Anmerkung zur Anwendung von Malware Anti-Malware, da ich nicht weiß, ob es wichtig ist:
Im ersten Durchgang wurden über 1400 Bedrohungen nach 23 Minuten gefunden, jedoch wies der Verlauf nur die nicht relevanten Protection-Logs aus, aber keinen einzigen Scan-Log, sodass ein neuer Suchlauf gestartet wurde. Dieser ergab nach 53 Minuten 201 Bedrohungen, die nach einer Weile auch im Verlauf als Scan-Log erschienen. Diese Datei ist als txt. untenstehend. Nach beiden Durchläufen wurde jeweils der Quarantäne-Ordner gelöscht, wie im dortigen Hinweis auch ersichtlich, um Bedrohungen vom Rechner zu löschen. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.06.2015
Suchlauf-Zeit: 19:31:25
Logdatei: Malware Scan.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.16.05
Rootkit Datenbank: v2015.06.15.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: Anja
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 336294
Verstrichene Zeit: 53 Min, 22 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 171
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\LocalLow\BabylonToolbar, , [b8ada615bad0e650e637bf0d27dce020],
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\LocalLow\BabylonToolbar\BabylonToolbar, , [b8ada615bad0e650e637bf0d27dce020],
PUP.Optional.SystemSpeedup, C:\Users\Anja\AppData\Roaming\Systweak\ssd, , [6bfa982388029f97eb96626f51b2817f],
PUP.Optional.Spigot.A, C:\Program Files\Common Files\Spigot, , [6401f1cad8b2ac8a2237eeeba45f7b85],
PUP.Optional.Spigot.A, C:\Program Files\Common Files\Spigot\GC, , [6401f1cad8b2ac8a2237eeeba45f7b85],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\logic, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\logic\uninstall, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\logic\uninstall\dialog, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\logic\uninstall\dialog\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\logic\uninstall\dialog\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\logic\uninstall\dialog\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\aboutBox, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\aboutBox\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\aboutBox\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ac, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ac\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ac\img, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ac\res, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\api, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\msd, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\options, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\options\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\options\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\options\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\options\js\resources, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\sp, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\sp\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\sp\spbd, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\sp\spbd\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\sp\spsd, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\sp\spsd\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\dlg, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\dlg\ftd, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\dlg\ftd\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\gadgetFrame, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\gf, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\gf\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\gf\img, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\gf\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\menu, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\menu\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\menu\img, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\ui\menu\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\APPLICATION_BUTTON, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\APPLICATION_BUTTON\Js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\APPLICATION_BUTTON\resources, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\EMAIL_NOTIFIER, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\EMAIL_NOTIFIER\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\EMAIL_NOTIFIER\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\HIGHLIGHTER, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\HIGHLIGHTER\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\HIGHLIGHTER\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\MULTI_RSS, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\MULTI_RSS\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\MULTI_RSS\img, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\MULTI_RSS\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\MULTI_RSS\js\resources, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\NOTIFICATION, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\NOTIFICATION\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\NOTIFICATION\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\NOTIFICATION\images\dark, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\NOTIFICATION\images\light, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\NOTIFICATION\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\Optimizer, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\Optimizer\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\PRICE_GONG, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\PRICE_GONG\agreement, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\PRICE_GONG\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\PRICE_GONG\css\custom-theme, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\PRICE_GONG\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\RADIO_PLAYER, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\RADIO_PLAYER\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\RADIO_PLAYER\css\custom-theme, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\RADIO_PLAYER\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\RADIO_PLAYER\js\resources, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\buildSettings, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\Css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\resources, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\view, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\view\script, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\view\style, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\SEARCH\view\style\rsx, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\TWITTER, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\TWITTER\img, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\TWITTER\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\WEATHER, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\WEATHER\css, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\al\wa\WEATHER\js, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\core, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\lib, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\lib\jquery.alerts, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\lib\jquery.alerts\images, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\lib\jquery.jscrollpane, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\CT3316068\content\tb\sl, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\mam, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Chrome\mam\content, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\components, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\components\mam, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\defaults, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\defaults\preferences, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\lib, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\META-INF, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\modules, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.SweetPacks.