Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Firefox stürzt ständig ab

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 11.05.2014, 18:27   #1
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo,

da ihr mir schon ein paar Mal super geholfen habt, wende ich mich nun erneut mit einem Problem an euch und würde mich freuen, falls ihr mir weiterhelfen könnt.
Ich benutze als Internetnavigator Mozilla Firefox, leider stürzt dieser nun seit längerem immer öfter ab - meine Überlegung ist, ob ein Virus oder ein Trojaner daran schuld sein könnte, deswegen stelle ich meine Frage hier im Forum.
Es kommt nun schon seit einiger Zeit vor, dass sich Firefox nach einiger Zeit blockiert (mind. 1 - 2 am Tag, Tendenz steigend) und meist nicht mehr reagiert - oder er stürzt einfach sofort ab und es kommt diese Entschuldigungsmeldung von Firefox (Entschuldigung, das hätte nicht passieren dürfen). Falls sich die geöffneten Seiten nicht mehr herstellen lassen, ist der Datenverlust für mich jedes Mal relativ groß, da ich viel im Internet recherchieren muss und daher meist viele Seiten geöffnet habe (aber nicht mehr als früher, Überlastung sollte eigentlich als Grund ausscheiden).
Seit einigen Tagen gibt es nun auch eine neue Variante: Firefox wird einfach schwarz (der komplette Bildschirm ist schwarz - andere Anwendungen funktionieren), dann stellen sich nach und nach Elemente der jeweiligen Internetseiten wieder her. Auch in diesem Fall muss ich Firefox komplett schließen und den PC neustarten, da Firefox nicht mehr richtig funktioniert.
Außerdem stürzt auch des öfteren der Adobe Flashplayer ab, wenn ich online Videos schaue (dann stürzt Firefox oft auch mit ab) - ob dies nun jedoch mit dem zuvor geschilderten Problem zusammenhängt, weiß ich nicht.

Mein System:
Windows 7, 64bit
Internet: Firefox (habe ich regelmäßig abgedatet, ebenso Adobe Flashplayer)
Virenprogramm: Avast

Im folgenden würde ich nun die Ergebnisse der Scans laut Board-Anleitung posten:

Defogger:

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 18:51 on 11/05/2014 (Libelle)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-


FRST:

frst.text
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014
Ran by Libelle (administrator) on PC on 11-05-2014 18:53:25
Running from C:\Users\Libelle\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdat-ed.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
(Informatic Ltd.) C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & De-stroy\SDWinSec.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUsb\XFastUsb.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Pan-el\VolPanlu.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Geek Software GmbH) E:\Programme\PDF24\pdf24.exe
(Adobe Systems Inc.) E:\Programme\Adobe Pro\Acrobat\acrotray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Compo-nents\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Compo-nents\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office 2010\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\AmbRunE.dll [17920 2009-02-26] (Creative Technology Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3019376 2011-02-22] (VIA)
HKLM-x32\...\Run: [XFastUsb] => C:\Program Files (x86)\XFastUsb\XFastUsb.exe [4942336 2012-04-18] (FNet Co., Ltd.)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office 2010\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incor-porated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Soft-ware\Avast\AvastUI.exe [3873704 2014-04-26] (AVAST Software)
HKLM-x32\...\Run: [PDFPrint] => E:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Programme\Adobe Pro\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4118839908-2255762619-2302489997-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKU\S-1-5-21-4118839908-2255762619-2302489997-1000\...\MountPoints2: {34f6a3cb-904a-11e1-98fa-002522ce01c6} - F:\LaunchU3.exe -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ORFO Agent.lnk
ShortcutTarget: ORFO Agent.lnk -> C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe (Informatic Ltd.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.delta-search.com/?babsrc=HP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://at.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3097DBB87D1DCD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache Accept-Langs = de-at
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013
SearchScopes: HKCU - DefaultScope {E17E02ED-3C1F-4989-A889-B0611CDF9C26} URL = http://search.softonic.com/MOY00006/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=fce15e28000000000000002522ce01c6&r=71
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968
SearchScopes: HKCU - {D4DC2C6E-7CE3-47a9-9224-D11F8999EB99} URL = http://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms}
SearchScopes: HKCU - {E17E02ED-3C1F-4989-A889-B0611CDF9C26} URL = http://search.softonic.com/MOY00006/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=fce15e28000000000000002522ce01c6&r=71
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corpora-tion)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorpo-rated)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Mi-crosoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorpo-rated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Dragon NaturallySpeaking Rich Internet Application Support - Extension - {73A89C60-CF59-4EC7-9215-9B7EF05ECEA4} - E:\Dragon Naturally Speaking 12 Deutsch\Program\ieShim.dll (Nuance Communications, Inc.)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorpo-rated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh\Softonic.dll (Softonic.com)
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorpo-rated)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Fi-les\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorpora-ted)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicTlbr.dll (Softonic.com)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Fi-les\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Cor-poration)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{EDEF3BBF-1341-4E63-9148-8934BB617129}: [NameSer-ver]130.244.127.161,130.244.127.169

