:09 - 00001031 _____ () C:\Users\Public\Desktop\OkayFreedom.lnk
2015-03-31 23:09 - 2015-03-31 23:09 - 00000000 ____D () C:\Program Files\Common Files\Steganos
2015-03-31 21:52 - 2015-04-12 18:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-31 21:52 - 2015-04-09 22:16 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 21:52 - 2015-04-09 22:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 21:52 - 2015-03-31 21:52 - 01055936 _____ (Adobe) C:\Users\Dadmar Petri\Downloads\install_flashplayer17x32_mssd_aaa_aih.exe
2015-03-31 21:08 - 2015-03-31 21:08 - 00243576 _____ () C:\Users\Dadmar Petri\Downloads\Firefox Setup Stub 37.0.exe
2015-03-30 23:41 - 2015-03-31 21:45 - 00000000 ____D () C:\Program Files\Learn to Play Bridge 2
2015-03-30 23:41 - 2015-03-30 23:41 - 02062482 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb2setup.exe
2015-03-30 11:33 - 2015-03-31 21:45 - 00286720 _____ (Indigo Rose Corporation) C:\Windows\iun506.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 01865951 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb1setup.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\UpdatusUser\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Hans Leo\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Dadmar Petri\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\Program Files\Learn to Play Bridge
2015-03-30 11:24 - 2015-03-30 11:24 - 00698138 _____ () C:\Users\Dadmar Petri\Downloads\bbo_shortcut.exe
2015-03-30 00:14 - 2015-03-20 15:27 - 25808896 _____ () C:\Users\Dadmar Petri\Documents\Büro_2015_24.03.15.mdb
2015-03-26 18:08 - 2015-03-26 18:08 - 00462552 _____ () C:\Windows\Minidump\032615-20139-01.dmp
2015-03-23 16:06 - 2015-03-26 17:15 - 00000000 ____D () C:\e79d95644af82acfec248548e1a8067b
2015-03-23 16:05 - 2015-03-23 16:09 - 373578968 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe
2015-03-23 16:05 - 2015-03-23 16:07 - 08676128 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 40888512 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows-KB890830-V5.22.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 39074536 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\FileFormatConverters(1).exe
2015-03-23 13:57 - 2015-03-23 13:57 - 00462936 _____ () C:\Windows\Minidump\032315-32775-01.dmp
2015-03-23 12:24 - 2015-03-23 12:24 - 00031282 _____ () C:\Users\Dadmar Petri\Documents\Die Uhus.dotx
2015-03-23 10:50 - 2015-03-23 10:50 - 00463416 _____ () C:\Windows\Minidump\032315-21309-01.dmp
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-16 13:42 - 2015-03-16 13:42 - 00462864 _____ () C:\Windows\Minidump\031615-20280-01.dmp
2015-03-15 01:14 - 2015-03-15 01:14 - 00475440 _____ () C:\Windows\Minidump\031515-20030-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-12 19:19 - 2014-11-20 15:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-04-12 19:19 - 2014-11-20 01:14 - 00001368 _____ () C:\Windows\Tasks\UTLKMTU.job
2015-04-12 19:19 - 2014-11-20 01:13 - 00001366 _____ () C:\Windows\Tasks\FUPWXF.job
2015-04-12 19:19 - 2014-11-19 22:59 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-04-12 19:19 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-12 19:19 - 2009-07-14 06:39 - 00001141 _____ () C:\Windows\setupact.log
2015-04-12 19:18 - 2014-11-19 23:40 - 00968790 _____ () C:\Windows\PFRO.log
2015-04-12 19:08 - 2014-11-19 16:32 - 01836315 _____ () C:\Windows\WindowsUpdate.log
2015-04-12 12:10 - 2009-07-14 06:34 - 00002526 _____ () C:\Windows\DtcInstall.log
2015-04-12 12:03 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-12 11:42 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-12 11:42 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-12 11:38 - 2014-11-19 17:52 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-12 11:37 - 2009-07-14 06:39 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\ProgramData\Avira
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\Program Files\Avira
2015-04-11 12:37 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-11 12:32 - 2015-01-03 13:51 - 00000000 ____D () C:\AdwCleaner
2015-04-10 10:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-04-09 22:16 - 2014-11-20 01:41 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Adobe
2015-04-08 19:56 - 2014-12-30 10:50 - 00271360 _____ () C:\Users\Hans Leo\Documents\Kontakte.pst
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\ProgramData\Netzmanager
2015-04-08 09:59 - 2014-11-20 01:42 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-08 09:59 - 2014-11-20 00:09 - 00000000 ____D () C:\Users\Hans Leo
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-08 09:58 - 2014-11-21 11:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Mozilla
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-08 09:58 - 2014-11-20 00:52 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Mozilla
2015-04-08 09:57 - 2014-01-18 12:16 - 00000000 __RHD () C:\MSOCache
2015-04-08 09:13 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri
2015-04-01 19:22 - 2014-11-20 13:46 - 00065464 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 00:54 - 2014-11-29 14:48 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\dlg
2015-04-01 00:48 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\VirtualStore
2015-03-31 22:11 - 2009-07-14 06:33 - 00303112 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-31 20:37 - 2014-11-19 23:59 - 00065464 _____ () C:\Users\Dadmar Petri\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-31 20:14 - 2014-11-23 20:04 - 00000000 ____D () C:\Users\Dadmar Petri\Documents\DIE UHUS
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-31 19:17 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-29 20:54 - 2015-01-12 20:57 - 00000000 ____D () C:\Windows\pss
2015-03-29 20:11 - 2015-01-02 13:41 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-29 09:03 - 2015-01-02 13:42 - 00000000 ____D () C:\Program Files\Bonjour
2015-03-28 19:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-26 18:08 - 2015-01-03 16:50 - 321192056 _____ () C:\Windows\MEMORY.DMP
2015-03-26 18:08 - 2015-01-03 16:50 - 00000000 ____D () C:\Windows\Minidump
2015-03-26 17:15 - 2015-01-03 16:48 - 00000000 ____D () C:\NVIDIA
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 17:15 - 2014-11-28 23:40 - 00000000 ____D () C:\Program Files\Microsoft Windows 7 Upgrade Advisor

==================== Files in the root of some directories =======

2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Dadmar Petri\AppData\Roaming\FUPWXF
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Dadmar Petri\AppData\Roaming\UTLKMTU
2014-12-20 10:45 - 2014-12-20 10:45 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Dadmar Petri\AppData\Local\Temp\AskSLib.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\avgnt.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\BackupSetup.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\MSNEE75.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\ose00000.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\Quarantine.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\setup_337.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\sqlite3.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is3FAE.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is8574.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is9A89.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-25 10:42

==================== End Of Log ============================

--- --- ---

--- --- ---


Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-04-2015
Ran by Dadmar Petri (administrator) on DAGMAR on 12-04-2015 20:30:27
Running from C:\Users\Dadmar Petri\Desktop
Loaded Profiles: Dadmar Petri & UpdatusUser (Available profiles: Dadmar Petri & Hans Leo & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium  (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_17_0_0_134_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-11] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\MountPoints2: {1114a94f-70d1-11e4-8c49-806e6f6e6963} - E:\setup.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
Startup: C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_14&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzzyDtN1L2XzutAtFzytFyEtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0Ezz0C0DzytDyBtGtCzy0CzztG0C0FyEyBtGtAtCtD0DtGtCtDtBzyzy0Fzy0DyCtDtCtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0BtC0EyEtC0ByE0FtG0AyEyD0FtGyEtDyCyCtGzytCyD0EtGtBzytDtA0EyBzz0C0AtB0F0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyCyDyD%26cr%3D761057204%26a%3Dwny_secureddownload_15_14%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\nt2ty56p.Hans Leo
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-31] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-29]
CHR Extension: (Google Docs) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-29]
CHR Extension: (Google Drive) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-29]
CHR Extension: (YouTube) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-29]
CHR Extension: (Google Search) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-29]
CHR Extension: (Google Sheets) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-29]
CHR Extension: (Google Wallet) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-29]
CHR Extension: (Gmail) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-17] (Avira Operations GmbH & Co. KG)
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-03-17] (Avira GmbH)
S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-12 19:31 - 2015-04-12 19:31 - 00243656 _____ () C:\Users\Dadmar Petri\Desktop\Firefox Setup Stub 37.0.1.exe
2015-04-12 19:22 - 2015-04-12 19:22 - 00020262 _____ () C:\Users\Dadmar Petri\Desktop\Addition.txt
2015-04-12 19:21 - 2015-04-12 20:30 - 00016582 _____ () C:\Users\Dadmar Petri\Desktop\FRST.txt
2015-04-12 19:12 - 2015-04-12 19:12 - 01135616 _____ (Farbar) C:\Users\Dadmar Petri\Desktop\FRST.exe
2015-04-12 12:03 - 2015-04-12 12:06 - 00001022 _____ () C:\Windows\comsetup.log
2015-04-12 11:53 - 2015-04-12 11:53 - 00000000 ____D () C:\$WINDOWS.~LS
2015-04-12 11:51 - 2015-04-12 11:51 - 00000000 ____D () C:\$WINDOWS.~BT
2015-04-12 09:34 - 2015-04-12 09:34 - 00000632 _____ () C:\Users\Dadmar Petri\Desktop\JRT.txt
2015-04-12 09:20 - 2015-04-12 09:20 - 02686959 _____ (Thisisu) C:\Users\Dadmar Petri\Desktop\JRT.exe
2015-04-11 19:49 - 2015-04-11 19:49 - 40676944 _____ () C:\Users\Dadmar Petri\Desktop\Firefox_Setup_37.0.1.exe
2015-04-11 14:45 - 2015-04-11 14:45 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Avira
2015-04-11 14:41 - 2015-03-17 13:02 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-11 14:38 - 2015-04-11 14:38 - 00001165 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-11 14:37 - 2015-04-11 15:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-11 14:37 - 2015-04-11 14:37 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-11 14:34 - 2015-04-11 14:34 - 04625104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dadmar Petri\Desktop\avira_de_av_5529133b5619d__wsm.exe
2015-04-11 14:24 - 2015-04-11 14:51 - 00000000 ____D () C:\Program Files\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:38 - 00000000 ____D () C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:24 - 105603488 _____ () C:\Users\Dadmar Petri\Downloads\avira-antivirus.exe
2015-04-11 14:24 - 2015-04-11 14:24 - 00000000 ____D () C:\Program Files\Assist Point
2015-04-11 13:45 - 2015-04-11 13:45 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DAGMAR-Windows-7-Home-Premium-(32-bit).dat
2015-04-11 13:45 - 2015-04-11 13:45 - 00000000 ____D () C:\RegBackup
2015-04-11 11:50 - 2015-04-11 11:50 - 02217984 _____ () C:\Users\Dadmar Petri\Desktop\AdwCleaner_4.201.exe
2015-04-10 11:00 - 2015-04-10 11:00 - 00029620 _____ () C:\Users\Dadmar Petri\Downloads\Addition.txt
2015-04-10 10:59 - 2015-04-10 11:00 - 00038002 _____ () C:\Users\Dadmar Petri\Downloads\FRST.txt
2015-04-10 10:58 - 2015-04-12 20:30 - 00000000 ____D () C:\FRST
2015-04-10 10:57 - 2015-04-10 10:57 - 01135104 _____ (Farbar) C:\Users\Dadmar Petri\Downloads\FRST.exe
2015-04-09 15:39 - 2015-04-09 15:39 - 00000000 ____D () C:\Users\Dadmar Petri\Desktop\Malware
2015-04-09 12:05 - 2015-04-09 12:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(2).exe
2015-04-09 11:38 - 2015-04-09 11:38 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(1).exe
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 11:18 - 2015-04-09 11:18 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 09:35 - 2015-04-12 19:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimService
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimCleaner Plus
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc
2015-04-07 13:42 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\DriverUpdate
2015-04-07 13:42 - 2015-04-07 17:51 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc
2015-04-01 00:59 - 2015-04-12 11:37 - 00002542 _____ () C:\Windows\diagwrn.xml
2015-04-01 00:59 - 2015-04-12 11:37 - 00001890 _____ () C:\Windows\diagerr.xml
2015-04-01 00:53 - 2015-04-01 00:53 - 00394480 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis(1).exe
2015-04-01 00:49 - 2015-04-01 00:49 - 00005168 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis.log
2015-04-01 00:47 - 2015-04-01 00:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Dadmar Petri\Downloads\HijackThis.exe
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\OkayFreedom
2015-03-31 23:09 - 2015-04-01 01:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos VPN
2015-03-31 23:09 - 2015-03-31 23:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos
2015-03-31 23:09 - 2015-03-31 23:09 - 00001031 _____ () C:\Users\Public\Desktop\OkayFreedom.lnk
2015-03-31 23:09 - 2015-03-31 23:09 - 00000000 ____D () C:\Program Files\Common Files\Steganos
2015-03-31 21:52 - 2015-04-12 19:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-31 21:52 - 2015-04-09 22:16 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 21:52 - 2015-04-09 22:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 21:52 - 2015-03-31 21:52 - 01055936 _____ (Adobe) C:\Users\Dadmar Petri\Downloads\install_flashplayer17x32_mssd_aaa_aih.exe
2015-03-31 21:08 - 2015-03-31 21:08 - 00243576 _____ () C:\Users\Dadmar Petri\Downloads\Firefox Setup Stub 37.0.exe
2015-03-30 23:41 - 2015-03-31 21:45 - 00000000 ____D () C:\Program Files\Learn to Play Bridge 2
2015-03-30 23:41 - 2015-03-30 23:41 - 02062482 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb2setup.exe
2015-03-30 11:33 - 2015-03-31 21:45 - 00286720 _____ (Indigo Rose Corporation) C:\Windows\iun506.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 01865951 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb1setup.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\UpdatusUser\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Hans Leo\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Dadmar Petri\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\Program Files\Learn to Play Bridge
2015-03-30 11:24 - 2015-03-30 11:24 - 00698138 _____ () C:\Users\Dadmar Petri\Downloads\bbo_shortcut.exe
2015-03-30 00:14 - 2015-03-20 15:27 - 25808896 _____ () C:\Users\Dadmar Petri\Documents\Büro_2015_24.03.15.mdb
2015-03-26 18:08 - 2015-03-26 18:08 - 00462552 _____ () C:\Windows\Minidump\032615-20139-01.dmp
2015-03-23 16:06 - 2015-03-26 17:15 - 00000000 ____D () C:\e79d95644af82acfec248548e1a8067b
2015-03-23 16:05 - 2015-03-23 16:09 - 373578968 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe
2015-03-23 16:05 - 2015-03-23 16:07 - 08676128 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 40888512 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows-KB890830-V5.22.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 39074536 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\FileFormatConverters(1).exe
2015-03-23 13:57 - 2015-03-23 13:57 - 00462936 _____ () C:\Windows\Minidump\032315-32775-01.dmp
2015-03-23 12:24 - 2015-03-23 12:24 - 00031282 _____ () C:\Users\Dadmar Petri\Documents\Die Uhus.dotx
2015-03-23 10:50 - 2015-03-23 10:50 - 00463416 _____ () C:\Windows\Minidump\032315-21309-01.dmp
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-16 13:42 - 2015-03-16 13:42 - 00462864 _____ () C:\Windows\Minidump\031615-20280-01.dmp
2015-03-15 01:14 - 2015-03-15 01:14 - 00475440 _____ () C:\Windows\Minidump\031515-20030-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-12 19:33 - 2012-01-31 20:40 - 00000236 _____ () C:\Users\Dadmar Petri\Desktop\Bridge Base Online.url
2015-04-12 19:26 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-12 19:26 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-12 19:22 - 2014-11-19 16:32 - 01836315 _____ () C:\Windows\WindowsUpdate.log
2015-04-12 19:19 - 2014-11-20 15:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-04-12 19:19 - 2014-11-20 01:14 - 00001368 _____ () C:\Windows\Tasks\UTLKMTU.job
2015-04-12 19:19 - 2014-11-20 01:13 - 00001366 _____ () C:\Windows\Tasks\FUPWXF.job
2015-04-12 19:19 - 2014-11-19 22:59 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-04-12 19:19 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-12 19:19 - 2009-07-14 06:39 - 00001141 _____ () C:\Windows\setupact.log
2015-04-12 19:18 - 2014-11-19 23:40 - 00968790 _____ () C:\Windows\PFRO.log
2015-04-12 12:10 - 2009-07-14 06:34 - 00002526 _____ () C:\Windows\DtcInstall.log
2015-04-12 12:03 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-12 11:38 - 2014-11-19 17:52 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-12 11:37 - 2009-07-14 06:39 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\ProgramData\Avira
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\Program Files\Avira
2015-04-11 12:37 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-11 12:32 - 2015-01-03 13:51 - 00000000 ____D () C:\AdwCleaner
2015-04-10 10:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-04-09 22:16 - 2014-11-20 01:41 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Adobe
2015-04-08 19:56 - 2014-12-30 10:50 - 00271360 _____ () C:\Users\Hans Leo\Documents\Kontakte.pst
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\ProgramData\Netzmanager
2015-04-08 09:59 - 2014-11-20 01:42 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-08 09:59 - 2014-11-20 00:09 - 00000000 ____D () C:\Users\Hans Leo
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-08 09:58 - 2014-11-21 11:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Mozilla
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-08 09:58 - 2014-11-20 00:52 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Mozilla
2015-04-08 09:57 - 2014-01-18 12:16 - 00000000 __RHD () C:\MSOCache
2015-04-08 09:13 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri
2015-04-01 19:22 - 2014-11-20 13:46 - 00065464 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 00:54 - 2014-11-29 14:48 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\dlg
2015-04-01 00:48 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\VirtualStore
2015-03-31 22:11 - 2009-07-14 06:33 - 00303112 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-31 20:37 - 2014-11-19 23:59 - 00065464 _____ () C:\Users\Dadmar Petri\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-31 20:14 - 2014-11-23 20:04 - 00000000 ____D () C:\Users\Dadmar Petri\Documents\DIE UHUS
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-31 19:17 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-29 20:54 - 2015-01-12 20:57 - 00000000 ____D () C:\Windows\pss
2015-03-29 20:11 - 2015-01-02 13:41 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-29 09:03 - 2015-01-02 13:42 - 00000000 ____D () C:\Program Files\Bonjour
2015-03-28 19:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-26 18:08 - 2015-01-03 16:50 - 321192056 _____ () C:\Windows\MEMORY.DMP
2015-03-26 18:08 - 2015-01-03 16:50 - 00000000 ____D () C:\Windows\Minidump
2015-03-26 17:15 - 2015-01-03 16:48 - 00000000 ____D () C:\NVIDIA
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 17:15 - 2014-11-28 23:40 - 00000000 ____D () C:\Program Files\Microsoft Windows 7 Upgrade Advisor

==================== Files in the root of some directories =======

2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\Dadmar Petri\AppData\Roaming\FUPWXF
2014-09-01 10:18 - 2014-09-01 10:18 - 0002086 _____ () C:\Users\Dadmar Petri\AppData\Roaming\UTLKMTU
2014-12-20 10:45 - 2014-12-20 10:45 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Dadmar Petri\AppData\Local\Temp\AskSLib.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\avgnt.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\BackupSetup.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\MSNEE75.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\ose00000.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\Quarantine.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\setup_337.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\sqlite3.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is3FAE.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is8574.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is9A89.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-25 10:42


schrauber 13.04.2015 09:50

Und ESET Onlinescan und Securitycheck???

daggimaus 13.04.2015 15:56

ich habe nach Anweisung den Esetsmart installer heruntergeladen und einen Scan durchgeführt nach der bebilderten Anweisung. Das lief bis ungefähr 50 %, dann ging nichts mehr weiter. Ich habe den Eset deinsalliert und nochmal von der Seite neu installiert. Dann kommt die Meldung, dass mein Computer bereits gescannt wurde und nur noch die Dateien heruntergeladen werden, die noch benötigt werden. Dann wurde bis 5 % gescannt und es ging wieder nicht weiter. Was soll ich tun?

daggimaus

schrauber 14.04.2015 06:31

ESET weg lassen, dafür das hier:

Lade Dir bitte von hier Emsisoft Emergency Kit Download Emsisoft Emergency Kit herunter.
  • Bitte installiere das Programm in den vorgegebenen Pfad.
  • Starte das Programm durch Doppelklick der Desktopverknüpfung.
  • Das EEK ist nach dem Laden der Malwaresignaturen für den Scan bereit.
  • Folge nun bitte der bebilderten Bildanleitung zu Emergency Kit, entferne alle Funde und poste am Ende des Scans bzw. der Bereinigung das Log.


daggimaus 14.04.2015 08:48

Hallo,

hab ich gemacht. Der Scan hat angefangen und jetzt bei 50 % geht es nicht weiter. Dasselbe Phänomen wie bei dem nderen progrmm.
Gruß daggimaus

Hallo,

was ist das denn? Ich hatt das Programm noch nicht beendet und als ich ins Internet auf die Seite hier ging und wieder zurück, lief das Programm weiter. Jetz warte ich mal ab.