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48}\Plugins, , [8cd98a3168224cea3789d8019f6449b7],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Logs, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\AddedAppDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DefualtImages, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DetectedAppDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\EngineFirstTimeDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\images, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\Images, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarUntrustedAppsApprovalDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UninstallDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAddedAppDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppApprovalDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppPendingDialog, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\ExternalComponent, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\MyStuffApps, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\plugins, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\RadioPlayer, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\AppsMetaData, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\DynamicDialogs, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenLogin, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenSettings, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarLogin, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarSettings, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarTranslation, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_de, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_de\ToolbarTranslation, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\SearchInNewTab, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE\UserDefinedItems, , [560f2c8f4d3df640b900b922bc47a35d],
PUP.Optional.DVDVideoSoftTB.A, C:\Program Files\DVDVideoSoftTB_DE, , [22431c9f800ac4723189f3e8748fb44c],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\alert, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\alert\Dialogs, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\alert\Dialogs\AppNotificationDialog, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\alert\Dialogs\AppNotificationDialog\Images, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\alert\Dialogs\AppNotificationDialog\Images\dark, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\alert\Dialogs\AppNotificationDialog\Images\light, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\facebook, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\modules, , [82e325965a306ccae80ef8f8bf4449b7],
PUP.Optional.ConduitTB.Gen, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\conduitCommon\modules\3.14.1.0, , [82e325965a306ccae80ef8f8bf4449b7],
Dateien: 30
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), ,[f76e605b8505e6501b42077ed82e5ba5]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (ferechanges to this file while the application is running,
* the), ,[293c07b44f3b0036e17c88fd808636ca]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: ( this file while the application is running,
* the changes will be overwritten whe), ,[1d485c5fd2b8eb4b73ea463fb650bf41]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (he application is running,
* the changes will be overwritten when the applicat), ,[cb9a09b2731742f4332ac2c31aec49b7]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (le the application is running,
* the changes will be over), ,[184d902b90fa3105b4a9394c838330d0]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (nges to this file while the application is running,
* t), ,[bca987346228ce68ee6fd0b56e9857a9]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (hanges to this file while the application is running,
* the cha), ,[70f56a515f2bba7c233abbcaa6606799]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (o this file while the application is running,
* the change), ,[cf96d0ebfa90350190cd8ef7759157a9]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (ges to this file while the application is running,
* th), ,[a4c1e6d5f397999d4b12c1c40afc1be5]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (hanges to this file while the application is running,
), ,[600527945b2fb284302d3a4b36d0748c]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (rechanges to this file while the application is running), ,[a4c1d3e86d1d999d7de07b0a5aacfe02]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (echanges to this file while the application is running,
), ,[69fc5566b6d4c571f36ac8bdc73f6c94]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (anges to this file while the application is running,
* the changes), ,[bbaa7b40a7e3e5512538285d44c2bc44]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (his file while the application is running,
* the changes ), ,[b5b0f7c4038737ffb4a97c09c4428c74]
PUP.Optional.Conduit.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (user_pref("CT3316068.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3316068&SearchSource=2&CUI=UN20141627741223012&UM=2&q=");), ,[31341ba03d4ddb5b09a9aed7d234a45c]
PUP.Optional.Conduit.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\prefs.js, Gut: (), Schlecht: (user_pref("CT3316068.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3316068&octid=CT3316068&SearchSource=15&CUI=UN20141627741223012&SSPV=&Lay=1&UM=2\"}");), ,[4b1ad0ebddadec4af9c75d28de28936d]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), ,[6203a11ae9a1280ee61f780d8f77ba46]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (ons.autoDisablse);
user_pref("extensions.BabylonToo), ,[214447741e6cb284e42194f17b8b56aa]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (s.autoDisablse);
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_p), ,[b0b5f6c58dfd46f012f3d2b3ec1a8d73]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (ref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar), ,[4a1ba813addd0234d233fd88c73fcf31]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: ("extensions.BabylonToolbar_i.babExt", "");
user_pref("exte), ,[481d9d1ea4e69a9cf312186d16f027d9]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (oDisablse);
user_pref("extensions.BabylonToolbar_i.babE), ,[fd68b8031872ed490cf9a9dca561ed13]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (toDisablse);
user_pref("extensions.BabylonToolbar_i.babE), ,[026369526e1c8aaca164e69fd72ffe02]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (oDisablse);
user_pref("extensions.BabylonToolbar_i.babExt", "");
), ,[560f02b991f91b1bbb4adea7c4428b75]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: ();
user_pref("extensions.BabylonToolbar_i.babExt", "");