FireFox:
========
FF ProfilePath: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default
FF user.js: detected! => C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js
FF Homepage: www.google.at | www.pons.eu
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Fi-les\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Fi-les\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silver-light\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Fi-les\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.669 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - E:\Programme\Adobe Pro\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Fi-les\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: nuance.com/DragonRIAPlugin - E:\DRAGON~4\Program\npDgnRia.dll (Nuance Communications Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla fire-fox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\softonic.xml
FF SearchPlugin: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla fire-fox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla fire-fox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla fire-fox\browser\searchplugins\yahoo-de.xml
FF Extension: Разпознаване на устройство Logitech - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\DeviceDetection@logitech.com [2012-04-19]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012-04-19]
FF Extension: Flash and Video Download - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2014-04-25]
FF Extension: Adobe DLM (powered by getPlus(R)) - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2012-04-19]
FF Extension: Classic Theme Restorer - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-10]
FF Extension: Advertising Cookie Opt-out - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\optout@google.com.xpi [2013-02-07]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-20]
FF Extension: Adblock Plus - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-02-07]
FF Extension: Menu Editor - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi [2012-04-19]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: No Name - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-06-24]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Soft-ware\Avast\WebRep\FF [2012-04-19]
FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi
FF Extension: No Name - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi [2013-02-11]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn [2014-04-22]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Softonic Chrome Toolbar) - C:\Users\Libelle\AppData\Local\Google\Chrome\User Da-ta\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-06-18]
CHR HKCU\...\Chrome\Extension: [gaiilaahiahdejapggenmdmafpmbipje] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-06-18]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - E:\Programme\Adobe Pro\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21]
CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonic.crx [2013-05-01]
CHR HKLM-x32\...\Chrome\Extension: [mikhcaiakabeeokmenglcdebplfdjicn] - E:\Dragon Naturally Speaking 12 Deutsch\Program\chromeShim.crx [2013-02-11]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-26] (AVAST Software)
S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & De-stroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-26] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-26] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-26] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-26] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-26] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-26] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-04-26] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-26] ()
S3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-11 18:53 - 2014-05-11 18:53 - 00022279 _____ () C:\Users\Libelle\Desktop\FRST.txt
2014-05-11 18:53 - 2014-05-11 18:53 - 00000000 ____D () C:\FRST
2014-05-11 18:51 - 2014-05-11 18:51 - 00000476 _____ () C:\Users\Libelle\Desktop\defogger_disable.log
2014-05-11 18:51 - 2014-05-11 18:38 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe
2014-05-11 18:50 - 2014-05-11 18:50 - 02066432 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe
2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable
2014-05-10 01:08 - 2014-05-10 01:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList
2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-05-07 18:24 - 2014-05-07 18:25 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-04 23:32 - 2014-05-11 18:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-04 23:32 - 2014-05-04 23:32 - 00692400 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-04 23:32 - 2014-05-04 23:32 - 00070832 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-04 23:32 - 2014-05-04 23:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-03 00:42 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-03 00:42 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-03 00:42 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-03 00:42 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-30 10:52 - 2014-04-30 10:52 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-30 08:58 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-30 08:58 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-29 23:43 - 2014-04-30 08:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex
2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-22 11:30 - 2014-04-26 09:51 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-04-22 11:30 - 2014-04-26 09:51 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-04-22 11:30 - 2014-04-26 09:51 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download As-sistant.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2014-04-11 01:04 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-11 01:04 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-11 01:04 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-11 01:04 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-11 01:04 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-11 01:04 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-11 01:04 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-11 01:04 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-11 01:04 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-11 01:04 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-11 01:04 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-11 01:04 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-11 01:04 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-11 01:04 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-11 01:04 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-11 01:04 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-11 01:04 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-11 01:04 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-11 01:04 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-11 01:04 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-11 01:04 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-11 01:04 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-11 01:04 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-11 01:04 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-11 01:04 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-11 01:04 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-11 01:04 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-11 01:04 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-11 01:04 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-11 01:04 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-11 01:04 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-11 01:04 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-11 01:04 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-11 01:04 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-11 01:04 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-11 01:04 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-11 01:04 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-11 01:04 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-11 01:04 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-11 01:04 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-11 01:04 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-11 01:04 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-11 01:04 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-11 01:04 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

==================== One Month Modified Files and Folders =======

2014-05-11 18:53 - 2014-05-11 18:53 - 00022279 _____ () C:\Users\Libelle\Desktop\FRST.txt
2014-05-11 18:53 - 2014-05-11 18:53 - 00000000 ____D () C:\FRST
2014-05-11 18:51 - 2014-05-11 18:51 - 00000476 _____ () C:\Users\Libelle\Desktop\defogger_disable.log
2014-05-11 18:50 - 2014-05-11 18:50 - 02066432 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe
2014-05-11 18:38 - 2014-05-11 18:51 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe
2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable
2014-05-11 18:38 - 2012-04-18 16:36 - 00000000 ____D () C:\Users\Libelle
2014-05-11 18:28 - 2014-05-04 23:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-11 18:27 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-11 18:27 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-11 18:26 - 2011-04-12 09:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-05-11 18:26 - 2011-04-12 09:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-05-11 18:26 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-11 18:23 - 2012-04-18 22:45 - 01453003 _____ () C:\Windows\WindowsUpdate.log
2014-05-11 18:20 - 2013-03-04 22:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-11 18:20 - 2012-07-17 22:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-11 18:20 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-11 18:20 - 2009-07-14 06:51 - 00163101 _____ () C:\Windows\setupact.log
2014-05-11 18:11 - 2013-03-04 22:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-11 12:45 - 2012-09-08 14:45 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Skype
2014-05-11 12:13 - 2012-05-03 11:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-11 01:23 - 2012-04-22 14:10 - 00000000 ____D () C:\Users\Libelle\Desktop\*****
2014-05-10 01:08 - 2014-05-10 01:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-09 11:06 - 2013-03-04 22:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-09 11:06 - 2013-03-04 22:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-09 01:17 - 2012-06-24 16:12 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\vlc
2014-05-08 15:32 - 2012-05-12 21:03 - 00000000 ____D () C:\Users\Libelle\AppData\Local\CrashDumps
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList
2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-05-07 18:25 - 2014-05-07 18:24 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-04 23:32 - 2014-05-04 23:32 - 00692400 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-04 23:32 - 2014-05-04 23:32 - 00070832 _____ (Adobe Systems Incorpo-rated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-04 23:32 - 2014-05-04 23:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-04 23:32 - 2012-04-19 11:29 - 00000000 ____D () C:\Downloads Program-me
2014-05-04 23:32 - 2012-04-18 18:46 - 00000000 ____D () C:\Users\Libelle\AppData\Local\Adobe
2014-05-04 23:30 - 2012-04-18 18:26 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-04-30 10:52 - 2014-04-30 10:52 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-30 08:59 - 2014-04-29 23:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-29 16:01 - 2014-05-03 00:42 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-03 00:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-03 00:42 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-03 00:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-27 11:32 - 2010-11-21 05:47 - 00893798 _____ () C:\Windows\PFRO.log
2014-04-26 23:03 - 2012-04-19 11:46 - 00000000 ____D () C:\Users\Libelle\Desktop\Utilities
2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-26 17:51 - 2014-03-22 22:35 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-26 17:51 - 2013-03-21 15:18 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-26 17:51 - 2013-03-21 15:18 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-26 17:51 - 2012-04-19 14:20 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-26 17:51 - 2012-04-19 14:20 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-26 17:51 - 2012-04-19 14:20 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-26 17:51 - 2012-04-19 14:20 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-26 17:51 - 2012-04-19 14:20 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-26 09:51 - 2014-04-22 11:30 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-04-26 09:51 - 2014-04-22 11:30 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-04-26 09:51 - 2014-04-22 11:30 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-04-26 09:48 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-22 17:40 - 2009-07-14 06:45 - 00399824 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-22 13:59 - 2012-04-18 23:36 - 00101920 _____ () C:\Users\Libelle\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex
2014-04-22 11:32 - 2012-04-18 18:26 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Adobe
2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-22 11:31 - 2012-04-18 18:26 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download As-sistant.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2014-04-20 01:57 - 2013-12-18 00:20 - 00000000 ____D () C:\Users\Libelle\Desktop\jin shin
2014-04-14 04:24 - 2014-04-30 08:58 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-30 08:58 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-12 13:36 - 2012-04-18 23:36 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-04-11 16:50 - 2013-06-13 16:03 - 00000000 ____D () C:\Windows\rescache
2014-04-11 15:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-11 01:05 - 2012-05-28 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-11 01:03 - 2013-07-25 11:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 01:02 - 2012-04-19 13:54 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Files to move or delete:
====================
C:\ProgramData\ezsid.dat


Some content of TEMP:
====================
C:\Users\Libelle\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Libelle\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Libelle\AppData\Local\Temp\vlc-2.1.3-win32.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-09 10:46