Gruß daggimaus

schrauber 14.04.2015 16:50

mysteriös :)

daggimaus 14.04.2015 19:43

Scan-Ergebnis von Emsisoft Emergenc Kit
 
Code:

Emsisoft Emergency Kit - Version 9.0
Letztes Update: 14.04.2015 09:33:39
Benutzerkonto: DAGMAR\Dadmar Petri

Scan-Einstellungen:

Scan Methode: Detail-Scan
Objekte: Rootkits, Speicher, Traces, C:\, D:\, F:\

PUPs-Erkennung: An
Archiv-Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus

Scan-Beginn:        14.04.2015 17:36:52
C:\Users\DADMAR~1\AppData\Local\Temp\APN-Stub        gefunden: Application.Win32.WebToolbar (A)
C:\Users\DADMAR~1\AppData\Local\Temp\APN-Stub        gefunden: Application.Win32.WebToolbar (A)
C:\Program Files\DriverUpdate        gefunden: Application.InstallDrive (A)
C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc\DriverUpdate        gefunden: Application.InstallDrive (A)
Value: HKEY_USERS\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR        gefunden: Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS        gefunden: Setting.DisableRegistryTools (A)
Key: HKEY_USERS\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}        gefunden: Application.Win32.WSearch (A)
Key: HKEY_USERS\S-1-5-21-941624961-3290542821-2423505712-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}        gefunden: Application.Win32.WSearch (A)
Key: HKEY_USERS\S-1-5-21-941624961-3290542821-2423505712-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}        gefunden: Application.Win32.WSearch (A)
Key: HKEY_USERS\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\SMARTBAR        gefunden: Application.InstallAd (A)
C:\AdwCleaner\Quarantine\C\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3.crx.vir -> extensionData/plugins/281.js        gefunden: Adware.JS.Agent.AC (B)
C:\AdwCleaner\Quarantine\C\Program Files\CinemaxMe-version2.0\24852ac1-7ce1-47a1-be11-fd5c12287df3.xpi.vir -> extensionData/plugins/281.js        gefunden: Adware.JS.Agent.AC (B)
C:\AdwCleaner\Quarantine\C\Program Files\CinemaxMe-version2.0\f2106091-a987-4e9e-af5a-faeea27b387e.crx.vir -> extensionData/plugins/281.js        gefunden: Adware.JS.Agent.AC (B)
C:\AdwCleaner\Quarantine\C\Program Files\CinemaxMe-version2.0\utils.exe.vir -> (NSIS o) -> lzma_solid_nsis0004        gefunden: Gen:Application.Parj.1 (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\CltMngSvc.exe.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\SPtool.dll.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\uninstall.exe.vir -> (NSIS o) -> lzma_solid_nsis0002        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\Main\bin\uninstall.exe.vir -> (NSIS o) -> lzma_solid_nsis0004 -> (NSIS o) -> zlib_nsis0000        gefunden: Application.SearchProtect.R (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\SPtool64.exe.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\VC32.dll.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\VC32Loader.dll.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\VC64.dll.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\SearchProtect\bin\VC64Loader.dll.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Program Files\SearchProtect\UI\bin\cltmngui.exe.vir        gefunden: Adware.SearchProtect.U (B)
C:\AdwCleaner\Quarantine\C\Users\Dadmar Petri\AppData\Local\clicup\chrmndr.exe.vir        gefunden: Adware.Cyclon.A (B)
C:\AdwCleaner\Quarantine\C\Users\Dadmar Petri\AppData\Local\clicup\ClicupHome.exe.vir -> (RAR Sfx o) -> chrmndr.exe        gefunden: Adware.Cyclon.A (B)
C:\AdwCleaner\Quarantine\C\Users\Dadmar Petri\AppData\Local\clicup\ClicupHome.exe.vir -> (RAR Sfx o) -> toast.exe        gefunden: Adware.Cyclon.A (B)
C:\AdwCleaner\Quarantine\C\Users\Dadmar Petri\AppData\Local\clicup\toast.exe.vir        gefunden: Adware.Cyclon.A (B)
C:\AdwCleaner\Quarantine\C\Users\Dadmar Petri\AppData\Local\StormWatch\StormWatchBrowser.exe.vir        gefunden: Application.Win32.AdWatch (A)
C:\AdwCleaner\Quarantine\C\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\d1bpz2dw.default-1394125433030\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}\bootstrap.js.vir        gefunden: Trojan.JS.Agent.JMG (B)
C:\AdwCleaner\Quarantine\C\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\rz7o2274.default-1403122915722\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}\bootstrap.js.vir        gefunden: Trojan.JS.Agent.JMG (B)
C:\AdwCleaner\Quarantine\C\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\sowx4lyk.default-1392247579485\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}\bootstrap.js.vir        gefunden: Trojan.JS.Agent.JMG (B)
C:\AdwCleaner\Quarantine\C\Users\Dagmar\AppData\Roaming\okitspace\IE\OkitSpace.dll.vir        gefunden: Adware.Agent.NZG (B)
C:\AdwCleaner\Quarantine\C\Users\Dagmar\AppData\Roaming\okitspace\protect\files\OKitSpace.dll.vir        gefunden: Adware.Agent.NZG (B)
C:\AdwCleaner\Quarantine\C\Users\Hans Leo.Dagmar-PC\AppData\Roaming\Mozilla\Firefox\Profiles\nrh2betl.default\Extensions\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}\bootstrap.js.vir        gefunden: Trojan.JS.Agent.JMG (B)
C:\ProgramData\Avira\Antivirus\INFECTED\0a498d8f.qua -> (Quarantine-8)        gefunden: Adware.BrowseFox.CQ (B)
C:\ProgramData\Avira\Antivirus\INFECTED\14a6b4f3.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Kazy.566748 (B)
C:\ProgramData\Avira\Antivirus\INFECTED\4270e8f4.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Kazy.566748 (B)
C:\ProgramData\Avira\Antivirus\INFECTED\45ffa92c.qua -> (Quarantine-8)        gefunden: Adware.BrowseFox.CQ (B)
C:\ProgramData\Avira\Antivirus\INFECTED\46f1af4a.qua -> (Quarantine-8)        gefunden: Adware.BrowseFox.CQ (B)
C:\ProgramData\Avira\Antivirus\INFECTED\5b18e907.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Kazy.566748 (B)
C:\ProgramData\Avira\Antivirus\INFECTED\7642fdca.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Kazy.566748 (B)
C:\temp\t.msi -> (Embedded CAB) -> CustomActionInstall        gefunden: Application.Generic.1163133 (B)
C:\temp\t.msi -> (Embedded CAB) -> IEOptimizer64.dll        gefunden: Application.Generic.1063474 (B)
C:\temp\t.msi -> (Embedded EXE)        gefunden: Application.Generic.1163133 (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\4EA4tmp\setup.exe -> (NSIS o) -> bzip2_solid_nsis0002        gefunden: Trojan.Generic.12210195 (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\D197tmp\lly_omiga-plus.exe        gefunden: Gen:Application.Elex.1 (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\D199tmp\setup.exe -> (NSIS o) -> bzip2_solid_nsis0002        gefunden: Trojan.Generic.12210195 (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\clicup_1211-047e07e1.exe -> (NSIS o) -> lzma_nsis0002 -> (RAR Sfx o) -> chrmndr.exe        gefunden: Adware.Cyclon.A (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\clicup_1211-047e07e1.exe -> (NSIS o) -> lzma_nsis0002 -> (RAR Sfx o) -> toast.exe        gefunden: Adware.Cyclon.A (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\clicup_1211-047e07e1.exe -> (NSIS o) -> lzma_nsis0005        gefunden: Adware.Cyclon.A (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\WIE_2.18.1.8.exe -> (NSIS o) -> lzma_solid_nsis0040        gefunden: Trojan.Generic.12956360 (B)
C:\Users\Dadmar Petri\AppData\Local\Temp\n7531\WIE_2.18.1.8.exe -> (NSIS o) -> lzma_solid_nsis0051        gefunden: Gen:Variant.Adware.Graftor.173564 (B)
C:\Users\Dadmar Petri\AppData\Roaming\FUPWXF -> background.js        gefunden: Trojan.Script.Agent.FA (B)
C:\Users\Dadmar Petri\AppData\Roaming\UTLKMTU -> content/overlay.js        gefunden: Adware.JS.Mplug.A (B)
C:\Users\Dagmar\AppData\Roaming\nationzoom\UpDate.dll        gefunden: Application.Win32.InstallTech (A)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 0) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (BMP)        gefunden: Exploit.CVE-2013-2729.Gen (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 0) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 0) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT-COMPILATION)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 14) -> [Subject: Proof of Delivery Report: 05/05/14][Date: Mon, 5 May 2014 18:58:14 +0000] -> (MIME part) -> pod report 05.05.2014-35506035.zip -> pod report 05.05.2014-11902101.exe        gefunden: Gen:Variant.Kazy.377287 (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 0) -> [Subject: Proof of Delivery Report: 05/05/14][Date: Mon, 5 May 2014 18:58:14 +0000] -> (MIME part) -> pod report 05.05.2014-35506035.zip -> pod report 05.05.2014-11902101.exe        gefunden: Gen:Variant.Kazy.377287 (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 5) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (BMP)        gefunden: Exploit.CVE-2013-2729.Gen (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 5) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 5) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT-COMPILATION)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Windows.old\Program Files\Feven Pro\Uninstall.exe        gefunden: Gen:Application.Heur.eqW@lmCdLZai (B)
C:\Windows.old\Program Files\MediaPlayerEnhance\Uninstall.exe        gefunden: Gen:Application.Heur.fqX@l4ngO8mi (B)
C:\Windows.old\Program Files\MediaPlayerEnhance\utils.exe        gefunden: Application.Win32.InstallTool (A)
C:\Windows.old\Program Files\Plus-HD-7.2\Uninstall.exe        gefunden: Gen:Application.Heur.eqX@lGoUhqbi (B)
C:\Windows.old\Program Files\SavingsBull\bootstrap.js        gefunden: Adware.Adpeak.L (B)
C:\Windows.old\Program Files\SavingsBull\IEOptimizer64.dll        gefunden: Application.Generic.1063474 (B)
C:\Windows.old\Program Files\Uninstaller\Uninstall.exe        gefunden: Application.InstallAd (A)
C:\Windows.old\Program Files\Web Protect\PCCertInstaller.dll        gefunden: Gen:Adware.WebProtect.1 (B)
C:\Windows.old\Program Files\Web Protect\PCProtect.dll        gefunden: Adware.Agent.NXW (B)
C:\Windows.old\Program Files\Web Protect\pcwatch.sys        gefunden: Gen:Adware.WebProtect.1 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\0ccf6f8c.qua -> (Quarantine-8)        gefunden: Gen:Variant.Zusy.107504 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\1285838d.qua -> (Quarantine-8)        gefunden: Application.Generic.1016044 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\15f193cc.qua -> (Quarantine-8)        gefunden: Application.Bundler.DomaIQ.Q (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\183cf449.qua -> (Quarantine-8)        gefunden: Adware.Agent.NXR (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\1ce314f5.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Graftor.141873 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\2b67aa43.qua -> (Quarantine-8)        gefunden: Trojan.Generic.12752903 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\3087d101.qua -> (Quarantine-8)        gefunden: Application.Generic.872997 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\3a30842b.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.NewNextMe.1 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\3f504ec3.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Graftor.141873 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\4227848d.qua -> (Quarantine-8)        gefunden: Application.Bundler.HG (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\42c08ece.qua -> (Quarantine-8)        gefunden: Application.Generic.961669 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\4516a914.qua -> (Quarantine-8)        gefunden: Adware.Agent.OFO (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\47907f77.qua -> (Quarantine-8)        gefunden: Adware.Agent.ODG (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\4967408d.qua -> (Quarantine-8)        gefunden: Adware.Agent.ODG (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\4a639eab.qua -> (Quarantine-8)        gefunden: Adware.Agent.NXR (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\4eef3938.qua -> (Quarantine-8)        gefunden: Gen:Variant.Zusy.107504 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\50d34775.qua -> (Quarantine-8) -> (Instyler o) -> (Instyler Module 0)        gefunden: Trojan.GenericKD.1698677 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\50e940f6.qua -> (Quarantine-8) -> (Instyler o) -> (Instyler Module 0)        gefunden: Trojan.GenericKD.1698677 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\5133cf01.qua -> (Quarantine-8) -> (Instyler o) -> (Instyler Module 0)        gefunden: Trojan.GenericKD.1698677 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\515e7568.qua -> (Quarantine-8)        gefunden: Trojan.GenericKD.2188191 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\51f061a6.qua -> (Quarantine-8)        gefunden: Adware.Agent.ODG (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\5275f454.qua -> (Quarantine-8)        gefunden: Gen:Variant.Application.Bundler.5 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\52f48b90.qua -> (Quarantine-8)        gefunden: Adware.Agent.NXR (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\539c383c.qua -> (Quarantine-8)        gefunden: Adware.Adpeak.K (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\54042667.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\544bf8dc.qua -> (Quarantine-8) -> (NSIS o) -> lzma_solid_nsis0007        gefunden: Gen:Variant.Adware.Graftor.133169 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\546c7290.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\547039ba.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\547f9d98.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\548599ed.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\552eaf71.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\55361020.qua -> (Quarantine-8)        gefunden: Gen:Variant.Application.Bundler.OptimumInstaller.3 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\55814f5c.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\55dcbcc8.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\5617cfb0.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\56781863.qua -> (Quarantine-8)        gefunden: Gen:Variant.Zusy.107504 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\567c7aa1.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\56b5f4a9.qua -> (Quarantine-8)        gefunden: Trojan.Generic.11625666 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\5fe9d4fc.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.NewNextMe.1 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\6647f433.qua -> (Quarantine-8)        gefunden: Adware.Generic.1178286 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\6e41f514.qua -> (Quarantine-8)        gefunden: Adware.Generic.1068408 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\79c8f391.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.NewNextMe.1 (B)
C:\Windows.old\ProgramData\Avira\AntiVir Desktop\INFECTED\7ad455bb.qua -> (Quarantine-8)        gefunden: Gen:Variant.Adware.Graftor.141873 (B)
C:\Windows.old\ProgramData\WPM\wprotectmanager.exe        gefunden: Adware.WProtManager.A (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\nationzoom\UpDate.dll        gefunden: Application.Win32.InstallTech (A)
C:\Windows.old\Users\Dagmar\AppData\Roaming\okitspace\IE\OkitSpace.dll        gefunden: Adware.Agent.NZG (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\okitspace\protect\files\OKitSpace.dll        gefunden: Adware.Agent.NZG (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 0) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (BMP)        gefunden: Exploit.CVE-2013-2729.Gen (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 0) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 0) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT-COMPILATION)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\INBOX -> (message 14) -> [Subject: Proof of Delivery Report: 05/05/14][Date: Mon, 5 May 2014 18:58:14 +0000] -> (MIME part) -> pod report 05.05.2014-35506035.zip -> pod report 05.05.2014-11902101.exe        gefunden: Gen:Variant.Kazy.377287 (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 0) -> [Subject: Proof of Delivery Report: 05/05/14][Date: Mon, 5 May 2014 18:58:14 +0000] -> (MIME part) -> pod report 05.05.2014-35506035.zip -> pod report 05.05.2014-11902101.exe        gefunden: Gen:Variant.Kazy.377287 (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 5) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (BMP)        gefunden: Exploit.CVE-2013-2729.Gen (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 5) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Windows.old\Users\Dagmar\AppData\Roaming\Thunderbird\Profiles\dkum7ocy.default\ImapMail\imap.unitybox.de\Trash -> (message 5) -> [Subject: Invoice 787016 April][Date: Tue, 6 May 2014 12:55:45 +0530] -> (MIME part) -> (MIME part) -> April invoice 717334.pdf -> (JAVASCRIPT-COMPILATION)        gefunden: Exploit.JS.PDF.FJ (B)
C:\Windows.old\Windows\Installer\116ee.msi -> (Embedded CAB) -> CustomActionInstall        gefunden: Application.Generic.1163133 (B)
C:\Windows.old\Windows\Installer\116ee.msi -> (Embedded CAB) -> IEOptimizer64.dll        gefunden: Application.Generic.1063474 (B)
C:\Windows.old\Windows\Installer\116ee.msi -> (Embedded EXE)        gefunden: Application.Generic.1163133 (B)
C:\Windows.old\Windows\System32\PCProtect.dll        gefunden: Adware.Agent.NXW (B)

Gescannt        479079
Gefunden        134

Scan-Ende:        14.04.2015 20:08:04
Scan-Zeit:        2:31:12

Code:

Results of screen317's Security Check version 1.00 
 Windows 7  x86 (UAC is enabled) 
 Out of date service pack!!
``````````````Antivirus/Firewall Check:``````````````
Avira Antivirus 
 Antivirus up to date!  (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
 Adobe Flash Player        17.0.0.134 
 Adobe Reader XI 
````````Process Check: objlist.exe by Laurent```````` 
 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 
````````````````````End of Log``````````````````````


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-04-2015
Ran by Dadmar Petri (administrator) on DAGMAR on 14-04-2015 20:40:01
Running from C:\Users\Dadmar Petri\Downloads
Loaded Profiles: Dadmar Petri & Hans Leo & UpdatusUser (Available profiles: Dadmar Petri & Hans Leo & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium  (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
() C:\Users\Dadmar Petri\Desktop\SecurityCheck.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-11] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [InetStat] => C:\Users\Hans Leo\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [clicup-Agent] => C:\Users\Hans Leo\AppData\Local\clicup\chrmndr.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
Startup: C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)
BootExecute: autocheck autochk * C:\Windows\system32\eamclean.exe \??\C:\Windows\system32\eamclean.dat eamcleanC:\Windows\system32\eamclean.exe \??\C:\Windows\system32\eamclean.dat eamcleanC:\Windows\system32\eamclean.exe \??\C:\Windows\system32\eamclean.dat eamclean

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1001 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-31] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-29]
CHR Extension: (Google Docs) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-29]
CHR Extension: (Google Drive) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-29]
CHR Extension: (YouTube) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-29]
CHR Extension: (Google Search) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-29]
CHR Extension: (Google Sheets) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-29]
CHR Extension: (Google Wallet) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-29]
CHR Extension: (Gmail) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 A2DDA; C:\EEK\bin\a2ddax86.sys [22056 2015-04-14] (Emsisoft GmbH)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-17] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\EEK\bin\cleanhlp32.sys [50200 2015-04-14] (Emsisoft GmbH)
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-03-17] (Avira GmbH)
S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-14 20:39 - 2015-04-14 20:39 - 00000000 ____D () C:\Users\Dadmar Petri\Downloads\FRST-OlderVersion
2015-04-14 20:12 - 2015-04-14 20:12 - 00072704 _____ (Emsisoft GmbH) C:\Windows\system32\eamclean.exe
2015-04-14 20:12 - 2015-04-14 20:12 - 00000386 _____ () C:\Windows\system32\eamclean.dat
2015-04-14 15:30 - 2015-04-14 15:30 - 00466488 _____ () C:\Windows\Minidump\041415-36629-01.dmp
2015-04-14 12:24 - 2015-04-14 12:24 - 00465824 _____ () C:\Windows\Minidump\041415-22432-01.dmp
2015-04-14 09:26 - 2015-04-14 17:36 - 00000000 ____D () C:\EEK
2015-04-13 16:42 - 2015-04-13 16:42 - 00852616 _____ () C:\Users\Dadmar Petri\Desktop\SecurityCheck.exe
2015-04-12 19:31 - 2015-04-12 19:31 - 00243656 _____ () C:\Users\Dadmar Petri\Desktop\Firefox Setup Stub 37.0.1.exe
2015-04-12 19:21 - 2015-04-12 20:31 - 00032041 _____ () C:\Users\Dadmar Petri\Desktop\FRST.txt
2015-04-12 12:03 - 2015-04-12 12:06 - 00001022 _____ () C:\Windows\comsetup.log
2015-04-12 11:53 - 2015-04-12 11:53 - 00000000 ____D () C:\$WINDOWS.~LS
2015-04-12 11:51 - 2015-04-12 11:51 - 00000000 ____D () C:\$WINDOWS.~BT
2015-04-11 19:49 - 2015-04-11 19:49 - 40676944 _____ () C:\Users\Dadmar Petri\Desktop\Firefox_Setup_37.0.1.exe
2015-04-11 14:45 - 2015-04-11 14:45 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Avira
2015-04-11 14:41 - 2015-03-17 13:02 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-11 14:38 - 2015-04-11 14:38 - 00001165 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-11 14:37 - 2015-04-11 15:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-11 14:37 - 2015-04-11 14:37 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-11 14:34 - 2015-04-11 14:34 - 04625104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dadmar Petri\Desktop\avira_de_av_5529133b5619d__wsm.exe
2015-04-11 14:24 - 2015-04-11 14:51 - 00000000 ____D () C:\Program Files\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:38 - 00000000 ____D () C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:24 - 105603488 _____ () C:\Users\Dadmar Petri\Downloads\avira-antivirus.exe
2015-04-11 13:45 - 2015-04-11 13:45 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DAGMAR-Windows-7-Home-Premium-(32-bit).dat
2015-04-11 13:45 - 2015-04-11 13:45 - 00000000 ____D () C:\RegBackup
2015-04-10 11:00 - 2015-04-10 11:00 - 00029620 _____ () C:\Users\Dadmar Petri\Downloads\Addition.txt
2015-04-10 10:59 - 2015-04-14 20:40 - 00015740 _____ () C:\Users\Dadmar Petri\Downloads\FRST.txt
2015-04-10 10:58 - 2015-04-14 20:40 - 00000000 ____D () C:\FRST
2015-04-10 10:57 - 2015-04-14 20:39 - 01135616 _____ (Farbar) C:\Users\Dadmar Petri\Downloads\FRST.exe
2015-04-09 12:05 - 2015-04-09 12:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(2).exe
2015-04-09 11:38 - 2015-04-09 11:38 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(1).exe
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 11:18 - 2015-04-09 11:18 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 09:35 - 2015-04-13 23:02 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimService
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimCleaner Plus
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc
2015-04-07 13:42 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\DriverUpdate
2015-04-07 13:42 - 2015-04-07 17:51 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc
2015-04-01 00:59 - 2015-04-12 11:37 - 00002542 _____ () C:\Windows\diagwrn.xml
2015-04-01 00:59 - 2015-04-12 11:37 - 00001890 _____ () C:\Windows\diagerr.xml
2015-04-01 00:49 - 2015-04-01 00:49 - 00005168 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis.log
2015-04-01 00:47 - 2015-04-01 00:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Dadmar Petri\Downloads\HijackThis.exe
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\OkayFreedom
2015-03-31 23:09 - 2015-04-01 01:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos VPN
2015-03-31 23:09 - 2015-03-31 23:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos
2015-03-31 23:09 - 2015-03-31 23:09 - 00001031 _____ () C:\Users\Public\Desktop\OkayFreedom.lnk
2015-03-31 23:09 - 2015-03-31 23:09 - 00000000 ____D () C:\Program Files\Common Files\Steganos
2015-03-31 21:52 - 2015-04-14 19:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-31 21:52 - 2015-04-09 22:16 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 21:52 - 2015-04-09 22:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 21:52 - 2015-03-31 21:52 - 01055936 _____ (Adobe) C:\Users\Dadmar Petri\Downloads\install_flashplayer17x32_mssd_aaa_aih.exe
2015-03-31 21:08 - 2015-03-31 21:08 - 00243576 _____ () C:\Users\Dadmar Petri\Downloads\Firefox Setup Stub 37.0.exe
2015-03-30 23:41 - 2015-03-31 21:45 - 00000000 ____D () C:\Program Files\Learn to Play Bridge 2
2015-03-30 23:41 - 2015-03-30 23:41 - 02062482 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb2setup.exe
2015-03-30 11:33 - 2015-03-31 21:45 - 00286720 _____ (Indigo Rose Corporation) C:\Windows\iun506.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 01865951 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb1setup.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\UpdatusUser\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Hans Leo\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Dadmar Petri\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\Program Files\Learn to Play Bridge
2015-03-30 11:24 - 2015-03-30 11:24 - 00698138 _____ () C:\Users\Dadmar Petri\Downloads\bbo_shortcut.exe
2015-03-30 00:14 - 2015-03-20 15:27 - 25808896 _____ () C:\Users\Dadmar Petri\Documents\Büro_2015_24.03.15.mdb
2015-03-26 18:08 - 2015-03-26 18:08 - 00462552 _____ () C:\Windows\Minidump\032615-20139-01.dmp
2015-03-23 16:06 - 2015-03-26 17:15 - 00000000 ____D () C:\e79d95644af82acfec248548e1a8067b
2015-03-23 16:05 - 2015-03-23 16:09 - 373578968 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe
2015-03-23 16:05 - 2015-03-23 16:07 - 08676128 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 40888512 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows-KB890830-V5.22.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 39074536 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\FileFormatConverters(1).exe
2015-03-23 13:57 - 2015-03-23 13:57 - 00462936 _____ () C:\Windows\Minidump\032315-32775-01.dmp
2015-03-23 12:24 - 2015-03-23 12:24 - 00031282 _____ () C:\Users\Dadmar Petri\Documents\Die Uhus.dotx
2015-03-23 10:50 - 2015-03-23 10:50 - 00463416 _____ () C:\Windows\Minidump\032315-21309-01.dmp
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-16 13:42 - 2015-03-16 13:42 - 00462864 _____ () C:\Windows\Minidump\031615-20280-01.dmp
2015-03-15 01:14 - 2015-03-15 01:14 - 00475440 _____ () C:\Windows\Minidump\031515-20030-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-14 20:12 - 2014-01-31 13:38 - 00000000 ____D () C:\temp
2015-04-14 20:12 - 2014-01-18 21:01 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\nationzoom
2015-04-14 19:54 - 2014-11-19 16:32 - 01938378 _____ () C:\Windows\WindowsUpdate.log
2015-04-14 17:06 - 2014-11-20 01:14 - 00001368 _____ () C:\Windows\Tasks\UTLKMTU.job
2015-04-14 17:06 - 2014-11-20 01:13 - 00001366 _____ () C:\Windows\Tasks\FUPWXF.job
2015-04-14 17:06 - 2014-11-19 22:59 - 00000430 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-04-14 15:38 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-14 15:38 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-14 15:30 - 2015-01-03 16:50 - 385888152 _____ () C:\Windows\MEMORY.DMP
2015-04-14 15:30 - 2015-01-03 16:50 - 00000000 ____D () C:\Windows\Minidump
2015-04-14 15:30 - 2014-11-20 15:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-04-14 15:30 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-14 15:30 - 2009-07-14 06:39 - 00001589 _____ () C:\Windows\setupact.log
2015-04-13 23:02 - 2014-11-19 23:40 - 00969864 _____ () C:\Windows\PFRO.log
2015-04-13 20:20 - 2014-12-30 10:50 - 00271360 _____ () C:\Users\Hans Leo\Documents\Kontakte.pst
2015-04-13 20:19 - 2014-11-23 20:04 - 00000000 ____D () C:\Users\Dadmar Petri\Documents\DIE UHUS
2015-04-13 11:47 - 2014-11-19 17:52 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-12 19:33 - 2012-01-31 20:40 - 00000236 _____ () C:\Users\Dadmar Petri\Desktop\Bridge Base Online.url
2015-04-12 12:10 - 2009-07-14 06:34 - 00002526 _____ () C:\Windows\DtcInstall.log
2015-04-12 12:03 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-12 11:37 - 2009-07-14 06:39 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\ProgramData\Avira
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\Program Files\Avira
2015-04-11 12:37 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-11 12:32 - 2015-01-03 13:51 - 00000000 ____D () C:\AdwCleaner
2015-04-10 10:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-04-09 22:16 - 2014-11-20 01:41 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Adobe
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\ProgramData\Netzmanager
2015-04-08 09:59 - 2014-11-20 01:42 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-08 09:59 - 2014-11-20 00:09 - 00000000 ____D () C:\Users\Hans Leo
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-08 09:58 - 2014-11-21 11:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Mozilla
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-08 09:58 - 2014-11-20 00:52 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Mozilla
2015-04-08 09:57 - 2014-01-18 12:16 - 00000000 __RHD () C:\MSOCache
2015-04-08 09:13 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri
2015-04-01 19:22 - 2014-11-20 13:46 - 00065464 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 00:54 - 2014-11-29 14:48 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\dlg
2015-04-01 00:48 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\VirtualStore
2015-03-31 22:11 - 2009-07-14 06:33 - 00303112 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-31 20:37 - 2014-11-19 23:59 - 00065464 _____ () C:\Users\Dadmar Petri\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-31 19:17 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-29 20:54 - 2015-01-12 20:57 - 00000000 ____D () C:\Windows\pss
2015-03-29 20:11 - 2015-01-02 13:41 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-29 09:03 - 2015-01-02 13:42 - 00000000 ____D () C:\Program Files\Bonjour
2015-03-28 19:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-26 17:15 - 2015-01-03 16:48 - 00000000 ____D () C:\NVIDIA
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 17:15 - 2014-11-28 23:40 - 00000000 ____D () C:\Program Files\Microsoft Windows 7 Upgrade Advisor

==================== Files in the root of some directories =======

2014-12-20 10:45 - 2014-12-20 10:45 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Dadmar Petri\AppData\Local\Temp\AskSLib.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\avgnt.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\BackupSetup.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\MSNEE75.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\ose00000.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\Quarantine.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\setup_337.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\sqlite3.dll
C:\Users\Dadmar Petri\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is3FAE.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is8574.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\_is9A89.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-14 16:00

==================== End Of Log ============================

--- --- ---

--- --- ---

schrauber 15.04.2015 10:55

Funde von EEK auch löschen lassen. Ordner Windows.old komplett löschen.

Windows updaten, da fehlen 4 Jahre Updates inklusive Servicepack 1.

daggimaus 16.04.2015 16:35

Hallo,

der Windows Ordner old lässt sich nicht löschen. Es kommt jedesmal die Meldung, dass die Datei gerade in "use" ist. Ich habe es auch schon amabgesicherten Modus probiert, aber das funktioniert auch nicht. Langsam nervt mich das alles. Was kann ich noch tun.Evt. im DOS Modus den Ordner löschen. Was muss ich eingeben, um in diesen Modus zu kommen. Danke fürdie Hilfe Gruß daggimaus

schrauber 16.04.2015 21:44

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

CloseProcesses:
HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [InetStat] => C:\Users\Hans Leo\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [clicup-Agent] => C:\Users\Hans Leo\AppData\Local\clicup\chrmndr.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
C:\Users\Hans Leo\AppData\Roaming\InetStat
C:\Users\Hans Leo\AppData\Local\clicup
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1001 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
C:\Windows.old
Emptytemp:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


daggimaus 17.04.2015 08:39

Hier nun die gewünschte log-Datei. Ich benutze Mozillan Firefox. Jedesmal wenn ich damit ins Internet gehe, muss ich bestätigen, dass ich Administrationsrechte und muss damit öffnen. Ist das neuerdings so. Ich habe schon zweimal das Programm gelöscht und wieder neu installiert. Es ändert sich aber nichts. Was ist das denn nun wieder? Oder ist das die neue Version von Mozilla Firefox. Das kanns aber doch nicht sein.:crazy:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by Dadmar Petri (administrator) on DAGMAR on 17-04-2015 09:32:43
Running from C:\Users\Dadmar Petri\Documents\Downloads
Loaded Profiles: Dadmar Petri & UpdatusUser (Available profiles: Dadmar Petri & Hans Leo & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium  Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(IObit) C:\Program Files\IObit\Smart Defrag 4\SmartDefrag.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 8\Monitor.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(IObit) C:\Program Files\IObit\IObit Malware Fighter\IMFTips.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Farbar) C:\Users\Dadmar Petri\Documents\Downloads\FRST(2).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-11] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [IObit Malware Fighter] => C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [5844800 2015-04-02] (IObit)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [Advanced SystemCare 8] => C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe [2429728 2015-04-08] (IObit)
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
Startup: C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2015-04-15] (IObit)
BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit)
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2015-04-15] (IObit)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer
FF Homepage: spiegel-online.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qid9w6ga.Dagmar\user.js [2015-04-15]
FF user.js: detected! => C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer\user.js [2015-04-15]
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qid9w6ga.Dagmar\Extensions\iobitascsurfingprotection@iobit.com [2015-04-15]
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer\Extensions\iobitascsurfingprotection@iobit.com [2015-04-15]
FF Extension: Adblock Plus - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-14]
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com

Chrome:
=======
CHR Profile: C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-29]
CHR Extension: (Google Docs) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-29]
CHR Extension: (Google Drive) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-29]
CHR Extension: (YouTube) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-29]
CHR Extension: (Google Search) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-29]
CHR Extension: (Google Sheets) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-29]
CHR Extension: (Google Wallet) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-29]
CHR Extension: (Gmail) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
R2 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [878912 2015-04-02] (IObit)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-03-26] (IObit)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-17] (Avira Operations GmbH & Co. KG)
R3 FileMonitor; C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [21480 2015-03-25] (IObit)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-04-15] (REALiX(tm))
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R3 RegFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [32288 2015-03-25] (IObit.com)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [18624 2014-06-04] (IObit)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-03-17] (Avira GmbH)
S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
R3 UrlFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [20944 2015-03-25] (IObit.com)
S1 A2DDA; \??\C:\EEK\bin\a2ddax86.sys [X]
S3 cleanhlp; \??\C:\EEK\bin\cleanhlp32.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-16 12:20 - 2015-04-16 12:20 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\Avira
2015-04-16 12:14 - 2015-04-16 12:14 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\IObit
2015-04-15 19:55 - 2015-04-17 08:51 - 00001288 _____ () C:\Windows\setupact.log
2015-04-15 19:55 - 2015-04-15 19:55 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-15 19:54 - 2015-04-15 19:54 - 00001028 _____ () C:\Windows\PFRO.log
2015-04-15 19:35 - 2015-04-15 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
2015-04-15 19:19 - 2014-06-04 15:17 - 00031008 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2015-04-15 19:18 - 2015-04-15 19:18 - 00001128 _____ () C:\Users\Public\Desktop\Smart Defrag 4.lnk
2015-04-15 19:18 - 2015-04-15 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 4
2015-04-15 19:18 - 2015-01-10 15:32 - 00109856 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
2015-04-15 19:18 - 2014-06-04 15:17 - 00018624 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2015-04-15 19:12 - 2015-04-17 08:51 - 00000286 _____ () C:\Windows\Tasks\Driver Booster Update.job
2015-04-15 19:12 - 2015-04-17 08:51 - 00000284 _____ () C:\Windows\Tasks\Driver Booster Scan.job
2015-04-15 19:12 - 2015-04-15 19:12 - 00023840 _____ (REALiX(tm)) C:\Windows\system32\Drivers\HWiNFO32.SYS
2015-04-15 19:12 - 2015-04-15 19:12 - 00001198 _____ () C:\Users\Public\Desktop\Driver Booster 2.lnk
2015-04-15 19:12 - 2015-04-15 19:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 2
2015-04-15 19:02 - 2015-04-17 08:51 - 00000294 _____ () C:\Windows\Tasks\ASC8_PerformanceMonitor.job
2015-04-15 19:01 - 2015-04-15 19:35 - 00001131 _____ () C:\Users\Public\Desktop\IObit Malware Fighter.lnk
2015-04-15 19:01 - 2015-04-15 19:01 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\ProductData
2015-04-15 19:00 - 2015-04-16 07:45 - 00000000 ____D () C:\Users\All Users\ProductData
2015-04-15 19:00 - 2015-04-16 07:45 - 00000000 ____D () C:\Users\All Users\IObit
2015-04-15 19:00 - 2015-04-16 07:45 - 00000000 ____D () C:\ProgramData\ProductData
2015-04-15 19:00 - 2015-04-16 07:45 - 00000000 ____D () C:\ProgramData\IObit
2015-04-15 19:00 - 2015-04-15 19:38 - 00000000 ____D () C:\Users\All Users\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-04-15 19:00 - 2015-04-15 19:38 - 00000000 ____D () C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-04-15 19:00 - 2015-04-15 19:18 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\IObit
2015-04-15 19:00 - 2015-04-15 19:18 - 00000000 ____D () C:\Program Files\IObit
2015-04-15 19:00 - 2015-04-15 19:11 - 00002127 _____ () C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
2015-04-15 19:00 - 2015-04-15 19:00 - 00001186 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-04-15 19:00 - 2015-04-15 19:00 - 00000000 ____D () C:\Windows\Tasks\ImCleanDisabled