), ,[d1942794602ab28420e5bfc6ad59e51b]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (Disablse);
user_pref("extensions.BabylonToolbar_i.babExt", "")), ,[f96c2a91bad058dee61f8afba165ae52]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (lse);
user_pref("extensions.BabylonToolbar_i.babExt",), ,[b6af6e4d484257df3ec79bea9b6b857b]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (autoDisablse);
user_pref("extensions.BabylonToolbar_i.), ,[ff66cfecc9c1b18593725d28b15554ac]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (utoDisablse);
user_pref("extensions.BabylonToolbar_i), ,[263fd7e43b4f4fe747bebacb4cba15eb]
PUP.Optional.Babylon.A, C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js, Gut: (), Schlecht: (.autoDisablse);
user_pref("extensions.BabylonToolbar_i), ,[1e4704b70d7df640ae57ef9610f649b7]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end)
--------------------------------------------------------------------------------------
Nun AdwCleaner: Code:
AdwCleaner Logfile:
Code:
# AdwCleaner v4.206 - Bericht erstellt 16/06/2015 um 21:02:32
# Aktualisiert 01/06/2015 von Xplode
# Datenbank : 2015-06-16.1 [Server]
# Betriebssystem : Windows Vista (TM) Home Basic Service Pack 2 (x86)
# Benutzername : Anja - ANJA-PC
# Gestarted von : C:\Users\Anja\Downloads\AdwCleaner_4.206.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Conduit
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\ProgramData\TubeDimmer
Ordner Gelöscht : C:\ProgramData\KingSoft
Ordner Gelöscht : C:\Program Files\DVDVideoSoftTB_DE
Ordner Gelöscht : C:\Program Files\FlvPlayer
Ordner Gelöscht : C:\Program Files\GreenTree Applications
Ordner Gelöscht : C:\Program Files\SearchProtect
Ordner Gelöscht : C:\Program Files\KingSoft
Ordner Gelöscht : C:\Program Files\Optimizer Pro
Ordner Gelöscht : C:\Users\Anja\AppData\Local\Babylon
Ordner Gelöscht : C:\Users\Anja\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Anja\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Anja\AppData\Local\KingSoft
Ordner Gelöscht : C:\Users\Anja\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Anja\AppData\LocalLow\DVDVideoSoftTB_DE
Ordner Gelöscht : C:\Users\Anja\AppData\LocalLow\mySecureSurfer
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\BabylonToolbar
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Solvusoft
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\KingSoft
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat
[!] Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi
Ordner Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{d64e478d-4dee-4bfb-afe4-30b84e6a3157}
Datei Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{C50CA3C4-5656-43C2-A061-13E717F73FC8}.xpi
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\system32\roboot.exe
Datei Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\invalidprefs.js
Datei Gelöscht : C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : LaunchSignup
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\agabegcgoagbgcpiegohpamfdpcnmfba
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\bhphemoobgnikcoofkgackkaimpfmenm
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bhphemoobgnikcoofkgackkaimpfmenm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\inetstat.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{07AD74F3-2AF5-4D6D-9755-6E5A8BDF9E7F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{52EA1989-D16E-4560-9021-F0AD247DE4D1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{52EA1989-D16E-4560-9021-F0AD247DE4D1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{52EA1989-D16E-4560-9021-F0AD247DE4D1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07AD74F3-2AF5-4D6D-9755-6E5A8BDF9E7F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{52EA1989-D16E-4560-9021-F0AD247DE4D1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{87EAB409-97D7-4889-ACFA-C548FC6F3ECF}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKCU\Software\MGShareware
Schlüssel Gelöscht : HKCU\Software\Microsoft\Babylon
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Babylon
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\MGShareware
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\InetStat
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83AA2913-C123-4146-85BD-AD8F93971D39}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\InetStat
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RegClean-Pro_is1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinThruster_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\3192AA38321C641458DBDAF83979D193
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\3192AA38321C641458DBDAF83979D193
Daten Gelöscht : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:52068;hxxps=127.0.0.1:52068
Daten Gelöscht : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1
Daten Gelöscht : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
***** [ Internetbrowser ] *****
-\\ Internet Explorer v9.0.8112.16659
-\\ Mozilla Firefox v36.0.3 (x86 de)
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.SavedHomepage", "hxxp://search.conduit.com/?ctid=CT3316068&octid=CT3316068&SearchSource=61&CUI=UN20141627741223012&UM=2&UP=SP56EB409F-B793-4175-BC62-D26A39CF877F");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.SearchCaption", "DVDVideoSoftTB DE Customized Web Search");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.SearchInNewTabURLFromSearchAPI", "hxxp://search.conduit.com/?ctid=CT2625848&octid=CT2625848&SearchSource=15&CUI=SB_CUI&SSPV=EB_SSPV&Lay=1&UM=UM_ID");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2625848&SearchSource=13");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2625848");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT2625848.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3316068&SearchSource=2&CUI=UN20141627741223012&UM=2&q=");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.embeddedsData", "[{\"appId\":\"130250223751191786\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.installType", "conduitnsisintegration");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3316068&octid=CT3316068&SearchSource=15&CUI=UN20141627741223012&SSPV=&Lay=1&UM=2\"}");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.mam_gk_appState_PiclickV2-WebSearch.enc", "b24=");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.smartbar.CTID", "CT3316068");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.smartbar.Uninstall", "0");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.smartbar.homepage", "true");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CT3316068.smartbar.toolbarName", "SweetPacks A8 ");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2625848&SearchSource=13");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ConduitSearchList", "DVDVideoSoftTB DE Customized Web