==================== End Of Log ============================
         

application.txt
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-05-2014
Ran by Libelle at 2014-05-11 18:53:50
Running from C:\Users\Libelle\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.06 - Adobe Systems)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.6 - Adobe Systems Incorporated)
Adobe Download Assistant (x32 Version: 1.2.6 - Adobe Systems Incorporated) Hid-den
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASRock App Charger v1.0.4 (HKLM\...\ASRock App Charger_is1) (Version:  - AS-Rock Inc.)
ASRock eXtreme Tuner v0.1.77 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version:  - )
ASRock InstantBoot v1.26 (HKLM-x32\...\ASRock InstantBoot_is1) (Version:  - )
avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2018 - Avast Software)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon iP4200 (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4200) (Version:  - )
Canon MG3100 series Benutzerregistrierung (HKLM-x32\...\Canon MG3100 series Benutzerregistrierung) (Version:  - )
Canon MG3100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3100_series) (Version:  - )
Canon MG3100 series On-screen Manual (HKLM-x32\...\Canon MG3100 series On-screen Manual) (Version:  - )
Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version:  - Microsoft)
Dragon NaturallySpeaking 12 (HKLM-x32\...\{D5D422B9-6976-4E98-8DDF-9632CB515D7E}) (Version: 12.50.000 - Nuance Communications Inc.)
FLV Player (HKCU\...\FLV Player) (Version:  - )
Free Studio version 2013 (HKLM-x32\...\Free Studio_is1) (Version: 6.1.8.725 - DVDVideoSoft Ltd.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Versi-on: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation)
Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (HKLM-x32\...\Office14.OMUI.pt-br) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - Portuguese/Português (HKLM-x32\...\Office14.OMUI.pt-pt) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - Spanish/Español (HKLM-x32\...\Office14.OMUI.es-es) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office O MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office O MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office O MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Versi-on: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Basque) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proof (Catalan) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proof (Galician) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corpo-ration) Hidden
Microsoft Office Proof (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Cor-poration) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Portuguese (Brazil)) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Portuguese (Portugal)) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Spanish) 2010 (Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Micro-soft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (Portuguese (Portugal)) 2010 (x32 Versi-on: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office X MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office X MUI (Portuguese (Portugal)) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office X MUI (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Ver-sion: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Micro-soft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Micro-soft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{cde5fd82-4a8f-483e-adf0-ca7343d00433}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Versi-on: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nero 12 (HKLM-x32\...\{80836C86-1305-40C9-B7C9-F3A75266070D}) (Version: 12.5.01900 - Nero AG)
Nero Audio Pack 1 (x32 Version: 11.0.11500.110.0 - Nero AG) Hidden
Nero BackItUp (x32 Version: 12.5.1000 - Nero AG) Hidden
Nero BackItUp Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden
Nero Blu-ray Player (x32 Version: 12.0.20014 - Nero AG) Hidden
Nero Blu-ray Player Help (CHM) (x32 Version: 12.0.9000 - Nero AG) Hidden
Nero Burning ROM (x32 Version: 12.5.5001 - Nero AG) Hidden
Nero Burning ROM Help (CHM) (x32 Version: 12.0.3000 - Nero AG) Hidden
Nero ControlCenter (x32 Version: 11.0.15600 - Nero AG) Hidden
Nero ControlCenter Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden
Nero Core Components (x32 Version: 11.0.20200 - Nero AG) Hidden
Nero Disc Menus Basic (x32 Version: 12.0.11500 - Nero AG) Hidden
Nero Effects Basic (x32 Version: 12.0.11500 - Nero AG) Hidden
Nero Express (x32 Version: 12.5.5002 - Nero AG) Hidden
Nero Express Help (CHM) (x32 Version: 12.0.13000 - Nero AG) Hidden
Nero Kwik Media (x32 Version: 1.18.20100 - Nero AG) Hidden
Nero Kwik Media Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden
Nero Kwik Themes Basic (x32 Version: 12.0.11500 - Nero AG) Hidden
Nero PiP Effects Basic (x32 Version: 12.0.11500 - Nero AG) Hidden
Nero Recode (x32 Version: 12.5.6000 - Nero AG) Hidden
Nero Recode Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden
Nero RescueAgent (x32 Version: 12.0.10002 - Nero AG) Hidden
Nero RescueAgent Help (CHM) (x32 Version: 12.0.7000 - Nero AG) Hidden
Nero SharedVideoCodecs (x32 Version: 1.0.12100.2.0 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11800.31.0 - Nero AG) Hidden
Nero Video (x32 Version: 12.5.2001 - Nero AG) Hidden
Nero Video Help (CHM) (x32 Version: 12.0.12000 - Nero AG) Hidden
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
Office-Bibliothek (HKLM-x32\...\{5C81B189-5456-40C4-9313-7FE6FA6DD64C}) (Version: 5.00.4 - Bibliographisches Institut & F.A. Brockhaus AG)
ORFO 9.0 (HKLM-x32\...\InstallShield_{FDEA11CF-BAF9-4EFE-AF7C-58EAB614A407}) (Version: 9.0 - Informatic)
ORFO 9.0 (HKLM-x32\...\Orfo) (Version:  - )
ORFO 9.0 (x32 Version: 9.0 - Informatic) Hidden
PDF24 Creator 6.3.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Platform (x32 Version: 1.36 - VIA Technologies, Inc.) Hidden
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Versi-on: 7.75.80.95 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.41.216.2011 - Realtek)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{1C7BD792-204F-49EB-BF0B-A0F9C904128D}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{95604CB2-E3F3-40FD-B90D-2DB0F144F4A2}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{18B9CFE9-6DD6-4C09-8146-F443DBBD62CF}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Ski Challenge 14 (HKCU\...\sc14-GAMETWIST_MAIN) (Version:  - )
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Ver-sion: 6.14.104 - Skype Technologies S.A.)
Softonic toolbar  on IE and Chrome (HKLM-x32\...\Softonic) (Version: 1.8.19.3 - Sof-tonic) <==== ATTENTION
Sound Blaster X-Fi MB (HKLM-x32\...\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}) (Version: 1.0 - Creative Technology Limited)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Tele2 Internet (x32 Version: 1.0 - Tele2UTA Telecommunication GmbH) Hidden
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0100-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OMUI.es-es_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.pt-br_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.es-es_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.pt-br_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{956FF6E4-8BBB-4B9A-9279-8A34D8C1FF9D}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{3552349D-C975-406D-84B8-BA298D01D5F7}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{A57A9AE3-09A9-44A0-AA78-458C71DA6FDE}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0416-0000-0000000FF1CE}_Office14.OMUI.pt-br_{27F43FC3-052A-41B5-9F39-68514C0AABC2}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0816-0000-0000000FF1CE}_Office14.OMUI.pt-pt_{44E3400B-C404-4656-8D25-EBEC0E6A5222}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0C0A-0000-0000000FF1CE}_Office14.OMUI.es-es_{837C1EAC-6A89-44A0-8C45-E655AAFD8CE1}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.36 - VIA Technologies, Inc.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
XFastUsb (HKLM-x32\...\XFastUsb) (Version:  - )