2015-04-15 19:00 - 2015-04-15 19:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-04-15 19:00 - 2015-04-15 19:00 - 00000000 ____D () C:\Program Files\Common Files\IObit
2015-04-14 21:08 - 2015-04-14 21:08 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-14 21:08 - 2015-04-14 21:08 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-14 21:08 - 2015-04-14 21:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-14 20:52 - 2015-04-14 20:52 - 00008242 _____ () C:\EamClean.log
2015-04-14 20:49 - 2015-04-14 20:50 - 01795729 _____ (Medion) C:\Users\Dadmar Petri\Downloads\fwupt50n.exe
2015-04-14 20:39 - 2015-04-14 20:39 - 00000000 ____D () C:\Users\Dadmar Petri\Downloads\FRST-OlderVersion
2015-04-14 15:30 - 2015-04-14 15:30 - 00466488 _____ () C:\Windows\Minidump\041415-36629-01.dmp
2015-04-14 12:24 - 2015-04-14 12:24 - 00465824 _____ () C:\Windows\Minidump\041415-22432-01.dmp
2015-04-13 16:42 - 2015-04-13 16:42 - 00852616 _____ () C:\Users\Dadmar Petri\Desktop\SecurityCheck.exe
2015-04-12 19:21 - 2015-04-12 20:31 - 00032041 _____ () C:\Users\Dadmar Petri\Desktop\FRST.txt
2015-04-12 11:53 - 2015-04-12 11:53 - 00000000 ____D () C:\$WINDOWS.~LS
2015-04-12 11:51 - 2015-04-12 11:51 - 00000000 ____D () C:\$WINDOWS.~BT
2015-04-11 14:45 - 2015-04-11 14:45 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Avira
2015-04-11 14:41 - 2015-03-17 13:02 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-11 14:38 - 2015-04-11 14:38 - 00001165 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-11 14:37 - 2015-04-11 15:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-11 14:37 - 2015-04-11 14:37 - 00000000 ____D () C:\Users\All Users\Package Cache
2015-04-11 14:37 - 2015-04-11 14:37 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-11 14:34 - 2015-04-11 14:34 - 04625104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dadmar Petri\Desktop\avira_de_av_5529133b5619d__wsm.exe
2015-04-11 14:24 - 2015-04-11 14:51 - 00000000 ____D () C:\Program Files\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:38 - 00000000 ____D () C:\Users\All Users\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:38 - 00000000 ____D () C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:24 - 105603488 _____ () C:\Users\Dadmar Petri\Downloads\avira-antivirus.exe
2015-04-11 13:45 - 2015-04-11 13:45 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DAGMAR-Windows-7-Home-Premium-(32-bit).dat
2015-04-11 13:45 - 2015-04-11 13:45 - 00000000 ____D () C:\RegBackup
2015-04-10 11:00 - 2015-04-10 11:00 - 00029620 _____ () C:\Users\Dadmar Petri\Downloads\Addition.txt
2015-04-10 10:59 - 2015-04-14 20:40 - 00031028 _____ () C:\Users\Dadmar Petri\Downloads\FRST.txt
2015-04-10 10:58 - 2015-04-17 09:32 - 00000000 ____D () C:\FRST
2015-04-10 10:57 - 2015-04-14 20:39 - 01135616 _____ (Farbar) C:\Users\Dadmar Petri\Downloads\FRST.exe
2015-04-09 12:05 - 2015-04-09 12:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(2).exe
2015-04-09 11:38 - 2015-04-09 11:38 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(1).exe
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\Users\All Users\Malwarebytes
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 11:18 - 2015-04-09 11:18 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 09:35 - 2015-04-14 21:08 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimService
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimCleaner Plus
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\Users\All Users\SlimWare Utilities Inc
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc
2015-04-07 13:42 - 2015-04-07 17:51 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc
2015-04-01 00:59 - 2015-04-12 11:37 - 00002542 _____ () C:\Windows\diagwrn.xml
2015-04-01 00:59 - 2015-04-12 11:37 - 00001890 _____ () C:\Windows\diagerr.xml
2015-04-01 00:49 - 2015-04-01 00:49 - 00005168 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis.log
2015-04-01 00:47 - 2015-04-01 00:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Dadmar Petri\Downloads\HijackThis.exe
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\OkayFreedom
2015-03-31 23:09 - 2015-04-01 01:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos VPN
2015-03-31 23:09 - 2015-03-31 23:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos
2015-03-31 23:09 - 2015-03-31 23:09 - 00000000 ____D () C:\Program Files\Common Files\Steganos
2015-03-31 21:52 - 2015-04-16 17:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-31 21:52 - 2015-04-14 21:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 21:52 - 2015-04-14 21:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 21:52 - 2015-03-31 21:52 - 01055936 _____ (Adobe) C:\Users\Dadmar Petri\Downloads\install_flashplayer17x32_mssd_aaa_aih.exe
2015-03-31 21:08 - 2015-03-31 21:08 - 00243576 _____ () C:\Users\Dadmar Petri\Downloads\Firefox Setup Stub 37.0.exe
2015-03-30 23:41 - 2015-03-31 21:45 - 00000000 ____D () C:\Program Files\Learn to Play Bridge 2
2015-03-30 23:41 - 2015-03-30 23:41 - 02062482 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb2setup.exe
2015-03-30 11:33 - 2015-03-31 21:45 - 00286720 _____ (Indigo Rose Corporation) C:\Windows\iun506.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 01865951 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb1setup.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\UpdatusUser\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Hans Leo\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Dadmar Petri\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\Program Files\Learn to Play Bridge
2015-03-30 11:24 - 2015-03-30 11:24 - 00698138 _____ () C:\Users\Dadmar Petri\Downloads\bbo_shortcut.exe
2015-03-30 00:14 - 2015-03-20 15:27 - 25808896 _____ () C:\Users\Dadmar Petri\Documents\Büro_2015_24.03.15.mdb
2015-03-26 18:08 - 2015-03-26 18:08 - 00462552 _____ () C:\Windows\Minidump\032615-20139-01.dmp
2015-03-23 16:06 - 2015-03-26 17:15 - 00000000 ____D () C:\e79d95644af82acfec248548e1a8067b
2015-03-23 16:05 - 2015-03-23 16:09 - 373578968 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe
2015-03-23 16:05 - 2015-03-23 16:07 - 08676128 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 40888512 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows-KB890830-V5.22.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 39074536 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\FileFormatConverters(1).exe
2015-03-23 13:57 - 2015-03-23 13:57 - 00462936 _____ () C:\Windows\Minidump\032315-32775-01.dmp
2015-03-23 12:24 - 2015-03-23 12:24 - 00031282 _____ () C:\Users\Dadmar Petri\Documents\Die Uhus.dotx
2015-03-23 10:50 - 2015-03-23 10:50 - 00463416 _____ () C:\Windows\Minidump\032315-21309-01.dmp
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\Users\All Users\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-17 08:58 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-17 08:58 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-17 08:54 - 2014-11-19 16:32 - 01055669 _____ () C:\Windows\WindowsUpdate.log
2015-04-17 08:51 - 2014-11-20 15:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-04-17 08:51 - 2014-11-20 01:14 - 00001368 _____ () C:\Windows\Tasks\UTLKMTU.job
2015-04-17 08:51 - 2014-11-20 01:13 - 00001366 _____ () C:\Windows\Tasks\FUPWXF.job
2015-04-17 08:51 - 2014-11-19 22:59 - 00000433 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-04-17 08:51 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-16 13:04 - 2014-12-30 10:50 - 00271360 _____ () C:\Users\Hans Leo\Documents\Kontakte.pst
2015-04-16 09:23 - 2014-11-19 22:12 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Microsoft Help
2015-04-16 08:30 - 2014-11-19 16:08 - 00000000 ____D () C:\Windows.old.000
2015-04-15 22:33 - 2014-11-17 11:27 - 00000000 ____D () C:\Windows.old
2015-04-15 19:11 - 2014-11-23 20:04 - 00000000 ____D () C:\Users\Dadmar Petri\Documents\DIE UHUS
2015-04-15 19:11 - 2014-11-19 16:28 - 00000000 ____D () C:\Windows\Panther
2015-04-15 19:00 - 2015-01-02 13:46 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Apple Computer
2015-04-15 19:00 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri
2015-04-14 21:37 - 2014-11-20 01:41 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Adobe
2015-04-14 20:50 - 2014-03-03 23:41 - 00000000 ____D () C:\Medion
2015-04-14 20:12 - 2014-01-31 13:38 - 00000000 ____D () C:\temp
2015-04-14 20:12 - 2014-01-18 21:01 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\nationzoom
2015-04-14 15:30 - 2015-01-03 16:50 - 385888152 _____ () C:\Windows\MEMORY.DMP
2015-04-14 15:30 - 2015-01-03 16:50 - 00000000 ____D () C:\Windows\Minidump
2015-04-13 11:47 - 2014-11-19 17:52 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-12 19:33 - 2012-01-31 20:40 - 00000236 _____ () C:\Users\Dadmar Petri\Desktop\Bridge Base Online.url
2015-04-12 12:03 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\Users\All Users\Avira
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\ProgramData\Avira
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\Program Files\Avira
2015-04-11 12:37 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-11 12:32 - 2015-01-03 13:51 - 00000000 ____D () C:\AdwCleaner
2015-04-10 10:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\Users\All Users\Netzmanager
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\ProgramData\Netzmanager
2015-04-08 09:59 - 2014-11-20 01:42 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-08 09:59 - 2014-11-20 00:09 - 00000000 ____D () C:\Users\Hans Leo
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-08 09:58 - 2014-11-21 11:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Mozilla
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\Users\All Users\NVIDIA
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-08 09:58 - 2014-11-20 00:52 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Mozilla
2015-04-08 09:57 - 2014-01-18 12:16 - 00000000 __RHD () C:\MSOCache
2015-04-01 19:22 - 2014-11-20 13:46 - 00065464 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 00:54 - 2014-11-29 14:48 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\dlg
2015-04-01 00:48 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\VirtualStore
2015-03-31 22:11 - 2009-07-14 06:33 - 00303112 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-31 20:37 - 2014-11-19 23:59 - 00065464 _____ () C:\Users\Dadmar Petri\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\Users\All Users\Microsoft Help
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-31 19:17 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-29 20:54 - 2015-01-12 20:57 - 00000000 ____D () C:\Windows\pss
2015-03-29 20:11 - 2015-01-02 13:41 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-29 09:03 - 2015-01-02 13:42 - 00000000 ____D () C:\Program Files\Bonjour
2015-03-28 19:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-26 17:15 - 2015-01-03 16:48 - 00000000 ____D () C:\NVIDIA
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 17:15 - 2014-11-28 23:40 - 00000000 ____D () C:\Program Files\Microsoft Windows 7 Upgrade Advisor

==================== Files in the root of some directories =======

2014-12-20 10:45 - 2014-12-20 10:45 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Dadmar Petri\AppData\Local\Temp\ASCSetup_3405267.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\avgnt.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-14 16:00

==================== End Of Log ============================

--- --- ---

schrauber 17.04.2015 19:46

Hast Du den Fix gemacht?

daggimaus 18.04.2015 10:58

Das hatte ich meines Wissens schon geschickt. Aber hier nochmal:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by Dadmar Petri (administrator) on DAGMAR on 17-04-2015 23:18:42
Running from C:\Users\Dadmar Petri\Downloads\FRST-OlderVersion
Loaded Profiles: Dadmar Petri & Hans Leo & UpdatusUser (Available profiles: Dadmar Petri & Hans Leo & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium  (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 8\Monitor.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Steganos Software GmbH) C:\Program Files\OkayFreedom\OkayFreedomService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_17_0_0_169_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [mbot_de_292] => [X]
HKLM\...\Run: [] => [X]
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-11] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Run: [Advanced SystemCare 8] => C:\Program Files\IObit\Advanced SystemCare 8\ASCTray.exe [2429728 2015-04-08] (IObit)
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [InetStat] => C:\Users\Hans Leo\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\...\Run: [clicup-Agent] => C:\Users\Hans Leo\AppData\Local\clicup\chrmndr.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [InetStat] => C:\Users\UpdatusUser\AppData\Roaming\InetStat\inetstat.exe
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\...\Run: [clicup-Agent] => C:\Users\UpdatusUser\AppData\Local\clicup\chrmndr.exe
Startup: C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-941624961-3290542821-2423505712-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKU\S-1-5-21-941624961-3290542821-2423505712-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSHw,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2pe3cBiUP2kjpCxARPJjGyrOgOPN7jaCfiLR6DLYFTCl6cPZmG0a45XDbr5kt5nQ,,
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_l4MkPpONrsnaOi2aKJtss8TtA0PxPtS5_ArfOXJhUttP0_eU1N1gN8AC7dI9zamlf1WqP38ntbhRJVUTju1csgZZN2leGpPaKT2Rf8vD-AFnsEea3NRoPTOFJbgbA1SXa4UM96GrzZz33zT5KVhynzSGA,,&q={searchTerms}
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
HKU\S-1-5-21-941624961-3290542821-2423505712-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1416436823&from=brd&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
SearchScopes: HKLM -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1000 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_secureddownload_15_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dde%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyEtDyCtCzzyCtD0ByE0EyE0F0FtCzy0CtN0D0Tzu0StCtCzyyCtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyD0EyCyD0EtByE0CtG0ByCtBzytGyCyByCzztG0CyEtB0FtGtByE0DyBtA0AyE0A0BzytAyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyCzyyB0D0AzzyDtG0C0CyE0FtGyEtC0F0FtG0AtC0DzytGyEyDtAzy0B0AtAyEtB0B0CtC2QtN0A0LzutB%26cr%3D1867299924%26a%3Dwny_secureddownload_15_15%26os%3DWindows 7 Home Premium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1001 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKU\S-1-5-21-941624961-3290542821-2423505712-1004 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File
Toolbar: HKLM - ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer
FF Homepage: spiegel-online.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-17] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qid9w6ga.Dagmar\user.js [2015-04-15]
FF user.js: detected! => C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer\user.js [2015-04-15]
FF Extension: Adblock Plus - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\qwtqktli.Standard-Benutzer\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-14]
FF HKU\S-1-5-21-941624961-3290542821-2423505712-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dadmar Petri\AppData\Roaming\Mozilla\Firefox\Profiles\3cdxsn3p.default\extensions\cliqz@cliqz.com
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-29]
CHR Extension: (Google Docs) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-29]
CHR Extension: (Google Drive) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-29]
CHR Extension: (YouTube) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-29]
CHR Extension: (Google Search) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-29]
CHR Extension: (Google Sheets) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-12-29]
CHR Extension: (Google Wallet) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-29]
CHR Extension: (Gmail) - C:\Users\Dadmar Petri\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService8; C:\Program Files\IObit\Advanced SystemCare 8\ASCService.exe [814880 2015-04-03] (IObit)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-11] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-11] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-03-26] (IObit)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed]
R2 OkayFreedom VPN Starter Service; C:\Program Files\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-04-15] (REALiX(tm))
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-03-17] (Avira GmbH)
S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
S1 A2DDA; \??\C:\EEK\bin\a2ddax86.sys [X]
S3 cleanhlp; \??\C:\EEK\bin\cleanhlp32.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-17 23:15 - 2015-04-17 23:15 - 00000000 _____ () C:\Users\Dadmar Petri\Desktop\Neues Textdokument.txt
2015-04-17 19:53 - 2015-04-17 19:53 - 2048196608 _____ () C:\Users\Dadmar Petri\Downloads\7601.17514.101119-1850_Update_Sp_Wave1-GRMSP1.1_DVD.iso
2015-04-17 19:40 - 2015-04-17 19:40 - 275488256 _____ () C:\Users\Dadmar Petri\Downloads\Windows_Win7SP1.7601.17514.101119-1850.AMD64CHK.Symbols.msi
2015-04-17 18:34 - 2015-04-17 18:34 - 00001291 _____ () C:\Windows\IE11_main.log
2015-04-16 12:20 - 2015-04-16 12:20 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\Avira
2015-04-16 12:14 - 2015-04-16 12:14 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\IObit
2015-04-15 19:55 - 2015-04-17 19:59 - 00001456 _____ () C:\Windows\setupact.log
2015-04-15 19:55 - 2015-04-15 19:55 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-15 19:54 - 2015-04-17 19:28 - 00002378 _____ () C:\Windows\PFRO.log
2015-04-15 19:19 - 2014-06-04 15:17 - 00031008 _____ (IObit) C:\Windows\system32\SmartDefragBootTime.exe
2015-04-15 19:12 - 2015-04-15 19:12 - 00023840 _____ (REALiX(tm)) C:\Windows\system32\Drivers\HWiNFO32.SYS
2015-04-15 19:02 - 2015-04-17 19:59 - 00000294 _____ () C:\Windows\Tasks\ASC8_PerformanceMonitor.job
2015-04-15 19:01 - 2015-04-15 19:01 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\ProductData
2015-04-15 19:00 - 2015-04-17 19:28 - 00002127 _____ () C:\Users\Public\Desktop\Advanced SystemCare 8.lnk
2015-04-15 19:00 - 2015-04-17 19:26 - 00000000 ____D () C:\Program Files\IObit
2015-04-15 19:00 - 2015-04-16 07:45 - 00000000 ____D () C:\ProgramData\ProductData
2015-04-15 19:00 - 2015-04-16 07:45 - 00000000 ____D () C:\ProgramData\IObit
2015-04-15 19:00 - 2015-04-15 19:38 - 00000000 ____D () C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-04-15 19:00 - 2015-04-15 19:18 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\IObit
2015-04-15 19:00 - 2015-04-15 19:00 - 00000000 ____D () C:\Windows\Tasks\ImCleanDisabled
2015-04-15 19:00 - 2015-04-15 19:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 8
2015-04-15 19:00 - 2015-04-15 19:00 - 00000000 ____D () C:\Program Files\Common Files\IObit
2015-04-14 20:52 - 2015-04-14 20:52 - 00008242 _____ () C:\EamClean.log
2015-04-14 20:49 - 2015-04-14 20:50 - 01795729 _____ (Medion) C:\Users\Dadmar Petri\Downloads\fwupt50n.exe
2015-04-14 20:39 - 2015-04-17 23:18 - 00000000 ____D () C:\Users\Dadmar Petri\Downloads\FRST-OlderVersion
2015-04-14 15:30 - 2015-04-14 15:30 - 00466488 _____ () C:\Windows\Minidump\041415-36629-01.dmp
2015-04-14 12:24 - 2015-04-14 12:24 - 00465824 _____ () C:\Windows\Minidump\041415-22432-01.dmp
2015-04-13 16:42 - 2015-04-13 16:42 - 00852616 _____ () C:\Users\Dadmar Petri\Desktop\SecurityCheck.exe
2015-04-12 19:21 - 2015-04-12 20:31 - 00032041 _____ () C:\Users\Dadmar Petri\Desktop\FRST.txt
2015-04-12 11:53 - 2015-04-12 11:53 - 00000000 ____D () C:\$WINDOWS.~LS
2015-04-12 11:51 - 2015-04-12 11:51 - 00000000 ____D () C:\$WINDOWS.~BT
2015-04-11 14:45 - 2015-04-11 14:45 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Avira
2015-04-11 14:41 - 2015-03-17 13:02 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-11 14:41 - 2015-03-17 13:01 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-11 14:38 - 2015-04-11 14:38 - 00001165 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-11 14:37 - 2015-04-11 15:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-11 14:37 - 2015-04-11 14:37 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-11 14:34 - 2015-04-11 14:34 - 04625104 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dadmar Petri\Desktop\avira_de_av_5529133b5619d__wsm.exe
2015-04-11 14:24 - 2015-04-11 14:51 - 00000000 ____D () C:\Program Files\Common Files\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:38 - 00000000 ____D () C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56
2015-04-11 14:24 - 2015-04-11 14:24 - 105603488 _____ () C:\Users\Dadmar Petri\Downloads\avira-antivirus.exe
2015-04-11 13:45 - 2015-04-11 13:45 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-DAGMAR-Windows-7-Home-Premium-(32-bit).dat
2015-04-11 13:45 - 2015-04-11 13:45 - 00000000 ____D () C:\RegBackup
2015-04-10 11:00 - 2015-04-10 11:00 - 00029620 _____ () C:\Users\Dadmar Petri\Downloads\Addition.txt
2015-04-10 10:59 - 2015-04-14 20:40 - 00031028 _____ () C:\Users\Dadmar Petri\Downloads\FRST.txt
2015-04-10 10:58 - 2015-04-17 23:18 - 00000000 ____D () C:\FRST
2015-04-10 10:57 - 2015-04-14 20:39 - 01135616 _____ (Farbar) C:\Users\Dadmar Petri\Downloads\FRST.exe
2015-04-09 12:05 - 2015-04-09 12:05 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(2).exe
2015-04-09 11:38 - 2015-04-09 11:38 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018(1).exe
2015-04-09 11:19 - 2015-04-09 11:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 11:18 - 2015-04-09 11:18 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Dadmar Petri\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 09:35 - 2015-04-17 19:28 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimService
2015-04-07 13:43 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\SlimCleaner Plus
2015-04-07 13:43 - 2015-04-07 13:43 - 00000000 ____D () C:\ProgramData\SlimWare Utilities Inc
2015-04-07 13:42 - 2015-04-07 17:51 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\SlimWare Utilities Inc
2015-04-01 00:59 - 2015-04-12 11:37 - 00002542 _____ () C:\Windows\diagwrn.xml
2015-04-01 00:59 - 2015-04-12 11:37 - 00001890 _____ () C:\Windows\diagerr.xml