Search");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2625848", "\"1367226749\"");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.20.0.4", "\"9f8d2729abc2ce1:0\"");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2625848", "\"9971ee9815a5fc569766cf6ddcaaca8e\"");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=de", "\"79f374394c38516c56ea9141bca29732\"");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3316068&SearchSource=2&CUI=UN20141627741223012&UM=2&q=");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ToolbarsList", "CT2625848");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ToolbarsList2", "CT2625848");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.ToolbarsList4", "CT2625848");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.globalUserId", "39002d45-9e3e-4ffe-a25e-5812dd94caf4");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2625848");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3316068&octid=CT3316068&SearchSource=61&CUI=UN20141627741223012&UM=2&UP=SP56EB409F-B793-4175-BC62-D26A39CF877F");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("CommunityToolbar.originalSearchEngine", "SweetPacks A8 Customized Web Search");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.ConduitHomepagesList", "");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.ConduitSearchEngineList", "");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.ConduitSearchUrlList", "");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT3316068");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultenginename", "DVDVideoSoftTB DE Customized Web Search");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultthis.engineName", "DVDVideoSoftTB DE Customized Web Search");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "DVDVideoSoftTB DE Customized Web Search");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.babExt", "");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.hardId", "fe4daf1a00000000000000ff79c56aa8");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.id", "fe4daf1a00000000000000ff79c56aa8");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.instlDay", "15463");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1714:06:25");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.admin", false);
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.aflt", "babsst");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.dfltLng", "en");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.excTlbr", false);
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.id", "fe4daf1a00000000000000ff79c56aa8");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.instlDay", "15562");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.instlRef", "sst");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.prdct", "claro");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.prtnrId", "claro");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.tlbrId", "claro");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.vrsn", "1.6.4.1");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro.vrsni", "1.6.4.1");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro_i.smplGrp", "none");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.claro_i.vrsnTs", "1.6.4.120:37:58");
[yaiw8gqm.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.proxytool.referers", "www.google.com,google.com,smallseotools.com,yahoo.com,bing.com,ask.com,currate.com,facebook.com,twitter.com,craigslist.org");
-\\ Google Chrome v43.0.2357.124
[C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&tt=010412_crm&babsrc=SP_crm
[C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN10104650612083217&ctid=CT3316068&UM=2
*************************
AdwCleaner[R0].txt - [18930 Bytes] - [16/06/2015 20:53:26]
AdwCleaner[S0].txt - [19286 Bytes] - [16/06/2015 21:02:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19346 Bytes] ########## --- --- --- -----------------------------------------------------------------------------------------
Junkmove-Removal: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.9.9 (06.16.2015:2)
OS: Windows Vista (TM) Home Basic x86
Ran by Anja on 16.06.2015 at 21:13:33.88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_50EA6731804A0FA2B2DE051BEA45E463
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Program Files\freerip3
Successfully deleted: [Folder] C:\ProgramData\freerip
Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\free window registry repair
Successfully deleted: [Folder] C:\Users\Anja\appdata\locallow\freerip
Successfully deleted: [Folder] C:\Users\Anja\AppData\Roaming\microsoft\windows\start menu\programs\free window registry repair
~~~ FireFox
~~~ Chrome
[C:\Users\Anja\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Anja\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Anja\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Anja\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
dhkplhfnhceodhffomolpfigojocbpcb,
mhkaekfpcppmmioggniknbnbdbcigpkk
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.06.2015 at 21:17:31.07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ---------------------------------------------------------------------------------------
Und zu guter Letzt noch ein frisches FRST.txt:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-06-2015
Ran by Anja (administrator) on ANJA-PC on 16-06-2015 21:23:55
Running from C:\Users\Anja\Downloads
Loaded Profiles: Anja (Available Profiles: Anja)
Platform: Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Bitdefender) C:\Program Files\Bitdefender\60-Second Virus Scanner\pdscan.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2008-10-31] (Realtek Semiconductor Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6609440 2008-10-31] (Realtek Semiconductor)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1994752 2014-02-20] (Wondershare)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\...\Run: [pdiface] => C:\Program Files\Bitdefender\60-Second Virus Scanner\pdiface.exe [261984 2013-10-30] (Bitdefender)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\...\Run: [GUDelayStartup] => C:\Program Files\Glary Utilities 5\StartupManager.exe [37152 2015-05-25] (Glarysoft Ltd)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\...\Run: [GoogleChromeAutoLaunch_50EA6731804A0FA2B2DE051BEA45E463] => C:\Program Files\Google\Chrome\Application\chrome.exe [813896 2015-06-05] (Google Inc.)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [704512 2009-04-11] (Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Picasa Media Detector] => C:\Program Files\Picasa2\PicasaMediaDetector.exe [443968 2008-02-26] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2013-08-15]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-809830661-3849426339-1780571292-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-809830661-3849426339-1780571292-1000 -> {443789B7-F39C-4b5c-9287-DA72D38F4FE6} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-23] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-23] (Oracle Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 80.69.100.102 80.69.100.230
FireFox:
========
FF ProfilePath: C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default
FF Homepage: about:home
FF NetworkProxy: "ftp", "123.110.49.119"
FF NetworkProxy: "ftp_port", 8088
FF NetworkProxy: "gopher", "5.135.193.216"
FF NetworkProxy: "gopher_port", 8089
FF NetworkProxy: "http", "123.110.49.119"
FF NetworkProxy: "http_port", 8088
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "socks", "123.110.49.119"
FF NetworkProxy: "socks_port", 8088
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "123.110.49.119"
FF NetworkProxy: "ssl_port", 8088
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-20] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Picasa2\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-23] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2015-04-30] (Adobe Systems Inc.)