==================== Restore Points  =========================


==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {03783D24-AA74-4CDE-B9F4-D3ABE357AA53} - Sys-tem32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-04] (Google Inc.)
Task: {096FEDF5-8579-4831-B7BC-462F5EBFD18F} - Sys-tem32\Tasks\{8EFD28B5-5E1F-4DE6-96B8-F7CF102255A3} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10] (Skype Technologies S.A.)
Task: {1248B4FD-7AE0-4B42-B790-866611FFEA14} - Sys-tem32\Tasks\DealPlyUpdate => C:\Program Files (x86)\DealPly\DealPlyUpdate.exe <==== ATTENTION
Task: {13CB59E9-9BE8-4C54-B915-88CC0A9CB39B} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Fi-les\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {4D3F1791-8000-4EEF-BEEF-0F79914B7FEE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-04] (Adobe Systems Incorporated)
Task: {825D6925-CBE2-468F-AA1B-2C6AEDA58972} - Sys-tem32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {85218FCB-9AF2-4874-B6FF-742282D14F92} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-26] (AVAST Software)
Task: {A3D367F9-DF1F-4D7A-9C93-2A55841D67C0} - Sys-tem32\Tasks\RealUpgradeLogonTaskS-1-5-21-4118839908-2255762619-2302489997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-06-21] (RealNetworks, Inc.)
Task: {AA1CF60E-851D-4740-B83A-F128B4B22DB2} - Sys-tem32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4118839908-2255762619-2302489997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-06-21] (RealNetworks, Inc.)
Task: {B4F34596-E14C-4B4B-8A0E-D14F6D3D477D} - System32\Tasks\Java Up-date Scheduler => C:\Program Files (x86)\Common Files\Java\Java Up-date\jusched.exe
Task: {D17E44B3-BF5E-4467-9E04-32B24F519B31} - Sys-tem32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E39552D0-681F-4E9D-8E67-6DFAA77FBF39} - Sys-tem32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-04] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Fi-les\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2012-04-18 18:22 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-04-18 18:23 - 2011-02-22 08:03 - 00078448 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2012-04-18 18:23 - 2011-02-22 08:03 - 00386160 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2012-04-18 18:23 - 2011-02-22 08:03 - 00621168 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll
2014-05-11 12:14 - 2014-05-11 12:14 - 02253312 _____ () C:\Program Files\AVAST Software\Avast\defs\14051100\algo.dll
2014-05-11 18:21 - 2014-05-11 18:21 - 02253312 _____ () C:\Program Files\AVAST Software\Avast\defs\14051103\algo.dll
2012-04-18 18:27 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL
2012-04-18 18:27 - 2009-04-20 11:55 - 00148480 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2014-03-22 22:35 - 2014-03-22 22:35 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2012-09-23 20:43 - 2012-09-23 20:43 - 00010240 _____ () E:\Programme\Adobe Pro\Acrobat\locale\de_de\acrotray.deu
2014-04-29 23:43 - 2014-04-29 23:43 - 03019888 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2014-04-29 23:43 - 2014-04-29 23:43 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2014-04-29 23:43 - 2014-04-29 23:43 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2014-05-10 01:08 - 2014-05-10 01:08 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-05-04 23:32 - 2014-05-04 23:32 - 16351920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-12-21 08:05 - 2013-12-21 08:05 - 00133120 _____ () E:\Programme\Adobe Pro\Acrobat\Locale\de_de\PDFMaker\PDFMOfficeAddin.DEU

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:0FF263E8

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: NAUpdate => 2
MSCONFIG\Services: VIAKaraokeService => 2
MSCONFIG\Services: WSearch => 2
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Fi-les\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Fi-les\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: VoipCheapCom => "E:\VoipCheapCom\VoipCheapCom.exe" -nosplash -minimized

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/11/2014 06:20:50 PM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/11/2014 06:18:08 PM) (Source: Application Hang) (User: ) (EventID: 1002)
Description: Programm firefox.exe, Version 29.0.1.5239 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1108

Startzeit: 01cf6d01cbbea2b9

Endzeit: 133

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: c50c3e73-d927-11e3-9928-002522ce01c6

Error: (05/11/2014 00:13:31 PM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/11/2014 01:53:24 AM) (Source: SideBySide) (User: ) (EventID: 80)
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/10/2014 10:49:42 AM) (Source: SideBySide) (User: ) (EventID: 80)
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/10/2014 10:20:01 AM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/09/2014 10:47:22 AM) (Source: SideBySide) (User: ) (EventID: 80)
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/09/2014 10:17:53 AM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/08/2014 03:32:16 PM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17041, Zeitstempel: 0x53180888
Name des fehlerhaften Moduls: IEFRAME.dll, Version: 11.0.9600.17041, Zeitstem-pel: 0x53181af7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000148331
ID des fehlerhaften Prozesses: 0x183c
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3

Error: (05/08/2014 03:32:01 PM) (Source: Application Error) (User: ) (EventID: 1000)
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 11.0.9600.17041, Zeitstempel: 0x53180888
Name des fehlerhaften Moduls: IEFRAME.dll, Version: 11.0.9600.17041, Zeitstem-pel: 0x53181af7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000148331
ID des fehlerhaften Prozesses: 0x1bc8
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3


System errors:
=============
Error: (05/11/2014 03:56:03 PM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (05/09/2014 11:48:38 PM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (05/08/2014 03:39:17 PM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (05/08/2014 11:13:35 AM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (05/07/2014 10:16:01 AM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (05/04/2014 03:07:00 PM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (05/02/2014 11:29:37 AM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (04/28/2014 08:39:16 PM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (04/24/2014 07:47:16 PM) (Source: Disk) (User: ) (EventID: 11)
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR4 gefunden.

Error: (04/23/2014 10:06:01 PM) (Source: volsnap) (User: ) (EventID: 36)
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.


Microsoft Office Sessions:
=========================
Error: (05/11/2014 06:20:50 PM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/11/2014 06:18:08 PM) (Source: Application Hang) (User: ) (EventID: 1002)
Description: firefox.exe29.0.1.5239110801cf6d01cbbea2b9133C:\Program Files (x86)\Mozilla Firefox\firefox.exec50c3e73-d927-11e3-9928-002522ce01c6

Error: (05/11/2014 00:13:31 PM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/11/2014 01:53:24 AM) (Source: SideBySide) (User: ) (EventID: 80)
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestE:\Dragon Naturally Speaking 12 Deutsch\Program\dragon_support_packager.exe

Error: (05/10/2014 10:49:42 AM) (Source: SideBySide) (User: ) (EventID: 80)
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestE:\Dragon Naturally Speaking 12 Deutsch\Program\dragon_support_packager.exe

Error: (05/10/2014 10:20:01 AM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/09/2014 10:47:22 AM) (Source: SideBySide) (User: ) (EventID: 80)
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-con-trols_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestE:\Dragon Naturally Speaking 12 Deutsch\Program\dragon_support_packager.exe

Error: (05/09/2014 10:17:53 AM) (Source: WinMgmt) (User: ) (EventID: 10)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetIn-stance.LoadPercentage > 990x80041003