2015-04-01 00:49 - 2015-04-01 00:49 - 00005168 _____ () C:\Users\Dadmar Petri\Downloads\hijackthis.log
2015-04-01 00:47 - 2015-04-01 00:47 - 00388608 _____ (Trend Micro Inc.) C:\Users\Dadmar Petri\Downloads\HijackThis.exe
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 23:09 - 2015-04-08 09:59 - 00000000 ____D () C:\Program Files\OkayFreedom
2015-03-31 23:09 - 2015-04-01 01:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos VPN
2015-03-31 23:09 - 2015-03-31 23:15 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Steganos
2015-03-31 23:09 - 2015-03-31 23:09 - 00000000 ____D () C:\Program Files\Common Files\Steganos
2015-03-31 21:52 - 2015-04-17 22:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-31 21:52 - 2015-04-17 19:09 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-31 21:52 - 2015-04-17 19:09 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-31 21:52 - 2015-03-31 21:52 - 01055936 _____ (Adobe) C:\Users\Dadmar Petri\Downloads\install_flashplayer17x32_mssd_aaa_aih.exe
2015-03-31 21:08 - 2015-03-31 21:08 - 00243576 _____ () C:\Users\Dadmar Petri\Downloads\Firefox Setup Stub 37.0.exe
2015-03-30 23:41 - 2015-03-31 21:45 - 00000000 ____D () C:\Program Files\Learn to Play Bridge 2
2015-03-30 23:41 - 2015-03-30 23:41 - 02062482 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb2setup.exe
2015-03-30 11:33 - 2015-03-31 21:45 - 00286720 _____ (Indigo Rose Corporation) C:\Windows\iun506.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 01865951 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dadmar Petri\Downloads\ltpb1setup.exe
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\UpdatusUser\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Hans Leo\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00001907 _____ () C:\Users\Dadmar Petri\Desktop\Learn to Play Bridge.lnk
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Learn to Play Bridge
2015-03-30 11:33 - 2015-03-30 11:33 - 00000000 ____D () C:\Program Files\Learn to Play Bridge
2015-03-30 11:24 - 2015-03-30 11:24 - 00698138 _____ () C:\Users\Dadmar Petri\Downloads\bbo_shortcut.exe
2015-03-30 00:14 - 2015-03-20 15:27 - 25808896 _____ () C:\Users\Dadmar Petri\Documents\Büro_2015_24.03.15.mdb
2015-03-26 18:08 - 2015-03-26 18:08 - 00462552 _____ () C:\Windows\Minidump\032615-20139-01.dmp
2015-03-23 16:06 - 2015-03-26 17:15 - 00000000 ____D () C:\e79d95644af82acfec248548e1a8067b
2015-03-23 16:05 - 2015-03-23 16:09 - 373578968 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\office2007sp3-kb2526086-fullfile-de-de.exe
2015-03-23 16:05 - 2015-03-23 16:07 - 08676128 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows7UpgradeAdvisorSetup.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 40888512 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\Windows-KB890830-V5.22.exe
2015-03-23 16:05 - 2015-03-23 16:06 - 39074536 _____ (Microsoft Corporation) C:\Users\Dadmar Petri\Downloads\FileFormatConverters(1).exe
2015-03-23 13:57 - 2015-03-23 13:57 - 00462936 _____ () C:\Windows\Minidump\032315-32775-01.dmp
2015-03-23 12:24 - 2015-03-23 12:24 - 00031282 _____ () C:\Users\Dadmar Petri\Documents\Die Uhus.dotx
2015-03-23 10:50 - 2015-03-23 10:50 - 00463416 _____ () C:\Windows\Minidump\032315-21309-01.dmp
2015-03-18 13:11 - 2015-03-29 20:11 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-17 23:10 - 2014-11-20 01:14 - 00001368 _____ () C:\Windows\Tasks\UTLKMTU.job
2015-04-17 21:10 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-17 21:10 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-17 21:08 - 2014-11-19 16:32 - 01281128 _____ () C:\Windows\WindowsUpdate.log
2015-04-17 20:00 - 2014-11-19 22:59 - 00000432 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-04-17 19:59 - 2014-11-20 15:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-04-17 19:59 - 2014-11-20 01:13 - 00001366 _____ () C:\Windows\Tasks\FUPWXF.job
2015-04-17 19:59 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-17 19:33 - 2014-11-19 17:52 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-17 19:19 - 2014-11-20 01:41 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Adobe
2015-04-17 10:25 - 2014-11-23 20:04 - 00000000 ____D () C:\Users\Dadmar Petri\Documents\DIE UHUS
2015-04-16 13:04 - 2014-12-30 10:50 - 00271360 _____ () C:\Users\Hans Leo\Documents\Kontakte.pst
2015-04-16 09:23 - 2014-11-19 22:12 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Microsoft Help
2015-04-16 08:30 - 2014-11-19 16:08 - 00000000 ____D () C:\Windows.old.000
2015-04-15 22:33 - 2014-11-17 11:27 - 00000000 ____D () C:\Windows.old
2015-04-15 19:11 - 2014-11-19 16:28 - 00000000 ____D () C:\Windows\Panther
2015-04-15 19:00 - 2015-01-02 13:46 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\Apple Computer
2015-04-15 19:00 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri
2015-04-14 20:50 - 2014-03-03 23:41 - 00000000 ____D () C:\Medion
2015-04-14 20:12 - 2014-01-31 13:38 - 00000000 ____D () C:\temp
2015-04-14 20:12 - 2014-01-18 21:01 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\nationzoom
2015-04-14 15:30 - 2015-01-03 16:50 - 385888152 _____ () C:\Windows\MEMORY.DMP
2015-04-14 15:30 - 2015-01-03 16:50 - 00000000 ____D () C:\Windows\Minidump
2015-04-12 19:33 - 2012-01-31 20:40 - 00000236 _____ () C:\Users\Dadmar Petri\Desktop\Bridge Base Online.url
2015-04-12 12:03 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\ProgramData\Avira
2015-04-11 14:41 - 2014-11-20 01:18 - 00000000 ____D () C:\Program Files\Avira
2015-04-11 12:37 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-11 12:32 - 2015-01-03 13:51 - 00000000 ____D () C:\AdwCleaner
2015-04-10 10:42 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2015-04-08 09:59 - 2015-01-04 23:59 - 00000000 ____D () C:\ProgramData\Netzmanager
2015-04-08 09:59 - 2014-11-20 01:42 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-08 09:59 - 2014-11-20 00:09 - 00000000 ____D () C:\Users\Hans Leo
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-08 09:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-08 09:58 - 2014-11-21 11:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Mozilla
2015-04-08 09:58 - 2014-11-20 01:10 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-08 09:58 - 2014-11-20 00:52 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\Mozilla
2015-04-08 09:57 - 2014-01-18 12:16 - 00000000 __RHD () C:\MSOCache
2015-04-01 19:22 - 2014-11-20 13:46 - 00065464 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-01 11:22 - 2014-11-20 00:53 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-01 00:54 - 2014-11-29 14:48 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Roaming\dlg
2015-04-01 00:48 - 2014-11-19 18:30 - 00000000 ____D () C:\Users\Dadmar Petri\AppData\Local\VirtualStore
2015-03-31 22:11 - 2009-07-14 06:33 - 00303112 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-31 20:37 - 2014-11-19 23:59 - 00065464 _____ () C:\Users\Dadmar Petri\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-31 19:18 - 2014-11-19 22:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-31 19:17 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-03-29 20:54 - 2015-01-12 20:57 - 00000000 ____D () C:\Windows\pss
2015-03-29 20:11 - 2015-01-02 13:41 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-29 09:03 - 2015-01-02 13:42 - 00000000 ____D () C:\Program Files\Bonjour
2015-03-28 19:37 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-03-26 17:15 - 2015-01-03 16:48 - 00000000 ____D () C:\NVIDIA
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-03-26 17:15 - 2014-11-30 21:07 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-26 17:15 - 2014-11-28 23:40 - 00000000 ____D () C:\Program Files\Microsoft Windows 7 Upgrade Advisor

==================== Files in the root of some directories =======

2014-12-20 10:45 - 2014-12-20 10:45 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Dadmar Petri\AppData\Local\Temp\ASCSetup_3405267.exe
C:\Users\Dadmar Petri\AppData\Local\Temp\avgnt.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

Hallo,

ich versuche immer noch den Ordner Windows old zu löschen. Es kommt immer die Meldung: "Sie benötigen Administrationsrechte, wiederholen sie den Vorgang." Gelöscht wird aber nicht. Vor dem Ordner ist ein Sicherheitsschloss. Ich habe versucht, übe die Zugriffsrechte die Berechtigung zu ändern, das funktioniert aber nicht. Muss nicht auch der Ordner Windos old000 gelöscht werden. Hier fehlt nämlich das Sicherheitsschloss vor dem Ordner. Bisher habe ich micht jedoch nicht getraut, diesen Ordner zu löschen. Das Windows Update funktioniert auch nicht. Ich habe versucht, die Service Pack manuelle herunterzuladen. Das klappt auch. Installieren kann man es jedoch nicht.
Gruß daggimaus

schrauber 18.04.2015 22:53

Datenträgerbereinigung von WIndows sollte den löschen können. Nach dem Fix öffnet sich automatisch ein Fixlog, das brauche ich bitte.

daggimaus 19.04.2015 08:57

Hallo,
die Defragmentierung habe ich gemacht. Der Windows old-Ordner ist aber immer noch vorhanden. Lediglich der Windows old 000 ist gelöscht. Wie schon berichtet, ist vor dem Windows old Ordner ein gelbes Schloss. Wenn ich mit Administrationsrechten lösche, verschwindet er auch nicht. Ich habe jetzt die Faxen dick. Vielen Dank für Ihre Bemühungen. Ich spiele Windows 7 neu auf.

Gruß
daggimaus

schrauber 19.04.2015 16:12

Dann wird der Ordner aber wieder da sein, der kommt nämlich durchs Neuaufsetzen, wenn das nicht richtig gemacht wurde :)

daggimaus 19.04.2015 18:44

wie muss ich denn das neue Windows aufspielen??

Vielen Dank für die Antwort.

daggimaus

schrauber 20.04.2015 13:24

Nicht auf Installieren klicken wenn Du von Scheibe bootest, sondern auf Erweitert, dann kannste die kompletten Partitionen löschen und formatieren. Dann WIndows installieren.

So entsteht dann auch kein Ordner Windows.old :)

daggimaus 02.05.2015 08:50

Guten Tag,

folgende Meldung erscheint, wenn ich den Computer hochfahre:
C:\Program Files\Common Files\microsoft shared\ink\tiptsdf.dll ist entweder nicht für die Ausführung unter Windows vorgesehen oder enthält einen Fehler. Installieren Sie das Programm mit den Originalinstallationsmedien erneut, oder wenden Sie sich an den Systemadministrator oder Softwarelieferanten, um Unterstützung zu erhalten.
Diese Meldung erschschien aber auch schon vorher. Da ich nicht weiß, um welches Programm es sich handelt, kann ich es nicht aufrufen. Bitte helfen Sie mir noch mal.


Ich habe inzwischen die Festplatte formatiert und Windows 7 neu installiert. Seitdem läuft alles rund. Es wurden 2 Partitionen mit fast identischer Größe erstellt. Ein Recovery wurde jedoch nicht erstellt. Jetzt habe ich auf C: das Betriebssystem und D: ist leer. Ich muss immer wenn ich boote bestätigen, dass ich Windows 7 laden möchte. Das ist aber nicht dramatisch. Vielleicht wäre das aber auch zu ändern.

schrauber 02.05.2015 14:10

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


daggimaus 02.05.2015 19:44


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-05-2015
Ran by Dagmar (administrator) on DAGMAR-PC on 02-05-2015 20:31:04
Running from C:\Users\Dagmar\Downloads
Loaded Profiles: Dagmar (Available profiles: Dagmar & Hans Leo)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Hewlett-Packard Company) C:\Program Files\HP\Common\HPSupportSolutionsFrameworkService.exe
() C:\Users\Dagmar\AppData\Roaming\Internet-Controller\internet-controllerservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
() C:\Users\Dagmar\AppData\Roaming\Internet-Controller\internet-controller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
(Microsoft Corporation) C:\Windows\ehome\mcGlidHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [130048 2015-04-10] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [726320 2015-03-24] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\S-1-5-21-1957182844-2440048667-671278128-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mystartsearch.com/?type=hp&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&q={searchTerms}
HKU\S-1-5-21-1957182844-2440048667-671278128-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.mystartsearch.com/web/?type=ds&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&q={searchTerms}
HKU\S-1-5-21-1957182844-2440048667-671278128-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.spiegel.de/
HKU\S-1-5-21-1957182844-2440048667-671278128-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mystartsearch.com/?type=hp&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126
HKU\S-1-5-21-1957182844-2440048667-671278128-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.mystartsearch.com/web/?type=ds&ts=1429692222&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1957182844-2440048667-671278128-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&ts=1429692291&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1957182844-2440048667-671278128-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&ts=1429692291&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1957182844-2440048667-671278128-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&ts=1429692291&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1957182844-2440048667-671278128-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&ts=1429692291&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1957182844-2440048667-671278128-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126&ts=1429692291&type=default&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Roaming Rate -> {8d0ea870-e492-4825-a734-a0ed7d65882a} ->  No File
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll [2012-02-10] (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll [2012-02-10] (Microsoft Corporation.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1429649850&from=air&uid=WDCXWD10EURX-73FH1Y0_WD-WCC1U498012680126

FireFox:
========
FF ProfilePath: C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: luckysearches
FF SelectedSearchEngine: mystartsearch
FF Homepage: hxxp://www.spiegel.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-05-01] ()
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\user.js [2015-04-22]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\searchplugins\google-images.xml [2015-04-28]
FF SearchPlugin: C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\searchplugins\google-maps.xml [2015-04-28]
FF SearchPlugin: C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\searchplugins\luckysearches.xml [2015-04-22]
FF Extension: Avira Browser Safety - C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\Extensions\abs@avira.com [2015-04-28]
FF Extension: Roaming Rate - C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\Extensions\{7c23685a-72f8-4f91-9ef8-a1f1230ea136}.xpi [2015-04-21]
FF Extension: Adblock Plus - C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-22]
FF HKU\S-1-5-21-1957182844-2440048667-671278128-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Dagmar\AppData\Roaming\Mozilla\Firefox\Profiles\N649Xmi7.default\extensions\cliqz@cliqz.com

Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [815920 2015-03-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [434424 2015-03-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [434424 2015-03-24] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1004280 2015-03-24] (Avira Operations GmbH & Co. KG)
S2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [205104 2015-04-10] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [918160 2015-03-28] (NVIDIA Corporation)
R2 HPSLPSVC; C:\Users\Dagmar\AppData\Local\Temp\7zS777E\hpslpsvc32.dll [701288 2013-07-19] (Hewlett-Packard Co.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)
R2 internetControllerService; C:\Users\Dagmar\AppData\Roaming\Internet-Controller\internet-controllerservice.exe [187168 2014-11-27] ()
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20696720 2015-03-28] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 22134214; "C:\Windows\system32\rundll32.exe" "c:\Program Files\Super Optimizer\SupOptStats.dll",ENT

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-03-24] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-24] (Avira Operations GmbH & Co. KG)
R1 ncdevice; C:\Windows\System32\DRIVERS\ncdevice.sys [35616 2014-05-22] (NT Kernel Resources)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [32912 2014-11-22] (NVIDIA Corporation)
R3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1488096 2009-08-27] (NXP Semiconductors Germany GmbH)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-03-24] (Avira GmbH)
S3 cpuz134; \??\C:\Users\Dagmar\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-02 20:28 - 2015-05-02 20:30 - 00045813 _____ () C:\Users\Dagmar\Downloads\Addition.txt
2015-05-02 20:26 - 2015-05-02 20:31 - 00015317 _____ () C:\Users\Dagmar\Downloads\FRST.txt
2015-05-02 20:26 - 2015-05-02 20:31 - 00000000 ____D () C:\FRST
2015-05-02 20:25 - 2015-05-02 20:25 - 01140736 _____ (Farbar) C:\Users\Dagmar\Downloads\FRST.exe
2015-05-02 10:11 - 2015-05-02 10:11 - 00000000 ____D () C:\Users\Dagmar\Documents\Uhus
2015-05-01 19:55 - 2015-05-01 19:55 - 01124544 _____ (Adobe Systems Incorporated) C:\Users\Dagmar\Downloads\flashplayer17_ha_install(2).exe
2015-05-01 19:45 - 2015-05-01 19:49 - 00000000 ____D () C:\Bridge Base Online
2015-05-01 19:44 - 2015-05-01 19:44 - 03826470 _____ (Indigo Rose Corporation hxxp://www.indigorose.com) C:\Users\Dagmar\Downloads\bbo_setup.exe
2015-05-01 19:42 - 2015-05-01 19:42 - 01124544 _____ (Adobe Systems Incorporated) C:\Users\Dagmar\Downloads\flashplayer17_ha_install(1).exe
2015-05-01 19:32 - 2015-05-01 19:32 - 02256152 _____ (Microsoft Corporation) C:\Users\Dagmar\Downloads\WcPlugin.exe
2015-05-01 19:27 - 2015-05-01 19:27 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-05-01 19:27 - 2015-05-01 19:27 - 00002017 _____ () C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-05-01 19:27 - 2015-05-01 19:27 - 00000000 ____D () C:\Program Files\Adobe
2015-05-01 19:25 - 2015-05-01 19:25 - 01124072 _____ (Adobe Systems Incorporated) C:\Users\Dagmar\Downloads\readerdc_de_ha_install.exe
2015-05-01 19:17 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-01 19:17 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-01 19:17 - 2015-03-04 06:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-01 19:17 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-04-30 01:35 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-04-29 22:57 - 2015-04-29 22:57 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2015-04-29 22:57 - 2015-04-29 22:57 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2015-04-29 19:24 - 2015-04-30 13:03 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-29 19:24 - 2015-04-29 22:57 - 00002539 _____ () C:\Users\Dagmar\Desktop\Outlook 2013.lnk
2015-04-29 19:24 - 2015-04-29 19:24 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-04-29 19:23 - 2015-04-29 19:23 - 00000000 ____D () C:\Windows\PCHEALTH
2015-04-29 19:23 - 2015-04-29 19:23 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2015-04-29 19:20 - 2015-05-01 19:33 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-04-29 19:20 - 2015-04-30 13:03 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-29 19:20 - 2015-04-29 19:20 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Microsoft Help
2015-04-29 19:20 - 2015-04-29 19:20 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-04-29 19:19 - 2015-04-29 19:19 - 00000000 __RHD () C:\MSOCache
2015-04-29 19:07 - 2015-04-29 19:11 - 653446012 _____ () C:\Users\Dagmar\Downloads\MSO2013PPx86.exe
2015-04-29 10:05 - 2015-04-29 10:05 - 02338824 _____ () C:\Users\Dagmar\Downloads\hppiw(2).exe
2015-04-29 10:04 - 2015-04-29 10:04 - 00000327 _____ () C:\Users\Dagmar\Desktop\HP Druckerdiagnosetools.url
2015-04-29 08:21 - 2015-04-29 08:21 - 00500798 _____ () C:\Users\Dagmar\Documents\görrlitz.xps
2015-04-28 20:55 - 2015-04-28 20:55 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\Avira
2015-04-28 20:26 - 2015-04-28 20:26 - 02338824 _____ () C:\Users\Dagmar\Downloads\hppiw(1).exe
2015-04-28 20:16 - 2015-04-28 20:16 - 00000000 ____D () C:\Windows\Hewlett-Packard
2015-04-28 19:36 - 2015-04-28 19:36 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Cliqz
2015-04-28 19:36 - 2011-05-13 12:16 - 00493056 _____ ( datenhaus GmbH) C:\Windows\system32\dhRichClient3.dll
2015-04-28 19:36 - 2011-03-25 20:42 - 00338432 _____ () C:\Windows\system32\sqlite36_engine.dll
2015-04-28 19:32 - 2015-04-28 19:32 - 01203488 _____ () C:\Users\Dagmar\Downloads\Firefox - CHIP-Installer(1).exe
2015-04-28 19:19 - 2015-04-30 13:03 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-28 19:19 - 2015-04-28 20:20 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-28 19:19 - 2015-04-28 19:37 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-28 19:19 - 2015-04-28 19:37 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-28 19:17 - 2015-04-28 19:17 - 01203488 _____ () C:\Users\Dagmar\Downloads\Firefox - CHIP-Installer.exe
2015-04-28 19:02 - 2015-04-28 19:02 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Avira
2015-04-28 19:00 - 2015-03-24 14:59 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-28 19:00 - 2015-03-24 14:59 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-28 19:00 - 2015-03-24 14:59 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-28 19:00 - 2015-03-24 14:59 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-28 18:59 - 2015-04-28 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-28 18:59 - 2015-04-28 19:00 - 00000000 ____D () C:\ProgramData\Avira
2015-04-28 18:59 - 2015-04-28 18:59 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-25 20:57 - 2015-04-25 20:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2015-04-25 06:50 - 2015-04-25 06:51 - 51327704 _____ () C:\Users\Hans Leo\Downloads\DJ1050_J410_1313-1.exe
2015-04-25 06:21 - 2015-04-25 06:21 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\Hewlett-Packard
2015-04-25 06:08 - 2015-04-25 06:08 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\Macromedia
2015-04-24 22:45 - 2015-04-24 22:54 - 00000000 ____D () C:\Program Files\DriverTurbo
2015-04-24 22:33 - 2015-04-25 06:28 - 00001962 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2015-04-24 22:14 - 2015-04-24 22:14 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\AviraSpeedup