FF Extension: FoxyProxy Standard - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\foxyproxy@eric.h.jung [2015-03-23]
FF Extension: Youtube Downloader - 4K Download - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\paulsaintuzb@gmail.com [2015-03-06]
FF Extension: No Name - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{0b5130a9-cc50-4ced-99d5-cda8cc12ae48} [2013-12-16]
FF Extension: Proxy-Listen.de - Proxyswitcher - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\admin@proxy-listen.de.xpi [2012-09-27]
FF Extension: Best Proxy Switcher - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\bestproxyswitcher@bestproxyswitcher.com.xpi [2014-07-08]
FF Extension: Elite Proxy Switcher - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\eliteproxyswitcher@my-proxy.com.xpi [2015-03-21]
FF Extension: Video Downloader Professional - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\ffext_basicvideoext@startpage24.xpi [2013-10-25]
FF Extension: ZenMate Security & Privacy VPN - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\firefox@zenmate.com.xpi [2015-03-21]
FF Extension: Awesome screenshot: Capture and Annotate - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack.xpi [2014-04-12]
FF Extension: Translate This! - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\jid0-k75TfRGfOXPHfEZmJ9cKu5eCgLc@jetpack.xpi [2013-11-06]
FF Extension: One Click Proxy - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\jid0-zXo3XFGyiDalgkeEO4UYJTUwo2I@jetpack.xpi [2014-07-08]
FF Extension: Nimbus Screen Capture - editable screenshots. - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\nimbusscreencaptureff@everhelper.me.xpi [2014-02-02]
FF Extension: Priv3+ - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\priv3plus@icsi.berkeley.edu.xpi [2015-03-21]
FF Extension: Proxy Tool - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\proxytool@proxylist.co.xpi [2012-12-11]
FF Extension: Google Translator for Firefox - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\translator@zoli.bod.xpi [2013-11-06]
FF Extension: Casino Toolbar - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\wagerlogic.xpi [2012-05-15]
FF Extension: ImTranslator - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2012-04-26]
FF Extension: Adblock Plus - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-06-20]
FF Extension: QuickProxy - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\Extensions\{d5ea4520-61a1-11da-8cd6-0800200c9a66}.xpi [2014-07-08]
FF Extension: Hotspot Shield Helper (Please allow this installation) - C:\Program Files\Mozilla Firefox\extensions\afurladvisor@anchorfree.com [2015-03-21]
FF Extension: Word Layers - C:\Program Files\Mozilla Firefox\extensions\ugnraew@jqhljqmpngx.net [2015-03-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-04-26]
FF Extension: No Name - C:\Users\Anja\AppData\Roaming\Mozilla\Firefox\Profiles\yaiw8gqm.default\extensions\support@tubedimmerapp.com [not found]
Chrome:
=======
CHR Profile: C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-15]
CHR Extension: (Google Docs) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-15]
CHR Extension: (Google Drive) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-15]
CHR Extension: (Webpage Screenshot) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdfnieppndfdhcgbmhfdlgdjegclkomk [2015-03-01]
CHR Extension: (YouTube) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-15]
CHR Extension: (Google Search) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-15]
CHR Extension: (CyberGhost VPN - Free Proxy) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcbnikgemihknccdjaihjnfbapinljpi [2015-04-06]
CHR Extension: (ZenMate Security, Privacy & Unblock VPN) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2015-03-30]
CHR Extension: (Google Sheets) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-15]
CHR Extension: (AdBlock) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-06-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-14]
CHR Extension: (Google Wallet) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-03]
CHR Extension: (Gmail) - C:\Users\Anja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-15]
CHR HKLM\...\Chrome\Extension: [aobbhmkkplckkcbnbcdbkneemiooegoc] - No Path Or update_url value
CHR HKU\S-1-5-21-809830661-3849426339-1780571292-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [aobbhmkkplckkcbnbcdbkneemiooegoc] - No Path Or update_url value
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [57520 2013-10-23] (Bitdefender)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-01-25] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-01-25] (Hewlett-Packard Co.) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 pdserv; C:\Program Files\Bitdefender\60-Second Virus Scanner\pdscan.exe [1221384 2013-11-11] (Bitdefender)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
S2 TestHandler; C:\Program Files\Fujitsu\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe [341264 2009-02-19] (Fujitsu Technology Solutions)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [173576 2008-05-27] (AMD Technologies Inc.)