Error: (05/08/2014 03:32:16 PM) (Source: Application Error) (User: ) (EventID: 1000)
Description: iexplo-re.exe11.0.9600.1704153180888IEFRAME.dll11.0.9600.1704153181af7c00000050000000000148331183c01cf6ac1ed3b8984C:\Program Files\Internet Explo-rer\iexplore.exeC:\Windows\system32\IEFRAME.dll2b1c05a6-d6b5-11e3-acf9-002522ce01c6

Error: (05/08/2014 03:32:01 PM) (Source: Application Error) (User: ) (EventID: 1000)
Description: iexplo-re.exe11.0.9600.1704153180888IEFRAME.dll11.0.9600.1704153181af7c000000500000000001483311bc801cf6ac1e47bd868C:\Program Files\Internet Explo-rer\iexplore.exeC:\Windows\system32\IEFRAME.dll228846a8-d6b5-11e3-acf9-002522ce01c6


==================== Memory info =========================== 

Percentage of memory in use: 54%
Total physical RAM: 3816.75 MB
Available physical RAM: 1727.88 MB
Total Pagefile: 7631.67 MB
Available Pagefile: 5562.29 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:59.53 GB) (Free:7.29 GB) NTFS
Drive e: (Volume) (Fixed) (Total:931.51 GB) (Free:643.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 60 GB) (Disk ID: 5B478C15)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=60 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 36DE7CD4)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

Gmer:

Code:
ATTFilter
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-11 19:19:35
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 M4-CT064M4SSD2 rev.0309 59,63GB
Running: Gmer-19357.exe; Driver: C:\Users\Libelle\AppData\Local\Temp\pxldapow.sys


---- User code sections - GMER 2.1 ----

.text   C:\Windows\system32\wininit.exe[480] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                  0000000076e6ef8d 1 byte [62]
.text   C:\Windows\system32\services.exe[528] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                 0000000076e6ef8d 1 byte [62]
.text   C:\Windows\system32\winlogon.exe[588] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                 0000000076e6ef8d 1 byte [62]
.text   C:\Windows\System32\svchost.exe[932] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                  0000000076e6ef8d 1 byte [62]
.text   C:\Windows\system32\svchost.exe[984] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                  0000000076e6ef8d 1 byte [62]
.text   C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe[436] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                        00000000753ba2fd 1 byte [62]
.text   C:\Windows\Explorer.EXE[1276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                         0000000076e6ef8d 1 byte [62]
.text   C:\Windows\system32\taskhost.exe[1352] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                0000000076e6ef8d 1 byte [62]
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1548] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                    00000000753ba2fd 1 byte [62]
.text   C:\Windows\System32\rundll32.exe[1824] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                0000000076e6ef8d 1 byte [62]
.text   C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe[2036] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                   00000000753ba2fd 1 byte [62]
.text   C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe[2036] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                 00000000755d1465 2 bytes [5D, 75]
.text   C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe[2036] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                00000000755d14bb 2 bytes [5D, 75]
.text   ...                                                                                                                                         * 2
.text   C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe[2108] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                         00000000753ba2fd 1 byte [62]
.text   C:\ProgramData\FLEXnet\Connect\11\agent.exe[2396] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                     00000000753ba2fd 1 byte [62]
.text   C:\Program Files (x86)\XFastUsb\XFastUsb.exe[2496] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                    00000000753ba2fd 1 byte [62]
.text   C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe[2516] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112            00000000753ba2fd 1 byte [62]
.text   C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe[2864] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                    00000000753ba2fd 1 byte [62]
.text   E:\Programme\PDF24\pdf24.exe[2072] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                    00000000753ba2fd 1 byte [62]
.text   E:\Programme\Adobe Pro\Acrobat\acrotray.exe[2600] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                     00000000753ba2fd 1 byte [62]
.text   C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[3160] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  00000000753ba2fd 1 byte [62]
.text   C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[2776] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  00000000753ba2fd 1 byte [62]
.text   C:\Users\Libelle\Desktop\Gmer-19357.exe[1908] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                         00000000753ba2fd 1 byte [62]

---- Threads - GMER 2.1 ----

Thread  C:\Windows\System32\svchost.exe [2556:3080]                                                                                                 000007fef0b99688

---- EOF - GMER 2.1 ----
         

Ich hoffe, ich habe alles richtig gemacht mit den Logfiles. Einen Virenscan mit avast habe ich ebenfalls durchgeführt, da wurde jedoch nichts gefunden.

Ich wäre euch sehr dankbar, wenn ihr mir helfen könnt! Es ist ein ziemlich lästiges Problem, da man nie weiß, wann wieder der nächste Absturz kommt.

Vielen Dank schonmal im Voraus für eure Hilfe!
jvc

Alt 12.05.2014, 06:51   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________

__________________

Alt 12.05.2014, 10:24   #3
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo schrauber,

vielen Dank für deine Antwort!!

Ich poste hier das Ergebnis vom Combofix:

Code:
ATTFilter
Combofix Logfile:
Code:
ATTFilter
ComboFix 14-05-10.01 - Libelle 12.05.2014  11:05:59.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.43.1031.18.3817.2445 [GMT 2:00]
ausgeführt von:: c:\users\Libelle\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\tmp3F7F.tmp
c:\windows\SysWow64\tmp3F8F.tmp
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-04-12 bis 2014-05-12  ))))))))))))))))))))))))))))))
.
.
2014-05-12 09:11 . 2014-05-12 09:11	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-05-11 16:53 . 2014-05-11 16:54	--------	d-----w-	C:\FRST
2014-05-09 08:22 . 2014-04-17 03:31	10651704	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{8ED24E8D-F70E-41D7-ACC0-C9B2751A213F}\mpengine.dll
2014-05-08 17:16 . 2014-05-08 17:16	--------	d-----w-	c:\users\Libelle\AppData\Roaming\SolidDocuments
2014-05-08 13:31 . 2014-05-08 13:31	--------	d-sh--w-	c:\users\Libelle\AppData\Local\EmieUserList
2014-05-08 13:31 . 2014-05-08 13:31	--------	d-sh--w-	c:\users\Libelle\AppData\Local\EmieSiteList
2014-05-07 16:25 . 2014-05-07 16:25	159744	----a-w-	c:\program fi-les\Internet Explorer\Plugins\npqtplugin5.dll
2014-05-07 16:25 . 2014-05-07 16:25	159744	----a-w-	c:\program fi-les\Internet Explorer\Plugins\npqtplugin4.dll
2014-05-07 16:25 . 2014-05-07 16:25	159744	----a-w-	c:\program fi-les\Internet Explorer\Plugins\npqtplugin3.dll
2014-05-07 16:25 . 2014-05-07 16:25	159744	----a-w-	c:\program fi-les\Internet Explorer\Plugins\npqtplugin2.dll
2014-05-07 16:25 . 2014-05-07 16:25	159744	----a-w-	c:\program fi-les\Internet Explorer\Plugins\npqtplugin.dll
2014-05-07 16:24 . 2014-05-07 16:25	--------	d-----w-	c:\program files (x86)\QuickTime
2014-05-04 21:32 . 2014-05-04 21:32	70832	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-04 21:32 . 2014-05-04 21:32	692400	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-02 22:42 . 2014-04-29 14:01	23547904	----a-w-	c:\windows\system32\mshtml.dll
2014-05-02 22:42 . 2014-04-29 13:40	2724864	----a-w-	c:\windows\system32\mshtml.tlb
2014-05-02 22:42 . 2014-04-29 12:34	2724864	----a-w-	c:\windows\SysWow64\mshtml.tlb
2014-04-30 08:52 . 2014-04-30 08:52	--------	d-s---w-	c:\windows\system32\CompatTel
2014-04-30 06:58 . 2014-04-14 02:24	465408	----a-w-	c:\windows\system32\aepdu.dll
2014-04-30 06:58 . 2014-04-14 02:19	424448	----a-w-	c:\windows\system32\aeinv.dll
2014-04-29 21:43 . 2014-04-30 06:59	--------	d-----w-	c:\program files (x86)\Mozilla Thunderbird
2014-04-26 15:51 . 2014-04-26 15:51	29208	----a-w-	c:\windows\system32\drivers\aswHwid.sys
2014-04-26 15:51 . 2014-04-26 15:51	43152	----a-w-	c:\windows\avastSS.scr
2014-04-22 09:35 . 2014-04-22 09:35	--------	d-----w-	c:\users\Libelle\AppData\Roaming\PDAppFlex
2014-04-22 09:31 . 2014-04-22 09:31	--------	d-----w-	c:\programdata\regid.1986-12.com.adobe
2014-04-22 09:14 . 2014-04-22 09:14	--------	d-----w-	c:\users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2014-04-21 20:22 . 2014-04-21 20:22	--------	d-----w-	c:\users\Libelle\AppData\Local\PDF24
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-26 15:51 . 2014-03-22 20:35	85328	----a-w-	c:\windows\system32\drivers\aswStm.sys
2014-04-26 15:51 . 2013-03-21 13:18	65776	----a-w-	c:\windows\system32\drivers\aswRvrt.sys
2014-04-26 15:51 . 2013-03-21 13:18	208416	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2014-04-26 15:51 . 2012-04-19 12:20	423240	----a-w-	c:\windows\system32\drivers\aswSP.sys
2014-04-26 15:51 . 2012-04-19 12:20	93568	----a-w-	c:\windows\system32\drivers\aswRdr2.sys
2014-04-26 15:51 . 2012-04-19 12:20	79184	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
2014-04-26 15:51 . 2012-04-19 12:20	334648	----a-w-	c:\windows\system32\aswBoot.exe
2014-04-26 15:51 . 2012-04-19 12:20	1039096	----a-w-	c:\windows\system32\drivers\aswSnx.sys
2014-04-10 23:02 . 2012-04-19 11:54	90655440	----a-w-	c:\windows\system32\MRT.exe
2014-04-01 16:08 . 2014-04-01 16:08	108968	----a-w-	c:\windows\system32\WindowsAccessBridge-64.dll
2014-04-01 16:08 . 2014-04-01 16:08	312744	----a-w-	c:\windows\system32\javaws.exe
2014-04-01 16:08 . 2014-04-01 16:08	189352	----a-w-	c:\windows\system32\javaw.exe
2014-04-01 16:08 . 2014-04-01 16:08	189352	----a-w-	c:\windows\system32\java.exe
2014-03-31 07:35 . 2010-11-21 03:27	270496	------w-	c:\windows\system32\MpSigStub.exe
2014-03-06 09:31 . 2014-04-10 23:04	4096	----a-w-	c:\windows\system32\ieetwcollectorres.dll
2014-03-06 08:59 . 2014-04-10 23:04	66048	----a-w-	c:\windows\system32\iesetup.dll
2014-03-06 08:57 . 2014-04-10 23:04	548352	----a-w-	c:\windows\system32\vbscript.dll
2014-03-06 08:57 . 2014-04-10 23:04	48640	----a-w-	c:\windows\system32\ieetwproxystub.dll
2014-03-06 08:53 . 2014-04-10 23:04	2767360	----a-w-	c:\windows\system32\iertutil.dll
2014-03-06 08:40 . 2014-04-10 23:04	51200	----a-w-	c:\windows\system32\jsproxy.dll
2014-03-06 08:39 . 2014-04-10 23:04	33792	----a-w-	c:\windows\system32\iernonce.dll
2014-03-06 08:32 . 2014-04-10 23:04	574976	----a-w-	c:\windows\system32\ieui.dll
2014-03-06 08:29 . 2014-04-10 23:04	139264	----a-w-	c:\windows\system32\ieUnatt.exe
2014-03-06 08:29 . 2014-04-10 23:04	111616	----a-w-	c:\windows\system32\ieetwcollector.exe
2014-03-06 08:28 . 2014-04-10 23:04	752640	----a-w-	c:\windows\system32\jscript9diag.dll
2014-03-06 08:15 . 2014-04-10 23:04	940032	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2014-03-06 08:11 . 2014-04-10 23:04	5784064	----a-w-	c:\windows\system32\jscript9.dll
2014-03-06 08:09 . 2014-04-10 23:04	453120	----a-w-	c:\windows\system32\dxtmsft.dll
2014-03-06 08:03 . 2014-04-10 23:04	586240	----a-w-	c:\windows\system32\ie4uinit.exe
2014-03-06 08:02 . 2014-04-10 23:04	61952	----a-w-	c:\windows\SysWow64\iesetup.dll
2014-03-06 08:02 . 2014-04-10 23:04	455168	----a-w-	c:\windows\SysWow64\vbscript.dll
2014-03-06 08:01 . 2014-04-10 23:04	51200	----a-w-	c:\windows\SysWow64\ieetwproxystub.dll
2014-03-06 07:56 . 2014-04-10 23:04	38400	----a-w-	c:\windows\system32\JavaScriptCollectionAgent.dll
2014-03-06 07:48 . 2014-04-10 23:04	195584	----a-w-	c:\windows\system32\msrating.dll
2014-03-06 07:46 . 2014-04-10 23:04	4254720	----a-w-	c:\windows\SysWow64\jscript9.dll
2014-03-06 07:42 . 2014-04-10 23:04	296960	----a-w-	c:\windows\system32\dxtrans.dll
2014-03-06 07:38 . 2014-04-10 23:04	112128	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2014-03-06 07:36 . 2014-04-10 23:04	592896	----a-w-	c:\windows\SysWow64\jscript9diag.dll
2014-03-06 07:21 . 2014-04-10 23:04	628736	----a-w-	c:\windows\system32\msfeeds.dll
2014-03-06 07:13 . 2014-04-10 23:04	32256	----a-w-	c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2014-03-06 07:11 . 2014-04-10 23:04	2043904	----a-w-	c:\windows\system32\inetcpl.cpl
2014-03-06 06:53 . 2014-04-10 23:04	13551104	----a-w-	c:\windows\system32\ieframe.dll
2014-03-06 06:40 . 2014-04-10 23:04	1967104	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2014-03-06 06:22 . 2014-04-10 23:04	2260480	----a-w-	c:\windows\system32\wininet.dll
2014-03-06 05:58 . 2014-04-10 23:04	1400832	----a-w-	c:\windows\system32\urlmon.dll
2014-03-06 05:50 . 2014-04-10 23:04	846336	----a-w-	c:\windows\system32\ieapfltr.dll
2014-03-06 05:41 . 2014-04-10 23:04	1789440	----a-w-	c:\windows\SysWow64\wininet.dll
2014-03-04 09:44 . 2014-04-10 09:08	362496	----a-w-	c:\windows\system32\wow64win.dll
2014-03-04 09:44 . 2014-04-10 09:08	243712	----a-w-	c:\windows\system32\wow64.dll
2014-03-04 09:44 . 2014-04-10 09:08	13312	----a-w-	c:\windows\system32\wow64cpu.dll
2014-03-04 09:44 . 2014-04-10 09:08	16384	----a-w-	c:\windows\system32\ntvdm64.dll
2014-03-04 09:44 . 2014-04-10 09:08	1163264	----a-w-	c:\windows\system32\kernel32.dll
2014-03-04 09:17 . 2014-04-10 09:08	14336	----a-w-	c:\windows\SysWow64\ntvdm64.dll
2014-03-04 09:17 . 2014-04-10 09:08	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2014-03-04 09:16 . 2014-04-10 09:08	25600	----a-w-	c:\windows\SysWow64\setup16.exe
2014-03-04 09:16 . 2014-04-10 09:08	5120	----a-w-	c:\windows\SysWow64\wow32.dll
2014-03-04 08:09 . 2014-04-10 09:08	7680	----a-w-	c:\windows\SysWow64\instnm.exe
2014-03-04 08:09 . 2014-04-10 09:08	2048	----a-w-	c:\windows\SysWow64\user.exe
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Ob-jects\{E87806B5-E908-45FD-AF5E-957D83E58E68}]