2015-04-24 22:02 - 2015-04-24 22:02 - 02338824 _____ () C:\Users\Dagmar\Downloads\hppiw.exe
2015-04-24 21:21 - 2015-04-24 21:21 - 05197824 _____ () C:\Users\Dagmar\Downloads\HPSupportSolutionsFramework-11.51.0049 (1).msi
2015-04-23 09:25 - 2015-04-23 09:25 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\NVIDIA Corporation
2015-04-23 09:24 - 2015-04-23 09:24 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\NVIDIA
2015-04-23 00:37 - 2015-04-23 00:37 - 00000000 ____D () C:\Program Files\Microsoft ASP.NET
2015-04-23 00:30 - 2015-04-23 00:30 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Microsoft Games
2015-04-23 00:26 - 2015-05-02 11:13 - 00005979 _____ () C:\Windows\setupact.log
2015-04-23 00:26 - 2015-04-23 00:26 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-23 00:25 - 2015-05-01 21:48 - 00295952 _____ () C:\Windows\PFRO.log
2015-04-23 00:19 - 2015-04-23 00:20 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\NVIDIA Corporation
2015-04-23 00:18 - 2015-04-23 00:20 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\NVIDIA
2015-04-23 00:17 - 2015-04-23 00:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-04-23 00:17 - 2015-04-23 00:17 - 00000000 ____D () C:\Program Files\AGEIA Technologies
2015-04-23 00:17 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll
2015-04-23 00:17 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge.dll
2015-04-23 00:17 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-04-23 00:17 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-04-23 00:17 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-04-23 00:16 - 2015-02-03 18:18 - 04229086 _____ () C:\Windows\system32\nvcoproc.bin
2015-04-23 00:13 - 2015-02-04 05:35 - 24199824 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 15294096 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 11272048 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 11209376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 10702664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-04-23 00:13 - 2015-02-04 05:35 - 03987784 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 01060680 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234144.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 00911504 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234144.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 00908432 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll
2015-04-23 00:13 - 2015-02-04 05:35 - 00870032 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll
2015-04-23 00:13 - 2014-11-22 12:46 - 00032912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2015-04-23 00:13 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2015-04-23 00:11 - 2015-04-23 00:11 - 00000000 ____D () C:\NVIDIA
2015-04-23 00:07 - 2015-04-23 00:11 - 227056768 _____ (NVIDIA Corporation) C:\Users\Dagmar\Downloads\341.44-notebook-win8-win7-32bit-international-whql.exe
2015-04-22 23:54 - 2015-04-22 23:54 - 04636584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dagmar\Downloads\avira_de_av_5536aa3015bd3__ws (1).exe
2015-04-22 23:48 - 2015-05-01 19:27 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-04-22 23:47 - 2015-05-01 19:27 - 00000000 ____D () C:\ProgramData\Adobe
2015-04-22 23:46 - 2015-04-22 23:47 - 76313280 _____ (Adobe Systems Incorporated) C:\Users\Dagmar\Downloads\AdbeRdr11010_de_DE.exe
2015-04-22 23:29 - 2015-04-22 23:32 - 01124544 _____ (Adobe Systems Incorporated) C:\Users\Dagmar\Downloads\flashplayer17ax_ra_install.exe
2015-04-22 23:16 - 2015-04-22 23:16 - 00000000 ____D () C:\Program Files\PlayReady
2015-04-22 22:41 - 2015-04-22 22:47 - 00002052 _____ () C:\Windows\epplauncher.mif
2015-04-22 22:05 - 2015-01-31 05:33 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-04-22 22:05 - 2015-01-31 05:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-04-22 22:05 - 2015-01-31 02:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-04-22 22:05 - 2014-12-11 19:47 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-04-22 21:59 - 2015-04-22 21:59 - 00000000 __SHD () C:\Users\Hans Leo\AppData\Local\EmieUserList
2015-04-22 21:59 - 2015-04-22 21:59 - 00000000 __SHD () C:\Users\Hans Leo\AppData\Local\EmieSiteList
2015-04-22 21:59 - 2015-04-22 21:59 - 00000000 __SHD () C:\Users\Hans Leo\AppData\Local\EmieBrowserModeList
2015-04-22 20:54 - 2015-04-22 20:54 - 00613255 _____ (CMI Limited) C:\Users\Dagmar\AppData\Local\nsn7918.tmp
2015-04-22 20:51 - 2015-04-22 20:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\UnicoBrowser
2015-04-22 20:50 - 2015-04-22 20:52 - 00008363 _____ () C:\claraInstaller.txt
2015-04-22 20:46 - 2015-04-22 20:46 - 00000000 ____D () C:\Users\Dagmar\SupTab
2015-04-22 20:44 - 2015-04-22 21:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\MyDailyVideo
2015-04-22 20:40 - 2015-04-22 20:40 - 00613255 _____ (CMI Limited) C:\Users\Dagmar\AppData\Local\nsiB3F.tmp
2015-04-22 20:40 - 2015-04-22 20:40 - 00000000 __SHD () C:\Users\Dagmar\AppData\Roaming\AnyProtectEx
2015-04-22 20:38 - 2015-04-22 21:52 - 00000000 ____D () C:\ProgramData\NetEngine
2015-04-22 20:37 - 2015-04-22 21:39 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Opera Software
2015-04-22 20:37 - 2015-04-22 21:39 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Opera Software
2015-04-22 20:37 - 2015-04-22 21:39 - 00000000 ____D () C:\Program Files\Opera
2015-04-22 20:37 - 2015-04-22 20:40 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\ZombieNews
2015-04-22 20:36 - 2015-04-22 21:52 - 00000000 ____D () C:\Program Files\shopperz
2015-04-22 20:34 - 2015-04-22 20:35 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\BrowserHelper
2015-04-22 20:33 - 2015-04-22 21:52 - 00000000 ____D () C:\ProgramData\ZombieNews
2015-04-22 20:33 - 2015-04-22 21:52 - 00000000 ____D () C:\ProgramData\rSKCvuySwHh
2015-04-22 20:33 - 2015-04-22 21:52 - 00000000 ____D () C:\ProgramData\{8e6e07cd-f2e5-e03e-8e6e-e07cdf2e1f37}
2015-04-22 20:33 - 2015-04-22 20:33 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Crossbrowse
2015-04-22 20:33 - 2015-04-22 20:33 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\CrashRpt
2015-04-22 20:29 - 2015-04-22 21:44 - 00000000 _____ () C:\momotor.txt
2015-04-22 20:29 - 2015-04-22 20:29 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\globalUpdate
2015-04-22 20:28 - 2015-04-22 21:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\MailUpdate
2015-04-22 20:28 - 2015-04-22 21:52 - 00000000 ____D () C:\ProgramData\MailUpdate
2015-04-22 20:19 - 2015-04-22 21:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\09E50158-1429733966-11DE-99D6-22C6518679A9
2015-04-22 20:19 - 2015-04-22 21:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\09E50158-1429733956-11DE-99D6-22C6518679A9
2015-04-22 20:15 - 2015-04-22 21:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\09E50158-1429726517-11DE-99D6-22C6518679A9
2015-04-22 19:22 - 2009-08-27 16:55 - 01488096 _____ (NXP Semiconductors Germany GmbH) C:\Windows\system32\Drivers\NxpCap.sys
2015-04-22 19:22 - 2009-08-27 16:55 - 00105056 _____ (NXP Semiconductors Germany GmbH) C:\Windows\system32\NXPMV32.dll
2015-04-22 19:22 - 2009-08-27 16:55 - 00009824 _____ () C:\Windows\system32\716xCoInstaller.dll
2015-04-22 19:22 - 2009-08-27 16:55 - 00000495 _____ () C:\Windows\11317231_000416BE_1.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000495 _____ () C:\Windows\11317231_000116BE_11.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000495 _____ () C:\Windows\11317231_000116BE_1.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000464 _____ () C:\Windows\11317231_001016BE_1.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000464 _____ () C:\Windows\11317231_000216BE_11.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000464 _____ () C:\Windows\11317231_000216BE_1.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000458 _____ () C:\Windows\11317231_000716BE_8a.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000442 _____ () C:\Windows\11317231_000616BE_61.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000442 _____ () C:\Windows\11317231_000616BE_1.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000442 _____ () C:\Windows\11317231_000416BE_11.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000405 _____ () C:\Windows\11317231_001116BE_ca.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000405 _____ () C:\Windows\11317231_000816BE_ca.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000380 _____ () C:\Windows\11317231_000616BE_11.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000380 _____ () C:\Windows\11317231_000516BE_61.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000380 _____ () C:\Windows\11317231_000516BE_11.bin
2015-04-22 19:22 - 2009-08-27 16:55 - 00000380 _____ () C:\Windows\11317231_000516BE_1.bin
2015-04-22 19:20 - 2009-08-27 16:55 - 00485920 _____ (NVIDIA Corporation) C:\Windows\system32\nvuninst.exe
2015-04-22 19:20 - 2009-08-27 16:55 - 00151552 _____ (NVIDIA Corporation) C:\Windows\system32\NVCOSMU.DLL
2015-04-22 19:20 - 2009-08-27 16:55 - 00017920 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvsmu.sys
2015-04-22 19:20 - 2009-08-27 16:55 - 00001383 _____ () C:\Windows\system32\nvsmu.nvu
2015-04-22 19:03 - 2014-09-05 03:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-04-22 18:04 - 2015-04-22 18:04 - 00985600 _____ () C:\Users\Dagmar\Downloads\MicrosoftFixit50123(1).msi
2015-04-22 11:35 - 2015-04-22 11:35 - 00000000 ____D () C:\Users\Hans Leo\AppData\Roaming\Adobe
2015-04-22 11:05 - 2015-04-22 11:05 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Macromedia
2015-04-22 11:05 - 2015-04-22 11:05 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Macromedia
2015-04-22 11:04 - 2015-05-02 20:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-22 11:04 - 2015-05-01 19:56 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-22 11:04 - 2015-05-01 19:56 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-22 11:04 - 2015-05-01 19:56 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Adobe
2015-04-22 11:04 - 2015-04-22 11:04 - 00000000 ____D () C:\Windows\system32\Macromed
2015-04-22 11:03 - 2015-04-22 11:04 - 01124544 _____ (Adobe Systems Incorporated) C:\Users\Dagmar\Downloads\flashplayer17_ha_install.exe
2015-04-22 10:45 - 2015-04-22 10:45 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\BrowserWeb
2015-04-22 10:44 - 2015-05-02 08:37 - 00000270 _____ () C:\Windows\Tasks\DriverScanner.job
2015-04-22 10:43 - 2015-05-02 08:37 - 00000330 _____ () C:\Windows\Tasks\dsmonitor.job
2015-04-22 10:43 - 2015-04-28 19:11 - 00000000 ____D () C:\ProgramData\{365816b0-8340-8b06-3658-816b08345ac2}
2015-04-22 10:25 - 2015-04-22 10:25 - 00000057 _____ () C:\ProgramData\Ament.ini
2015-04-22 10:21 - 2015-04-22 10:21 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Hewlett-Packard
2015-04-22 10:21 - 2015-04-22 10:21 - 00000000 ____D () C:\Program Files\Hewlett-Packard
2015-04-22 10:20 - 2015-04-22 10:20 - 05197824 _____ () C:\Users\Dagmar\Downloads\HPSupportSolutionsFramework-11.51.0049.msi
2015-04-22 10:10 - 2015-04-22 10:12 - 00000144 _____ () C:\Windows\Reimage.ini
2015-04-22 10:10 - 2015-04-22 10:11 - 00000072 _____ () C:\Windows\efix.ini
2015-04-22 09:49 - 2015-04-22 09:49 - 00000000 ____D () C:\Program Files\Company Name
2015-04-22 09:42 - 2015-04-22 22:31 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Internet-Controller
2015-04-22 09:40 - 2015-04-22 09:52 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Company Name
2015-04-22 09:31 - 2013-10-02 02:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2015-04-22 09:31 - 2013-10-02 01:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2015-04-22 09:31 - 2012-08-23 16:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-04-22 09:31 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2015-04-22 09:30 - 2013-10-02 02:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2015-04-22 09:30 - 2013-10-02 02:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2015-04-22 09:30 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2015-04-22 09:30 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2015-04-22 09:30 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-04-22 09:30 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-04-22 09:30 - 2013-10-02 00:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2015-04-22 09:30 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-04-22 09:29 - 2015-05-02 11:07 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Skype
2015-04-22 09:29 - 2015-04-22 09:29 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-22 09:29 - 2015-04-22 09:29 - 00000000 ___RD () C:\Program Files\Skype
2015-04-22 09:29 - 2015-04-22 09:29 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Skype
2015-04-22 09:29 - 2015-04-22 09:29 - 00000000 ____D () C:\ProgramData\Skype
2015-04-22 09:29 - 2015-04-22 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-22 09:29 - 2015-04-22 09:29 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-04-22 09:02 - 2015-04-21 23:12 - 00000000 ____D () C:\Windows\Panther
2015-04-22 09:01 - 2015-04-22 09:01 - 00000000 ____D () C:\Hotfix
2015-04-22 09:01 - 2011-02-16 04:11 - 00000028 ___RH () C:\Windows\version
2015-04-22 09:01 - 2011-02-16 04:11 - 00000013 ____R () C:\Windows\csup.txt
2015-04-22 08:59 - 2015-04-22 09:32 - 00000000 ____D () C:\Windows\system32\Drivers\de-DE
2015-04-22 08:59 - 2015-04-22 08:59 - 00000000 ____D () C:\Windows\system32\XPSViewer
2015-04-22 08:59 - 2015-04-22 08:59 - 00000000 ____D () C:\Windows\system32\de
2015-04-22 08:59 - 2015-04-22 08:59 - 00000000 ____D () C:\Windows\system32\0407
2015-04-22 08:59 - 2015-04-22 08:59 - 00000000 ____D () C:\Windows\de-DE
2015-04-22 08:22 - 2015-03-14 05:04 - 01372160 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-04-22 08:22 - 2015-03-14 05:04 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-04-22 08:22 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-04-22 08:09 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-04-22 07:52 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-22 07:52 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2015-04-22 07:52 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2015-04-22 07:52 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2015-04-22 07:52 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2015-04-22 07:52 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2015-04-22 07:52 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-04-22 07:52 - 2012-02-11 07:37 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2015-04-22 07:52 - 2011-03-11 07:39 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2015-04-22 07:52 - 2011-03-11 07:39 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2015-04-22 07:52 - 2011-03-11 07:38 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2015-04-22 07:52 - 2011-03-11 07:38 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2015-04-22 07:52 - 2011-03-11 07:38 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2015-04-22 07:52 - 2011-03-11 07:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2015-04-22 07:52 - 2011-03-11 07:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2015-04-22 07:52 - 2011-03-11 06:01 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2015-04-22 07:52 - 2011-02-25 07:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-04-22 07:51 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-04-22 07:38 - 2015-04-22 07:38 - 00000000 __SHD () C:\Users\Dagmar\AppData\Local\EmieUserList
2015-04-22 07:38 - 2015-04-22 07:38 - 00000000 __SHD () C:\Users\Dagmar\AppData\Local\EmieSiteList
2015-04-22 07:38 - 2015-04-22 07:38 - 00000000 __SHD () C:\Users\Dagmar\AppData\Local\EmieBrowserModeList
2015-04-22 07:31 - 2015-04-22 21:52 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-22 07:22 - 2015-01-09 01:44 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-04-22 07:03 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-04-22 06:57 - 2015-04-29 23:14 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-04-22 06:54 - 2015-04-22 23:49 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Adobe
2015-04-22 05:27 - 2015-04-22 05:27 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-22 05:27 - 2015-04-22 05:27 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-22 03:34 - 2012-07-26 05:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2015-04-22 03:34 - 2012-07-26 05:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2015-04-22 03:34 - 2012-07-26 05:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2015-04-22 03:34 - 2012-07-26 05:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2015-04-22 03:34 - 2012-07-26 05:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2015-04-22 03:34 - 2012-07-26 04:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2015-04-22 03:34 - 2012-07-26 04:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2015-04-22 03:34 - 2012-06-02 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-04-22 03:32 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2015-04-22 03:32 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-04-22 03:32 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2015-04-22 03:32 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2015-04-22 01:21 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-04-22 00:19 - 2015-04-22 00:21 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-22 00:19 - 2015-04-01 11:22 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-22 00:05 - 2015-04-23 00:18 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-22 00:05 - 2015-02-04 04:06 - 04388040 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-04-22 00:05 - 2015-02-04 04:06 - 03060936 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll
2015-04-22 00:05 - 2015-02-04 04:05 - 02553032 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-04-22 00:05 - 2015-02-04 04:05 - 00670536 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-04-22 00:05 - 2015-02-04 04:05 - 00374928 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-04-22 00:05 - 2015-02-04 04:05 - 00061584 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-04-22 00:04 - 2015-02-04 05:35 - 00060744 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-04-22 00:03 - 2015-04-23 00:19 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-04-22 00:03 - 2015-04-23 00:17 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-21 23:50 - 2015-04-21 23:50 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\WindowsUpdate
2015-04-21 23:47 - 2015-02-24 04:23 - 00246920 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-04-21 23:47 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-04-21 23:47 - 2012-02-17 06:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-04-21 23:12 - 2015-04-28 22:22 - 00000000 __SHD () C:\Recovery
2015-04-21 23:12 - 2015-04-28 12:26 - 00000000 ____D () C:\Users\Dagmar
2015-04-21 23:12 - 2015-04-22 10:43 - 00001625 _____ () C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-21 23:12 - 2015-04-21 23:12 - 00000020 ___SH () C:\Users\Dagmar\ntuser.ini
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\Startmenü
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\Startmenü
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\Netzwerkumgebung
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\Druckumgebung
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\Documents\Eigene Musik
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\Documents\Eigene Bilder
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Users\Dagmar\AppData\Local\Verlauf
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\Programme
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\ProgramData\Startmenü
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 _SHDL () C:\ProgramData\Dokumente
2015-04-21 23:12 - 2015-04-21 23:12 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\VirtualStore
2015-04-21 23:12 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-21 23:12 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-21 23:11 - 2015-05-02 20:28 - 02013606 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 23:06 - 2015-04-21 23:06 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-04-21 23:06 - 2015-04-21 23:06 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-04-21 22:59 - 2015-04-21 22:59 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-21 22:59 - 2015-04-21 22:59 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-21 22:59 - 2015-04-21 22:59 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-04-21 22:59 - 2015-04-21 22:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-21 22:59 - 2015-04-21 22:59 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-04-21 22:59 - 2015-04-21 22:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-04-21 22:59 - 2015-04-21 22:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-04-21 22:59 - 2015-04-21 22:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-21 22:58 - 2015-04-22 10:13 - 00000000 ____D () C:\ProgramData\92e92012-2ebd-4b2d-83ca-70807d1e20fa
2015-04-21 22:58 - 2015-04-22 10:13 - 00000000 ____D () C:\Program Files\Common Files\92e92012-2ebd-4b2d-83ca-70807d1e20fa
2015-04-21 22:57 - 2015-04-21 22:58 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\Mozilla
2015-04-21 22:57 - 2015-04-21 22:57 - 00000000 ____D () C:\ProgramData\Mozilla
2015-04-21 22:56 - 2015-04-21 22:56 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-04-21 22:56 - 2015-04-21 22:56 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-04-21 22:54 - 2015-04-21 22:54 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2015-04-21 22:53 - 2015-04-21 22:53 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2015-04-21 22:51 - 2015-04-21 22:51 - 00000000 ____D () C:\ProgramData\CanonCP
2015-04-21 22:48 - 2015-04-21 22:48 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-04-21 22:48 - 2015-04-21 22:48 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-04-21 22:47 - 2015-04-21 22:47 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2015-04-21 22:41 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-04-21 22:41 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-04-21 22:41 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-04-21 22:41 - 2013-07-03 06:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2015-04-21 22:41 - 2013-07-03 05:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2015-04-21 22:41 - 2013-07-03 05:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2015-04-21 22:40 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-04-21 22:40 - 2013-02-12 05:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2015-04-21 22:38 - 2015-04-21 22:38 - 01218568 _____ (CANON INC.) C:\Users\Dagmar\Downloads\cp710w7.exe