R0 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [21576 2013-03-07] (AVAST Software)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [633344 2013-04-17] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [486536 2013-04-17] (BitDefender)
R1 bdftdif; C:\Program Files\Bitdefender\Antivirus Free Edition\bdftdif.sys [148600 2013-04-17] (Bitdefender SRL)
R1 bdselfpr; C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys [135472 2013-07-16] (BitDefender LLC)
R1 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [164952 2013-04-22] (BitDefender LLC)
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [76688 2008-04-03] (JMicron Technology Corp.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-06-16] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [355744 2013-05-28] (BitDefender S.R.L.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Anja\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS [X]
S3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS [X]
S1 SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS [X]
S3 taphss; system32\DRIVERS\taphss.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-16 21:23 - 2015-06-16 21:24 - 00018069 _____ C:\Users\Anja\Downloads\FRST.txt
2015-06-16 21:23 - 2015-06-16 21:23 - 00000000 ____D C:\Users\Anja\Downloads\FRST-OlderVersion
2015-06-16 21:17 - 2015-06-16 21:17 - 00001746 _____ C:\Users\Anja\Desktop\JRT.txt
2015-06-16 21:13 - 2015-06-16 21:13 - 00000207 _____ C:\Windows\tweaking.com-regbackup-ANJA-PC-Windows-Vista-(TM)-Home-Basic-(32-bit).dat
2015-06-16 21:13 - 2015-06-16 21:13 - 00000000 ____D C:\RegBackup
2015-06-16 21:12 - 2015-06-16 21:12 - 02945901 _____ (Thisisu) C:\Users\Anja\Downloads\JRT.exe
2015-06-16 20:52 - 2015-06-16 21:04 - 00000000 ____D C:\AdwCleaner
2015-06-16 20:51 - 2015-06-16 20:51 - 02231296 _____ C:\Users\Anja\Downloads\AdwCleaner_4.206.exe
2015-06-16 20:43 - 2015-06-16 20:43 - 00042979 _____ C:\Users\Anja\Documents\Malware Scan.txt
2015-06-16 20:36 - 2015-06-16 20:36 - 00042999 _____ C:\Users\Anja\Documents\Malware 201 Bedrohungen gefunden.txt
2015-06-16 18:50 - 2015-06-16 18:52 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-16 18:50 - 2015-06-16 18:50 - 00000865 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-16 18:50 - 2015-06-16 18:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-16 18:50 - 2015-06-16 18:50 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-06-16 18:50 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-16 18:50 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-16 18:50 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-16 18:45 - 2015-06-16 18:49 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Anja\Downloads\mbam-setup-2.1.6.1022.exe
2015-06-15 20:39 - 2015-06-15 20:39 - 00000000 ____D C:\Users\Anja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-15 20:34 - 2015-06-15 20:34 - 00035696 _____ C:\ComboFix.txt
2015-06-15 20:25 - 2015-06-16 21:06 - 00001302 _____ C:\Windows\PFRO.log
2015-06-15 20:10 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-06-15 20:10 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-06-15 20:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-06-15 20:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-06-15 20:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-06-15 20:10 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-06-15 20:10 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-06-15 20:10 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-06-15 20:09 - 2015-06-15 20:35 - 00000000 ____D C:\Qoobox
2015-06-15 20:09 - 2015-06-15 20:31 - 00000000 ____D C:\Windows\erdnt
2015-06-15 20:04 - 2015-06-15 20:04 - 05628161 ____R (Swearware) C:\Users\Anja\Downloads\ComboFix.exe
2015-06-14 17:15 - 2015-06-14 17:15 - 00015762 _____ C:\Users\Anja\Downloads\Sparda Bank Kapitalerträge.tif
2015-06-14 16:30 - 2015-06-14 16:30 - 00001023 _____ C:\Users\Anja\Desktop\Revo Uninstaller.lnk
2015-06-14 16:30 - 2015-06-14 16:30 - 00000000 ____D C:\Program Files\VS Revo Group
2015-06-14 16:27 - 2015-06-14 16:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Anja\Downloads\revosetup95.exe
2015-06-11 18:08 - 2015-06-11 18:09 - 00030501 _____ C:\Users\Anja\Downloads\Addition.txt
2015-06-11 18:06 - 2015-06-16 21:23 - 01148416 _____ (Farbar) C:\Users\Anja\Downloads\FRST.exe
2015-06-11 18:06 - 2015-06-16 21:23 - 00000000 ____D C:\FRST
2015-06-11 16:47 - 2015-05-21 16:22 - 02066432 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-11 16:47 - 2015-05-09 01:08 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-11 16:47 - 2015-04-24 17:54 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-11 16:34 - 2015-06-11 16:47 - 00000000 ____D C:\Windows\system32\MRT
2015-06-11 16:29 - 2015-05-05 00:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-11 16:28 - 2015-05-05 00:51 - 10628608 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-11 16:28 - 2015-05-05 00:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-11 16:28 - 2015-05-05 00:50 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-11 16:28 - 2015-05-04 23:21 - 08147456 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 10:46 - 2015-06-10 10:46 - 00000000 ____D C:\Program Files\NoVirusThanks