2013-05-06 15:36	301464	----a-w-	c:\program files (x86)\Softonic\Softonic\1.8.19.3\bh\Softonic.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explor-er\Toolbar]
"{5018CFD2-804D-4C99-9F81-25EAEA2769DE}"= "c:\program files (x86)\Softonic\Softonic\1.8.19.3\SoftonicTlbr.dll" [2013-05-06 288664]
.
[HKEY_CLASSES_ROOT\clsid\{5018cfd2-804d-4c99-9f81-25eaea2769de}]
[HKEY_CLASSES_ROOT\Softonic.dskBnd.1]
[HKEY_CLASSES_ROOT\Softonic.dskBnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2011-10-12 2068856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2011-02-22 3019376]
"XFastUsb"="c:\program files (x86)\XFastUsb\XFastUsb.exe" [2012-04-18 4942336]
"VolPanel"="c:\program files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" [2009-05-04 241789]
"BCSSync"="c:\program files (x86)\Microsoft Office 2010\Office14\BCSSync.exe" [2012-11-05 89184]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Sup-port\APSDaemon.exe" [2013-04-21 59720]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\\isuspm.exe" [2011-10-12 2068856]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-26 3873704]
"PDFPrint"="e:\programme\PDF24\pdf24.exe" [2014-02-06 189480]
"Acrobat Assistant 8.0"="e:\programme\Adobe Pro\Acrobat\Acrotray.exe" [2013-12-21 3478392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-01-17 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ORFO Agent.lnk - c:\program files (x86)\Informatic\ORFO 9.0\orfagent.exe [2007-8-3 114688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"UpdReg"=c:\windows\UpdReg.EXE
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"DNS7reminder"="e:\dragon naturally speaking 12 deutsch\Ereg\Ereg.exe" -r "c:\programdata\Nuance\NaturallySpeaking12\Ereg.ini"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Up-date\jusched.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Ser-vice;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Ser-vice;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 FNETTBOH_305;FNETTBOH_305;c:\windows\system32\drivers\FNETTBOH_305.SYS;c:\windows\SYSNATIVE\drivers\FNETTBOH_305.SYS [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Ser-vice;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Ser-vice;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Fil-ter);c:\windows\system32\DRIVERS\ss_bmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Mo-dem;c:\windows\system32\DRIVERS\ss_bmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ss_bmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB De-vice;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieserv-ice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
R4 VIAKaraokeService;VIA Karaoke digital mixer Ser-vice;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 FNE-TURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS;c:\windows\SYSNATIVE\drivers\FNETURPX.SYS [x]
S2 aswHwid;avast! Hard-wareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMon-Flt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 DragonSvc;Dragon Service;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & De-stroy\SDWinSec.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Ser-vice;c:\program files (x86)\Intel\Intel(R) Management Engine Compo-nents\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Com-ponents\UNS\UNS.exe [x]
S3 IntcDAud;Intel(R) Display-Au-dio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 RTL8167;Realtek 8167 NT Driv-er;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Ser-vice;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-05-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-04 21:32]
.
2014-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-04 20:40]
.
2014-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-03-04 20:40]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-26 15:51	290888	----a-w-	c:\program files\AVAST Soft-ware\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-04 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-04 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-04 418328]
"RunDLLEntry"="c:\windows\system32\AmbRunE.dll" [2009-02-26 17920]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-03 1580368]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-09-20 444904]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=FCE1002522CE01C6&affID=121564&tt=070813_wt3&tsp=4968
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=e2104eac-9743-4275-82eb-98b205103149&searchtype=ds&q={searchTerms}&installDate=31/05/2013
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Free YouTube Download - c:\users\Libelle\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Libelle\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{EDEF3BBF-1341-4E63-9148-8934BB617129}: NameServer = 130.244.127.161,130.244.127.169
FF - ProfilePath - c:\users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\
FF - prefs.js: browser.startup.homepage - www.google.at | www.pons.eu
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110819&tt=100512_4_
FF - user.js: extensions.BabylonToolbar_i.babExt - 
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - fce15e28000000000000002522ce01c6
FF - user.js: extensions.BabylonToolbar_i.hardId - fce15e28000000000000002522ce01c6
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15472
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1720:58
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extensions.Softonic.hpOld0 - hxxp://www.google.at|http://de.pons.eu/
FF - user.js: extensions.Softonic.tlbrSrchUrl - hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=1&cc=&mi=fce15e28000000000000002522ce01c6&q=
FF - user.js: extensions.Softonic.id - fce15e28000000000000002522ce01c6
FF - user.js: extensions.Softonic.appId - {7ABBFE1C-E485-44AA-8F36-353751B4124D}
FF - user.js: extensions.Softonic.instlDay - 15874
FF - user.js: extensions.Softonic.vrsn - 1.8.19.3
FF - user.js: extensions.Softonic.vrsni - 1.8.19.3
FF - user.js: extensions.Softonic.vrsnTs - 1.8.19.39:56
FF - user.js: extensions.Softonic.prtnrId - softonic
FF - user.js: extensions.Softonic.prdct - Softonic
FF - user.js: extensions.Softonic.aflt - SD
FF - user.js: extensions.Softonic.smplGrp - none
FF - user.js: extensions.Softonic.tlbrId - BASEirobinhoodActive
FF - user.js: extensions.Softonic.instlRef - MOY00006
FF - user.js: extensions.Softonic.dfltLng - de
FF - user.js: extensions.Softonic.excTlbr - false
FF - user.js: extensions.Softonic.ffxUnstlRst - false
FF - user.js: extensions.Softonic.admin - false
FF - user.js: extensions.Softonic.autoRvrt - false
FF - user.js: extensions.Softonic.rvrt - false
FF - user.js: extensions.Softonic.hmpg - true
FF - user.js: extensions.Softonic.hmpgUrl - hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&cc=&mi=fce15e28000000000000002522ce01c6
FF - user.js: extensions.Softonic.dfltSrch - true
FF - user.js: extensions.Softonic.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.Softonic.kw_url - hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=2&cc=&mi=fce15e28000000000000002522ce01c6&q=
FF - user.js: extensions.Softonic.dnsErr - true
FF - user.js: extensions.Softonic.newTab - true
FF - user.js: extensions.Softonic.newTabUrl - hxxp://search.softonic.com/MOY00006/tb_v1/?SearchSource=15&cc=&mi=fce15e28000000000000002522ce01c6
FF - user.js: extensions.delta.tlbrSrchUrl - 
FF - user.js: extensions.delta.id - fce15e28000000000000002522ce01c6
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15925
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.015:56
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=121564&tt=070813_wt3&tsp=4968
FF - user.js: extensions.delta_i.babExt - 
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-FLV Player - c:\program files (x86)\FLVPlayer\Uninstall\Uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Li-brary\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Li-brary\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-05-12  11:13:09
ComboFix-quarantined-files.txt  2014-05-12 09:13
.
Vor Suchlauf: 7.211.442.176 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 11.013.591.040 Bytes frei
.
- - End Of File - - E482FFE61694A204748F7FECF29E4B27
         