2015-04-21 22:38 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-21 22:38 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-21 22:38 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-21 22:38 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-21 22:38 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-21 22:38 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-21 22:38 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-21 22:38 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-21 22:38 - 2015-01-28 01:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-04-21 22:37 - 2015-04-21 22:37 - 00001736 _____ () C:\Users\Public\Desktop\Anleitung zum CP-Drucker.lnk
2015-04-21 22:37 - 2015-04-21 22:37 - 00000000 ____D () C:\Program Files\Common Files\Canon
2015-04-21 22:37 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2015-04-21 22:37 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2015-04-21 22:36 - 2015-04-21 22:36 - 00001293 _____ () C:\Users\Public\Desktop\Easy-PhotoPrint.lnk
2015-04-21 22:36 - 2015-04-21 22:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon PhotoRecord
2015-04-21 22:36 - 2015-04-21 22:36 - 00000000 _____ () C:\Windows\OpPrintServer.INI
2015-04-21 22:36 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-04-21 22:35 - 2015-04-21 22:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2015-04-21 22:35 - 2015-04-21 22:37 - 00000000 ____D () C:\Program Files\InstallShield Installation Information
2015-04-21 22:35 - 2015-04-21 22:37 - 00000000 ____D () C:\Program Files\Canon
2015-04-21 22:34 - 2015-04-21 22:34 - 00000010 _____ () C:\Windows\WININIT.INI
2015-04-21 22:34 - 2015-04-21 22:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon SELPHY CP710
2015-04-21 22:34 - 2015-04-21 22:34 - 00000000 ____D () C:\CNYSELPHYCP
2015-04-21 22:34 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-21 22:34 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-21 22:34 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-21 22:34 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-21 22:34 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-21 22:34 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-21 22:34 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-21 22:34 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-21 22:34 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-21 22:34 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-21 22:34 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-21 22:34 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-21 22:34 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-21 22:34 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-21 22:34 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-21 22:34 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-21 22:32 - 2014-11-11 04:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2015-04-21 22:32 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2015-04-21 22:32 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2015-04-21 22:31 - 2012-08-22 19:16 - 00712048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-04-21 22:31 - 2012-07-04 21:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2015-04-21 22:30 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-04-21 22:30 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2015-04-21 22:30 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2015-04-21 22:30 - 2013-01-24 06:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2015-04-21 22:30 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2015-04-21 22:29 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-04-21 22:29 - 2013-08-28 02:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2015-04-21 22:29 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2015-04-21 22:28 - 2015-04-21 22:28 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2015-04-21 22:28 - 2014-08-12 03:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2015-04-21 22:28 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2015-04-21 22:28 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-04-21 22:28 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-04-21 22:28 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2015-04-21 22:28 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-04-21 22:28 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2015-04-21 22:28 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2015-04-21 22:28 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2015-04-21 22:28 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2015-04-21 22:28 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2015-04-21 22:28 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2015-04-21 22:28 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2015-04-21 22:28 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2015-04-21 22:28 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2015-04-21 22:28 - 2012-10-03 18:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2015-04-21 22:28 - 2012-10-03 17:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2015-04-21 22:28 - 2012-08-21 22:12 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2015-04-21 22:28 - 2012-03-01 07:46 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2015-04-21 22:28 - 2012-03-01 07:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2015-04-21 22:27 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-21 22:27 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-21 22:27 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-21 22:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-04-21 22:27 - 2014-11-08 04:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-04-21 22:27 - 2014-10-14 03:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-04-21 22:27 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2015-04-21 22:27 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2015-04-21 22:27 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2015-04-21 22:27 - 2013-10-04 03:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2015-04-21 22:27 - 2013-10-04 03:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2015-04-21 22:27 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-04-21 22:27 - 2013-03-19 05:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2015-04-21 22:27 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2015-04-21 22:27 - 2012-07-04 23:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2015-04-21 22:27 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2015-04-21 22:27 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2015-04-21 22:27 - 2011-04-29 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-04-21 22:27 - 2011-04-29 04:46 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2015-04-21 22:27 - 2011-04-29 04:46 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2015-04-21 22:27 - 2011-02-12 07:35 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2015-04-21 22:26 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-04-21 22:26 - 2014-11-11 03:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-04-21 22:26 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2015-04-21 22:26 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-04-21 22:26 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2015-04-21 22:26 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2015-04-21 22:26 - 2011-12-30 07:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2015-04-21 22:26 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2015-04-21 22:26 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2015-04-21 22:26 - 2011-08-17 06:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2015-04-21 22:26 - 2011-08-17 06:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2015-04-21 22:26 - 2011-07-09 04:30 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-04-21 22:26 - 2011-06-16 06:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2015-04-21 22:26 - 2011-05-24 12:44 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2015-04-21 22:26 - 2011-05-04 06:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-04-21 22:26 - 2011-05-04 06:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-04-21 22:26 - 2011-05-04 06:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-04-21 22:26 - 2011-05-04 06:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-04-21 22:26 - 2011-05-04 06:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-04-21 22:26 - 2011-05-04 06:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2015-04-21 22:26 - 2011-05-04 06:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-04-21 22:26 - 2011-05-04 06:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-04-21 22:26 - 2011-05-04 06:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2015-04-21 22:26 - 2011-05-03 06:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-04-21 22:26 - 2011-04-27 04:17 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-04-21 22:26 - 2011-04-27 04:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-04-21 22:26 - 2011-03-03 07:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-04-21 22:26 - 2011-03-03 07:38 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2015-04-21 22:26 - 2011-03-03 07:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2015-04-21 22:26 - 2011-02-18 07:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2015-04-21 22:26 - 2010-12-23 07:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2015-04-21 22:26 - 2010-12-23 07:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2015-04-21 22:26 - 2010-12-23 07:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2015-04-21 22:25 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2015-04-21 22:25 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2015-04-21 22:25 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2015-04-21 22:25 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2015-04-21 22:25 - 2012-05-14 06:33 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-04-21 22:24 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-04-21 22:24 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2015-04-21 22:24 - 2012-04-26 06:45 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2015-04-21 22:24 - 2012-04-26 06:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2015-04-21 22:24 - 2012-03-17 09:27 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2015-04-21 22:24 - 2012-01-04 10:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2015-04-21 22:24 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2015-04-21 22:24 - 2011-11-17 07:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2015-04-21 22:24 - 2011-06-15 10:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll
2015-04-21 22:24 - 2011-06-15 10:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2015-04-21 22:24 - 2011-06-15 10:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2015-04-21 22:24 - 2011-06-15 10:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2015-04-21 22:24 - 2011-06-15 10:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-21 22:23 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-21 22:23 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-21 22:23 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-21 22:23 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2015-04-21 22:23 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2015-04-21 22:23 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2015-04-21 22:23 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2015-04-21 22:23 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2015-04-21 22:23 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2015-04-21 22:23 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2015-04-21 22:23 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2015-04-21 22:23 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2015-04-21 22:23 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2015-04-21 22:22 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-04-21 22:22 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-04-21 22:22 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-04-21 22:22 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-04-21 22:22 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-04-21 22:22 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-04-21 22:22 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-04-21 22:22 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-04-21 22:22 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-04-21 22:22 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-04-21 22:22 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-04-21 22:22 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-04-21 22:22 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-04-21 22:22 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-04-21 22:22 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-04-21 22:22 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-04-21 22:22 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-04-21 22:22 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-04-21 22:22 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2015-04-21 22:22 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-04-21 22:22 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2015-04-21 22:22 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-04-21 22:22 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-04-21 22:22 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-04-21 22:22 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-04-21 22:21 - 2014-12-19 04:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-04-21 22:21 - 2014-11-26 05:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-04-21 22:21 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2015-04-21 22:21 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-04-21 22:21 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-04-21 22:21 - 2013-10-12 04:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-04-21 22:21 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-04-21 22:21 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-04-21 22:21 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-04-21 22:20 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-04-21 22:20 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-04-21 22:20 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-04-21 22:20 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-04-21 22:20 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-04-21 22:20 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-04-21 22:20 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-04-21 22:20 - 2014-12-19 03:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-04-21 22:20 - 2014-10-30 03:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-04-21 22:20 - 2014-10-25 03:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2015-04-21 22:20 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-04-21 22:20 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2015-04-21 22:20 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2015-04-21 22:20 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-04-21 22:20 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-04-21 22:20 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-04-21 22:20 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2015-04-21 22:20 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2015-04-21 22:20 - 2013-11-27 03:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-04-21 22:20 - 2013-11-27 03:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2015-04-21 22:20 - 2013-11-27 03:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2015-04-21 22:20 - 2013-11-27 03:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2015-04-21 22:20 - 2013-11-27 03:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2015-04-21 22:20 - 2013-11-27 03:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2015-04-21 22:20 - 2013-11-26 13:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2015-04-21 22:20 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2015-04-21 22:20 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2015-04-21 22:20 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2015-04-21 22:20 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-04-21 22:20 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-04-21 22:20 - 2011-02-23 06:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2015-04-21 22:19 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-21 22:19 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-21 22:19 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-21 22:19 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-04-21 22:19 - 2014-12-06 05:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-04-21 22:19 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2015-04-21 22:19 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-04-21 22:19 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-04-21 22:19 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-04-21 22:19 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-21 22:19 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-21 22:19 - 2013-07-12 12:08 - 00146816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2015-04-21 22:19 - 2013-07-12 12:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2015-04-21 22:19 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-04-21 22:19 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-04-21 22:19 - 2012-11-29 00:57 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-04-21 22:19 - 2012-11-29 00:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2015-04-21 22:19 - 2012-11-29 00:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-04-21 22:19 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-04-21 22:19 - 2012-10-03 18:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-04-21 22:18 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-04-21 22:17 - 2015-04-22 08:14 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-04-21 22:17 - 2015-04-22 08:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-04-21 22:17 - 2015-04-21 22:24 - 00000000 ____D () C:\ProgramData\HP Photo Creations
2015-04-21 22:17 - 2015-04-21 22:17 - 00001055 _____ () C:\Users\Public\Desktop\HP Photo Creations.lnk
2015-04-21 22:17 - 2015-04-21 22:17 - 00000000 ____D () C:\Program Files\HP Photo Creations
2015-04-21 22:16 - 2015-04-29 10:04 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\HpUpdate
2015-04-21 22:16 - 2015-04-28 20:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-04-21 22:16 - 2015-04-24 22:03 - 00000000 ____D () C:\ProgramData\HP
2015-04-21 22:16 - 2015-04-21 22:16 - 00002236 _____ () C:\Users\Public\Desktop\HP Deskjet 1050 J410 series.lnk
2015-04-21 22:16 - 2015-04-21 22:16 - 00001194 _____ () C:\Users\Public\Desktop\Zubehör einkaufen - HP Deskjet 1050 J410 series.lnk
2015-04-21 22:16 - 2015-04-21 22:16 - 00001189 _____ () C:\Users\Public\Desktop\HP Deskjet 1050 J410 series Scan.lnk
2015-04-21 22:15 - 2015-04-24 22:20 - 00000000 ____D () C:\Program Files\HP
2015-04-21 22:14 - 2015-04-21 22:14 - 00000000 ____D () C:\Users\Dagmar\AppData\Local\HP
2015-04-21 22:05 - 2015-04-30 11:57 - 00113048 _____ () C:\Users\Hans Leo\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-21 22:05 - 2015-04-21 22:05 - 00001409 _____ () C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-21 22:04 - 2015-04-22 21:52 - 00000000 ____D () C:\Users\Hans Leo
2015-04-21 22:04 - 2015-04-22 21:33 - 00000000 ____D () C:\Users\Hans Leo\AppData\Local\VirtualStore
2015-04-21 22:04 - 2015-04-21 22:04 - 00000020 ___SH () C:\Users\Hans Leo\ntuser.ini
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\Startmenü
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\Netzwerkumgebung
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\Druckumgebung
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\Documents\Eigene Musik
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\Documents\Eigene Bilder
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-21 22:04 - 2015-04-21 22:04 - 00000000 _SHDL () C:\Users\Hans Leo\AppData\Local\Verlauf
2015-04-21 22:04 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-21 22:04 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Hans Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-21 21:56 - 2015-04-21 22:57 - 00000000 ____D () C:\Users\Dagmar\AppData\Roaming\Mozilla
2015-04-21 21:54 - 2015-03-24 14:59 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-21 21:53 - 2015-04-30 08:17 - 00113048 _____ () C:\Users\Dagmar\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-21 21:52 - 2015-04-28 19:00 - 00000000 ____D () C:\Program Files\Avira
2015-04-21 21:52 - 2015-04-21 21:52 - 04636584 _____ (Avira Operations GmbH & Co. KG) C:\Users\Dagmar\Downloads\avira_de_av_5536aa3015bd3__ws.exe
2015-04-21 21:52 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-04-21 21:52 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-04-21 21:52 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-04-21 21:52 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-04-21 21:52 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-04-14 18:28 - 2015-04-14 18:28 - 00004387 _____ () C:\Users\Dagmar\AppData\Roaming\shYKfVVYKicsWZrff7FtP3HVn
2015-04-14 18:28 - 2015-04-14 18:28 - 00004387 _____ () C:\Users\Dagmar\AppData\Roaming\FDabpSTyB3GqZd4NlqSja

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-02 11:15 - 2010-11-20 23:01 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-02 10:06 - 2009-07-14 06:34 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-02 10:06 - 2009-07-14 06:34 - 00020640 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-02 08:34 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-30 13:02 - 2009-07-14 04:04 - 00000478 _____ () C:\Windows\win.ini