2015-06-10 10:45 - 2015-06-10 10:45 - 01937000 _____ (NoVirusThanks Company Srl ) C:\Users\Anja\Downloads\filegovernor Löschdatei_setup.exe
2015-06-10 09:40 - 2015-05-31 01:54 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 09:40 - 2015-05-31 01:53 - 09750528 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 09:40 - 2015-05-31 01:50 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 09:40 - 2015-05-31 01:49 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 09:40 - 2015-05-31 01:49 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 09:40 - 2015-05-31 01:49 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 09:40 - 2015-05-31 01:49 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 09:40 - 2015-05-31 01:48 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 09:40 - 2015-05-31 01:48 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-06-10 09:40 - 2015-05-31 01:47 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 09:40 - 2015-05-31 01:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 09:40 - 2015-05-31 01:47 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-06-10 09:40 - 2015-05-31 01:47 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-06-10 09:39 - 2015-05-31 02:03 - 12385280 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 09:39 - 2015-05-31 01:55 - 01809920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 09:39 - 2015-05-31 01:47 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-09 19:06 - 2015-06-10 09:56 - 00000000 ____D C:\Program Files\Unlocker
2015-06-09 13:18 - 2015-06-09 13:21 - 00000000 ____D C:\Users\Anja\Documents\Sparda Bank Fax Kapitalerträge
2015-06-09 13:15 - 2015-06-11 17:03 - 00000000 ____D C:\Users\Anja\Documents\Norisbank
2015-06-08 23:23 - 2015-06-08 23:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-06-08 23:19 - 2015-06-08 23:22 - 36499753 _____ ( ) C:\Users\Anja\Downloads\K-Lite_Codec_Pack_1120_Full.exe
2015-06-08 20:09 - 2015-06-08 20:11 - 14929318 _____ ( ) C:\Users\Anja\Downloads\klcp_update_1121_20150605.exe
2015-06-05 16:41 - 2015-06-05 16:41 - 00000855 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2015-06-05 16:41 - 2015-06-05 16:41 - 00000843 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk
2015-06-05 16:41 - 2015-06-05 16:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2015-06-05 16:40 - 2015-06-05 16:40 - 00017472 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys
2015-06-05 16:37 - 2015-06-05 16:37 - 15121936 _____ C:\Users\Anja\Downloads\Glary_Utilities_v5.26.0.45.exe
2015-05-28 18:22 - 2015-05-29 22:04 - 00000000 ____D C:\Users\Anja\Documents\Roulette-Pilot Kopien nach Test
2015-05-25 17:06 - 2015-05-25 17:06 - 00242504 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2015-05-24 23:56 - 2015-05-25 00:09 - 00000000 ____D C:\Users\Anja\Documents\Roulette-Pilot Werbepause
2015-05-24 23:24 - 2015-05-24 23:24 - 00001973 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Free Edition.lnk
2015-05-24 23:24 - 2015-05-24 23:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
2015-05-24 23:22 - 2013-04-17 14:59 - 00633344 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2015-05-24 23:22 - 2013-04-17 14:59 - 00486536 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2015-05-24 23:22 - 2009-07-14 23:27 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2015-05-24 23:21 - 2013-05-28 12:11 - 00355744 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2015-05-24 23:21 - 2013-04-22 13:20 - 00164952 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2015-05-24 23:20 - 2015-05-24 23:21 - 00000000 ____D C:\Users\Anja\AppData\Roaming\QuickScan
2015-05-24 23:20 - 2015-05-24 23:20 - 09927424 _____ C:\Users\Anja\Downloads\Antivirus_Free_Edition_x86.exe
2015-05-24 23:19 - 2015-05-24 23:19 - 00162208 _____ C:\Users\Anja\Downloads\Antivirus_Free_Edition.exe
2015-05-24 23:07 - 2015-05-24 23:24 - 00000000 ____D C:\Program Files\Bitdefender
2015-05-24 23:07 - 2015-05-24 23:07 - 31571808 _____ C:\Users\Anja\Downloads\60Second_x86.exe
2015-05-24 23:07 - 2015-05-24 23:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 60-Second Virus Scanner
2015-05-24 23:07 - 2015-05-24 23:07 - 00000000 ____D C:\ProgramData\Bitdefender
2015-05-24 23:06 - 2015-05-24 23:06 - 00160160 _____ C:\Users\Anja\Downloads\60Second_en_us.exe
2015-05-22 18:32 - 2015-05-22 18:32 - 00000000 _____ C:\Users\Anja\AppData\Local\{4B2FA74C-8229-4EA3-8FB0-5E96B272257C}
2015-05-21 20:13 - 2015-05-31 21:12 - 00000000 ____D C:\Users\Anja\Documents\Roulette Pilot Verschiedene Systeme
2015-05-21 14:00 - 2015-05-21 14:00 - 00000000 _____ C:\Users\Anja\AppData\Local\{AFB11F1F-569B-4CE1-8BCC-931AA1DA58D8}
2015-05-20 19:04 - 2015-05-20 19:04 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-05-19 21:57 - 2015-05-19 21:57 - 00001643 _____ C:\Users\Anja\AppData\Roaming\Microsoft\Windows\Start Menu\Titanbet Casino.lnk
2015-05-19 21:57 - 2015-05-19 21:57 - 00001641 _____ C:\Users\Anja\Desktop\Titanbet Casino.lnk
2015-05-19 21:56 - 2015-05-19 21:57 - 00000000 ____D C:\Users\Anja\AppData\Local\Titanbet Casino
2015-05-19 20:04 - 2015-05-19 20:04 - 00000000 ____D C:\Users\Anja\AppData\Roaming\Betvoyager
2015-05-19 20:02 - 2015-05-19 20:03 - 58089440 _____ (Betvoyager N.V. ) C:\Users\Anja\Downloads\Betvoyager Casino.exe
2015-05-17 16:41 - 2015-05-17 16:41 - 02592768 _____ C:\Users\Anja\Downloads\Install_RoulettePilot.msi
2015-05-17 15:48 - 2015-05-17 15:48 - 00001637 _____ C:\Users\Anja\AppData\Roaming\Microsoft\Windows\Start Menu\Betfair Casino.lnk
2015-05-17 15:48 - 2015-05-17 15:48 - 00001635 _____ C:\Users\Anja\Desktop\Betfair Casino.lnk
2015-05-17 15:24 - 2015-05-17 15:24 - 00000000 ____D C:\Users\Anja\AppData\Roaming\GlarySoft
2015-05-17 15:24 - 2015-05-17 15:24 - 00000000 ____D C:\Users\Anja\AppData\Roaming\DiskDefrag
2015-05-17 15:23 - 2015-06-16 21:08 - 00000000 ____D C:\Program Files\Glary Utilities 5
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-16 21:17 - 2015-05-06 21:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-16 21:16 - 2006-11-02 14:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-06-16 21:16 - 2006-11-02 14:45 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-06-16 21:14 - 2012-04-25 19:03 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-16 21:11 - 2012-04-25 17:53 - 01528099 _____ C:\Windows\WindowsUpdate.log
2015-06-16 21:06 - 2012-04-25 19:03 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-16 21:06 - 2006-11-02 14:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-16 21:05 - 2006-11-02 14:58 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-06-16 20:28 - 2012-05-01 21:03 - 00000360 _____ C:\Windows\Tasks\WpsUpdateTask_Anja.job
2015-06-15 20:35 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default
2015-06-15 20:34 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2015-06-15 20:28 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini
2015-06-12 16:48 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2015-06-12 16:28 - 2006-11-02 14:44 - 00295896 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 20:54 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2015-06-11 16:33 - 2006-11-02 12:24 - 136900096 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-06-11 16:29 - 2013-11-09 12:22 - 00000000 ____D C:\Users\Anja\Documents\Meine Scans
2015-06-10 20:08 - 2014-05-02 12:47 - 03691624 _____ (MetaQuotes Software Corp.) C:\Windows\system32\MetaViewer.dll
2015-06-10 15:17 - 2012-05-03 15:32 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-06-10 15:17 - 2012-05-03 15:32 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-06-10 10:19 - 2014-07-09 20:33 - 00001929 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-09 18:01 - 2012-06-19 20:30 - 00000000 ____D C:\Users\Anja\AppData\Roaming\vlc
2015-06-08 23:23 - 2015-05-11 19:31 - 00000000 ____D C:\Program Files\K-Lite Codec Pack
2015-06-06 23:08 - 2012-04-28 16:52 - 00000000 ____D C:\Users\Anja\Documents\Roulettesysteme
2015-05-25 17:18 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool
2015-05-25 17:14 - 2014-05-24 12:33 - 00000000 ____D C:\Program Files\Common Files\G Data
2015-05-25 17:14 - 2013-04-26 19:25 - 00000000 ____D C:\ProgramData\G Data
2015-05-24 23:23 - 2012-04-25 18:06 - 00000000 ____D C:\Users\Anja
2015-05-21 19:54 - 2015-05-08 21:06 - 00000000 ____D C:\Users\Anja\AppData\Local\EuroGrand Casino
2015-05-20 14:56 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2015-05-20 11:07 - 2014-08-17 15:49 - 00000000 ____D C:\Users\Anja\AppData\Local\Adobe
2015-05-19 14:52 - 2013-08-16 18:26 - 00000000 ____D C:\Users\Anja\AppData\Roaming\HpUpdate
2015-05-17 15:48 - 2015-05-03 20:02 - 00000000 ____D C:\Users\Anja\AppData\Local\Betfair Casino
2015-05-17 15:30 - 2013-03-24 15:01 - 00000000 ____D C:\Windows\Minidump
==================== Files in the root of some directories =======
2014-05-22 20:13 - 2014-05-22 20:13 - 0000000 _____ () C:\Users\Anja\AppData\Roaming\gdfw.log
2014-05-22 20:12 - 2014-05-24 12:35 - 0000976 _____ () C:\Users\Anja\AppData\Roaming\gdscan.log
2014-09-08 19:28 - 2015-01-06 14:29 - 0000680 _____ () C:\Users\Anja\AppData\Local\d3d9caps.dat
2013-05-06 15:23 - 2013-05-06 15:23 - 0001483 _____ () C:\Users\Anja\AppData\Local\recently-used.xbel
2015-05-22 18:32 - 2015-05-22 18:32 - 0000000 _____ () C:\Users\Anja\AppData\Local\{4B2FA74C-8229-4EA3-8FB0-5E96B272257C}
2015-05-21 14:00 - 2015-05-21 14:00 - 0000000 _____ () C:\Users\Anja\AppData\Local\{AFB11F1F-569B-4CE1-8BCC-931AA1DA58D8}
2013-08-15 17:54 - 2015-02-12 13:45 - 0005078 _____ () C:\ProgramData\hpzinstall.log
2012-04-26 17:55 - 2012-04-26 17:55 - 0000107 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-06-12 20:57 - 2012-06-12 20:57 - 0001534 _____ () C:\ProgramData\ss.ini
Some files in TEMP:
====================
C:\Users\Anja\AppData\Local\Temp\Quarantine.exe
C:\Users\Anja\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-16 21:18
==================== End of log ============================ --- --- ---
Gruß,
Ecart |