2015-04-30 08:42 - 2009-07-14 04:07 - 00000000 ____D () C:\C
2015-04-30 08:33 - 2009-07-14 04:07 - 00000000 ____D () C:\Users\Dagmar\Documents\C
2015-04-30 01:30 - 2009-07-14 06:33 - 00439696 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-29 23:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-29 23:14 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-29 23:08 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-29 19:24 - 2010-11-21 02:46 - 00000000 ____D () C:\Windows\ShellNew
2015-04-28 22:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-04-28 20:06 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\twain_32
2015-04-24 22:15 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-24 22:04 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-23 23:18 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-23 10:13 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-23 00:29 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-04-22 23:15 - 2010-11-21 02:46 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-04-22 22:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-04-22 21:53 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-04-22 21:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-22 09:35 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-22 09:32 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-04-22 09:01 - 2009-07-14 06:57 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-04-22 09:01 - 2009-07-14 06:52 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2015-04-22 08:59 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-04-22 07:58 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\tracing
2015-04-22 07:31 - 2010-11-21 02:47 - 00000000 ____D () C:\Program Files\Windows Journal
2015-04-22 05:27 - 2010-11-21 02:38 - 00000000 ____D () C:\Windows\system32\winrm
2015-04-22 05:27 - 2010-11-21 02:38 - 00000000 ____D () C:\Windows\system32\WCN
2015-04-22 05:27 - 2010-11-21 02:38 - 00000000 ____D () C:\Windows\system32\slmgr
2015-04-22 05:27 - 2010-11-21 02:38 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2015-04-22 05:27 - 2010-11-21 02:38 - 00000000 ____D () C:\Windows\DigitalLocker
2015-04-22 05:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-04-22 05:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-04-22 05:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\DVD Maker
2015-04-22 05:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\MUI
2015-04-22 05:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\com
2015-04-22 05:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\IME
2015-04-22 05:26 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\zh-TW
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\zh-HK
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\zh-CN
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\sv-SE
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pt-PT
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pt-BR
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\nl-NL
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\nb-NO
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\it-IT
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\hu-HU
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\fr-FR
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\fi-FI
2015-04-22 05:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\el-GR
2015-04-22 00:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Help
2015-04-21 23:31 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Public\Libraries
2015-04-21 23:29 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\restore
2015-04-21 23:12 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2015-04-21 23:12 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\Recovery
2015-04-21 23:12 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Windows NT
2015-04-21 23:06 - 2009-07-14 06:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

==================== Files in the root of some directories =======

2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Dagmar\AppData\Roaming\FDabpSTyB3GqZd4NlqSja
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Dagmar\AppData\Roaming\shYKfVVYKicsWZrff7FtP3HVn
2015-04-22 20:40 - 2015-04-22 20:40 - 0613255 _____ (CMI Limited) C:\Users\Dagmar\AppData\Local\nsiB3F.tmp
2015-04-22 20:54 - 2015-04-22 20:54 - 0613255 _____ (CMI Limited) C:\Users\Dagmar\AppData\Local\nsn7918.tmp
2015-04-22 10:25 - 2015-04-22 10:25 - 0000057 _____ () C:\ProgramData\Ament.ini

Some content of TEMP:
====================
C:\Users\Dagmar\AppData\Local\Temp\avgnt.exe
C:\Users\Hans Leo\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-24 11:29

==================== End Of Log ============================

--- --- ---

daggimaus 02.05.2015 19:46

Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-05-2015
Ran by Dagmar at 2015-05-02 20:30:24
Running from C:\Users\Dagmar\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1957182844-2440048667-671278128-500 - Administrator - Disabled)
Dagmar (S-1-5-21-1957182844-2440048667-671278128-1000 - Administrator - Enabled) => C:\Users\Dagmar
Gast (S-1-5-21-1957182844-2440048667-671278128-501 - Limited - Disabled)
Hans Leo (S-1-5-21-1957182844-2440048667-671278128-1003 - Limited - Enabled) => C:\Users\Hans Leo
HomeGroupUser$ (S-1-5-21-1957182844-2440048667-671278128-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Antivirus (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Avira (HKLM\...\{d8490d5d-0f24-4000-b2e4-4b500a9a704d}) (Version: 1.1.35.25717 - Avira Operations GmbH & Co. KG)
Avira (Version: 1.1.35.25717 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM\...\Avira Antivirus) (Version: 15.0.9.504 - Avira Operations GmbH & Co. KG)
Bing Bar (HKLM\...\{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}) (Version: 7.1.361.0 - Microsoft Corporation)
Canon PhotoRecord (HKLM\...\{37A54340-6655-4FFC-BC4C-0B945764DA4B}) (Version: 02.02.04002 - Cisra)
Canon SELPHY CP710 (HKLM\...\Canon SELPHY CP710) (Version:  - )
Canon Utilities Anleitung zum CP-Drucker (HKLM\...\InstallShield_{B4A6DE2E-5E84-4F1D-B26A-EAB0D42ED932}) (Version: 5.0.0 - Canon)
Canon Utilities Easy-PhotoPrint (HKLM\...\Easy-PhotoPrint) (Version:  - )
Canon Utilities PhotoStitch 3.1 (HKLM\...\InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}) (Version: 3.1.14 - Canon)
CLIQZ (HKLM\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 1.0.0 - CLIQZ.com)
CP Printer Guide (Version: 5.0.0 - Canon) Hidden
DriverScanner (HKLM\...\{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1) (Version: 4.0.14.0 - Uniblue Systems Ltd)
HP Deskjet 1050 J410 series - Grundlegende Software für das Gerät (HKLM\...\{FE19B8A3-C79D-4A90-8F7C-1B206DB00CFC}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1050 J410 series Hilfe (HKLM\...\{5C90D8CF-F12A-41C6-9007-3B651A1F0D78}) (Version: 140.0.66.66 - Hewlett Packard)
HP Photo Creations (HKLM\...\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife)
HP Support Solutions Framework (HKLM\...\{FC3C2B77-6800-48C6-A15D-9D1031130C16}) (Version: 11.51.0049 - Hewlett-Packard Company)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
Internet Controller (HKLM\...\Internet Controller) (Version: 4.1.0.4 - Inquiro SA)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office Web Apps Browser Plugin (HKLM\...\{95140000-1148-0407-0000-0000000FF1CE}) (Version: 14.0.5568.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 37.0.2 (x86 de) (HKLM\...\Mozilla Firefox 37.0.2 (x86 de)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 37.0.2 - Mozilla)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.4 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 341.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PhotoStitch (Version: 3.1.14 - Canon) Hidden
PlayReady PC Runtime x86 (HKLM\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{90150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUS_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version:  - Microsoft)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Studie zur Verbesserung von HP Deskjet 1050 J410 series Produkten (HKLM\...\{40AAB711-8EFF-4830-8B39-017D3F66983D}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM\...\{90150000-012B-0407-0000-0000000FF1CE}_Office15.PROPLUS_{0C5B0539-7EDE-4297-947E-48890971B557}) (Version:  - Microsoft)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

29-04-2015 19:18:58 Installed Microsoft Office Professional Plus 2013
29-04-2015 19:19:21 PROPLUS
29-04-2015 22:47:44 Windows Update
30-04-2015 01:35:25 Windows Update
30-04-2015 12:26:53 Windows-Sicherung
30-04-2015 12:52:46 Windows Update
01-05-2015 19:17:40 Windows Update
01-05-2015 19:33:23 Microsoft Office Web Apps Browser Plugin wurde installiert.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {02A94CE3-1363-40B6-B153-D05217819D82} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {233681E8-ED35-4EBB-989B-E47FEB4D4FE9} - System32\Tasks\{181B4621-805A-4163-A822-083730C7BC89} => pcalua.exe -a E:\TROUBLESHOOT\REGUPD_IS.EXE -d E:\TROUBLESHOOT
Task: {272A59F5-4098-4E90-A5D8-9835529D054C} - System32\Tasks\DriverScanner => C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
Task: {2FFD3BE4-A2FA-4BA4-A656-B3ED52354371} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {492614C3-3060-41A5-9EBF-7D22D5B6FE42} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {4AF8CF5C-CD1E-4BD3-87D1-CDF64BC96828} - System32\Tasks\{D5BAB023-712A-428B-8BF2-A79897A9B4A5} => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [2015-04-10] (Avira Operations GmbH & Co. KG)
Task: {4F4AB625-B012-46C8-8F42-6FD1F5F0AF66} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {51C100AE-06B2-4384-AF6D-8A2AB6513F7E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {59C88F00-FEF3-480F-BADF-DDE806FD2B75} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Dagmar-PC-Hans Leo Dagmar-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2015-02-10] (Microsoft Corporation)
Task: {72AC95CF-39EC-445A-B2D1-C994F6A8B1DC} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {8415D138-65A9-4628-B7B9-48A23C86AAE9} - System32\Tasks\dsmonitor => C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
Task: {A09F4617-759A-4607-A2BC-25562CF62782} - System32\Tasks\{7166FA87-6EB4-4BE5-AF1C-1914F2FF6479} => pcalua.exe -a E:\TROUBLESHOOT\INSTMSIW.EXE -d E:\TROUBLESHOOT
Task: {A6E432CD-039A-47B8-A792-3A2D922EBBE8} - System32\Tasks\LaunchPreSignup => C:\Program Files\OLBPre\OLBPre.exe <==== ATTENTION
Task: {B829A914-D516-4CAA-87FD-5EB72E8FB022} - System32\Tasks\{4054F6B8-33F8-46AF-A84C-17688ACA85E7} => pcalua.exe -a E:\SETUP.EXE -d E:\
Task: {C6A4CDD3-5E94-4302-87D2-BB3B99AE60DA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {C8E974AB-D9AA-473F-85A7-7B569ADC413E} - System32\Tasks\Reimage Reminder => C:\Program Files\eFix\eFix Pro\eFixReminder.exe <==== ATTENTION
Task: {CC71DF06-5394-4B49-B4BE-B5590B7593F0} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {DAFA2CF2-402A-4407-BA95-DA09B6B769E2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)
Task: {DB3829E1-1A3C-41D0-9403-698D39965EF6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {E33680CC-0DA7-47C9-BB85-B93ADB4C998F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-01] (Adobe Systems Incorporated)
Task: {F0AE99A2-C53F-4634-A027-75678C042DBE} - System32\Tasks\HPCustParticipation HP Deskjet 1050 J410 series => C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverScanner.job => C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
Task: C:\Windows\Tasks\dsmonitor.job => C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe

==================== Loaded Modules (whitelisted) ==============

2015-04-22 00:05 - 2015-02-04 04:05 - 00106640 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2014-11-27 16:31 - 2014-11-27 16:31 - 00187168 _____ () C:\Users\Dagmar\AppData\Roaming\Internet-Controller\internet-controllerservice.exe
2014-11-27 16:31 - 2014-11-27 16:31 - 00913184 _____ () C:\Users\Dagmar\AppData\Roaming\Internet-Controller\internet-controller.exe
2015-04-23 00:24 - 2015-03-28 05:45 - 00011920 _____ () C:\Program Files\NVIDIA Corporation\Update Core\detoured.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1957182844-2440048667-671278128-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dagmar\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [{0134F0F2-8482-410C-AA67-AF1C4DC107B6}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{6849E066-A865-49D3-BCC8-338E2EA2E81B}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{B318FAAF-4C3D-4240-AA3F-BDAD1A37D4B8}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{4F88FC8F-C0A8-4A90-AC04-D96D4501D8DC}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{5D9267F7-4712-4EF6-8722-7071CF474FEE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{4BA57926-64A2-4B81-9EBE-6639BEF3A84D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{28F2531B-0BD3-41F3-8B91-F1CDE3CC52FA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{86808F1A-25B4-4374-9DBA-5F013ECCC0A4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{13977B3A-003B-42EB-8F4E-228A04DA58E8}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS777E\hppiw.exe
FirewallRules: [{F0B381DF-DA19-4E2C-A50D-6A6C103CDE4A}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS777E\hppiw.exe
FirewallRules: [{5236FC9F-6808-4CE3-B2EA-E16B172C7444}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS0551\HPDiagnosticCoreUI.exe
FirewallRules: [{38BF83CA-D29C-4C46-AD97-8E12187E721F}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS0551\HPDiagnosticCoreUI.exe
FirewallRules: [{6BB83565-3AD4-4BB1-B706-BCDF1D707C66}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS632E\HPDiagnosticCoreUI.exe
FirewallRules: [{C1FD21A5-DC7C-4C8F-A860-5EBE58624F02}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS632E\HPDiagnosticCoreUI.exe
FirewallRules: [{180BE5DE-A302-444F-87AA-5E578D10AF2E}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS0FC0\hppiw.exe
FirewallRules: [{E99B72ED-CCF8-4A9C-8E33-962E6F7F4D67}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS0FC0\hppiw.exe
FirewallRules: [{63CD2CB1-C766-478A-9CD8-31D997030710}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS1874\hppiw.exe
FirewallRules: [{68E10741-F90B-4DFF-96F0-EE78A648855F}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS1874\hppiw.exe
FirewallRules: [{A8102525-A1CC-408D-9C3A-3E5DF34F6DA8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{D87D609B-54FB-4B15-86E3-5044044B5920}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{28A242F9-8901-4BE5-BD22-9EF3B06CC8E6}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [{88B666CE-24D3-44B5-A5C9-57F023E68A3F}] => (Allow) C:\Program Files\HP\HP Deskjet 1050 J410 series\Bin\USBSetup.exe
FirewallRules: [{F7855F25-74C0-4595-9D75-E3334C13E9BC}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS66BA\hppiw.exe
FirewallRules: [{0827BD0C-2F57-4E20-83F0-D5F57B1F8FC8}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS66BA\hppiw.exe
FirewallRules: [{6999F882-9299-4814-B2FC-06881627CAFC}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS5928\hppiw.exe
FirewallRules: [{78727E59-338C-426B-BD10-6F8A407B3E97}] => (Allow) C:\Users\Dagmar\AppData\Local\Temp\7zS5928\hppiw.exe
FirewallRules: [{04F6639B-682E-470A-BC86-1525407DA979}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{4B26A453-3ECE-47C5-8057-D1750FE3727F}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB4C7814-98F2-4700-AB69-29595DBE7EE2}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{484C941E-AB52-40F7-9A65-F5821BC4B781}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{D2E71E92-DC55-457B-9DCA-FD584CD57856}] => (Allow) C:\Program Files\Microsoft Office\Office15\outlook.exe

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/02/2015 05:44:13 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]

Error: (05/02/2015 05:41:18 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]

Error: (05/02/2015 08:35:13 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/02/2015 08:35:02 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/02/2015 08:34:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x5513995d
Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x5513995d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0040f257
ID des fehlerhaften Prozesses: 0x89c
Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0
Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1
Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2
Berichtskennung: NvStreamNetworkService.exe3

Error: (05/02/2015 08:34:38 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/01/2015 09:49:59 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/01/2015 09:49:48 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/01/2015 09:49:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x5513995d
Name des fehlerhaften Moduls: NvStreamNetworkService.exe, Version: 4.1.1943.6202, Zeitstempel: 0x5513995d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0040f257
ID des fehlerhaften Prozesses: 0xd64
Startzeit der fehlerhaften Anwendung: 0xNvStreamNetworkService.exe0
Pfad der fehlerhaften Anwendung: NvStreamNetworkService.exe1
Pfad des fehlerhaften Moduls: NvStreamNetworkService.exe2
Berichtskennung: NvStreamNetworkService.exe3

Error: (05/01/2015 09:49:19 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()


System errors:
=============
Error: (05/02/2015 08:19:39 PM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.

Error: (05/02/2015 10:23:58 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.

Error: (05/02/2015 10:05:03 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.

Error: (05/02/2015 10:03:02 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.

Error: (05/02/2015 09:48:53 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.

Error: (05/02/2015 08:37:15 AM) (Source: cdrom) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden.

Error: (05/02/2015 08:35:13 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert.

Error: (05/02/2015 08:35:02 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (05/02/2015 08:34:52 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (05/02/2015 08:34:34 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SuperOptimizer Stats erreicht.


Microsoft Office Sessions:
=========================
Error: (05/02/2015 05:44:13 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]

Error: (05/02/2015 05:41:18 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]

Error: (05/02/2015 08:35:13 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/02/2015 08:35:02 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/02/2015 08:34:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: NvStreamNetworkService.exe4.1.1943.62025513995dNvStreamNetworkService.exe4.1.1943.62025513995dc00000050040f25789c01d084a20f2edc10C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe55f82a70-f095-11e4-ac9c-4061860b4e4f

Error: (05/02/2015 08:34:38 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/01/2015 09:49:59 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/01/2015 09:49:48 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/01/2015 09:49:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: NvStreamNetworkService.exe4.1.1943.62025513995dNvStreamNetworkService.exe4.1.1943.62025513995dc00000050040f257d6401d08447e8055b50C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exeC:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe336afdc0-f03b-11e4-acb6-4061860b4e4f

Error: (05/01/2015 09:49:19 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Avira.OE.ServiceHost.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.Xml.XmlException
Stapel:
  bei System.Xml.XmlTextReaderImpl.Throw(System.Exception)
  bei System.Xml.XmlTextReaderImpl.ParseDocumentContent()
  bei System.Xml.XmlTextReaderImpl.Read()
  bei System.Xml.XmlLoader.Load(System.Xml.XmlDocument, System.Xml.XmlReader, Boolean)
  bei System.Xml.XmlDocument.Load(System.Xml.XmlReader)
  bei System.Xml.XmlDocument.Load(System.String)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.TryLoadXmlDocumentFromFile(Int32, System.TimeSpan)
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.LoadXmlDocumentFromFile()
  bei Avira.OE.WinCore.OeSharedSettingsAccessor.Get(System.String)
  bei Avira.OE.WinCore.OeProductInfo.get_Culture()
  bei Avira.OE.WinCore.Utility.CultureSetter.SetDefaultCultureDefinedInAppsettings()
  bei Avira.OE.ServiceHost.ServiceHost.SetDefaultCulture()
  bei Avira.OE.ServiceHost.ServiceHost.Initialize(System.Object)
  bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
  bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
  bei System.Threading.ThreadPoolWorkQueue.Dispatch()
  bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()


==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4400 @ 2.20GHz
Percentage of memory in use: 55%
Total physical RAM: 3327.24 MB
Available physical RAM: 1493.98 MB
Total Pagefile: 6652.77 MB
Available Pagefile: 4065.94 MB
Total Virtual: 2047.88 MB
Available Virtual: 1878.98 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:390.62 GB) (Free:340.56 GB) NTFS
Drive d: () (Fixed) (Total:540.79 GB) (Free:540.68 GB) NTFS
Drive f: (Elements) (Fixed) (Total:931.48 GB) (Free:758.23 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F20FDE76)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=540.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=390.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 00023F15)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End Of Log ============================


schrauber 03.05.2015 13:44

Zitat:

Ich habe inzwischen die Festplatte formatiert und Windows 7 neu installiert. Seitdem läuft alles rund. Es wurden 2 Partitionen mit fast identischer Größe erstellt. Ein Recovery wurde jedoch nicht erstellt. Jetzt habe ich auf C: das Betriebssystem und D: ist leer. Ich muss immer wenn ich boote bestätigen, dass ich Windows 7 laden möchte. Das ist aber nicht dramatisch. Vielleicht wäre das aber auch zu ändern.
Ich sehe da immer noch ein altes XP rumliegen. Und wie schafft man es ein neu installiertes System gleich zu verseuchen?


http://www.trojaner-board.de/104197-...anleitung.html


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:04 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131