--- --- --- A36C5E4F47E84449FF07ED3517B43A31

Es gab während des Scans ein kleines Problem: Circa bei Stufe 7 kam in einem kleinen Fenster folgende Meldung:

PEV.exe funktioniert nicht mehr
Das Programm wird aufgrund eines Problems nicht richtig ausgeführt. Das Programm wird geschlossen und Sie werden benachrichtigt, wenn eine Lösung verfügbar ist.

Dann kam der Button "Programm schließen"

Da der Scan im Hintergrund jedoch einfach weiterlief, habe ich gar nichts gemacht (da ich ja die Maus nicht bewegen soll). Das Fenster schloss sich dann gegen Ende des Scans und las Logfile wurde problemlos erstellt.


Ich kann die ganzen bisherigen Logfiles leider überhaupt nicht deuten (kenne mich diesbezüglich gar nicht aus), kannst du mir sagen, ob mein PC infiziert ist?

Vielen Dank für deine Hilfe und viele Grüße,
jvc
__________________

Alt 13.05.2014, 09:35   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Ja, jede menge Adware.

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.05.2014, 21:16   #5
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo schrauber,

vielen Dank für deine Nachricht und für deine Hilfe.

Im folgenden poste ich die Logfiles:

Malwarebytes Anti-Malware (hier gab es über 60 Funde):

Code:
ATTFilter
<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2014/05/13 11:31:23 +0200</date>
<log>mbam-log-2014-05-13 (11-25-43).xml</log>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.00.1.1004</version>
<rules-database>v2014.05.13.06</rules-database>
<swissarmy-database>v2014.03.27.01</swissarmy-database>
<license>trial</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<osversion>Windows 7 Service Pack 1</osversion>
<arch>x64</arch>
<username>Libelle</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>completed</result>
<objects>287471</objects>
<time>336</time>
<processes>0</processes>
<modules>0</modules>
<keys>25</keys>
<values>3</values>
<datas>5</datas>
<folders>9</folders>
<files>116</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>disabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<shuriken>enabled</shuriken>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<key><path>HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>668458f85f1c93a3c0242238fe043fc1</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>668458f85f1c93a3c0242238fe043fc1</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7674aca4205bd066b1ddcb59f50d946c</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>40aa7dd33447e155c0e5751307fb8d73</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>1dcda4ac3b4063d37e27097fae5444bc</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>45a5b79994e737ff762fdfa9a260718f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>a941a9a7de9d1f172283addb1de5e61a</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\elchiiiejkobdbblfejjkbphbddgmljf</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>28c2e36dcdaeca6c7632dfa9689a9b65</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>b733ca869edd11254b5ea9df38cad030</hash></key>
<key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>48a2dc740675989e7e960ba243c05aa6</hash></key>
<key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE</path><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><hash>ad3d93bd572495a1d16a614c6e95af51</hash></key>
<key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>19d1d27ea6d5dc5ad6d089ff4db502fe</hash></key>
<key><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>8268163a05767abc214588fd679ba15f</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></key>
<value><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR</path><valuename>{5018CFD2-804D-4C99-9F81-25EAEA2769DE}</valuename><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><valuedata>Softonic Toolbar</valuedata><hash>7674aca4205bd066b1ddcb59f50d946c</hash></value>
<value><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}</path><valuename></valuename><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><valuedata></valuedata><hash>1dcd6ce4710a2d0989050321e31f28d8</hash></value>
<value><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE</path><valuename>tb</valuename><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><valuedata>0J1H1HtGtCtH1Q1R1T1VtF0C</valuedata><hash>ad3d93bd572495a1d16a614c6e95af51</hash></value>
<data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL</path><valuename>Default</valuename><vendor>PUP.Optional.SnapDo.A</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</baddata><gooddata>www.google.com</gooddata><hash>b93128283546e6504a6596a5d92b0af6</hash></data>
<data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Start Page</valuename><vendor>PUP.Optional.StartPage</vendor><action>replaced</action><valuedata>hxxp://www1.delta-search.com/?babsrc=HP_ss&amp;mntrId=FCE1002522CE01C6&amp;affID=121564&amp;tt=070813_wt3&amp;tsp=4968</valuedata><baddata>hxxp://www1.delta-search.com/?babsrc=HP_ss&amp;mntrId=FCE1002522CE01C6&amp;affID=121564&amp;tt=070813_wt3&amp;tsp=4968</baddata><gooddata>hxxp://www.google.com</gooddata><hash>c2285ff1f784e551e24edc6964a09868</hash></data>
<data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>Default_Search_URL</valuename><vendor>PUP.Optional.Snapdo</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</baddata><gooddata>hxxp://www.google.com</gooddata><hash>a446f858f08b092dda3daa9b2dd751af</hash></data>
<data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>SearchAssistant</valuename><vendor>PUP.Optional.Snapdo</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</baddata><gooddata>hxxp://www.google.com</gooddata><hash>d11995bbf784043217014302818303fd</hash></data>
<data><path>HKU\S-1-5-21-4118839908-2255762619-2302489997-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL</path><valuename>Default</valuename><vendor>PUP.Optional.SnapDo.A</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&amp;dpid=SnapdoOCYB&amp;co=AT&amp;userid=e2104eac-9743-4275-82eb-98b205103149&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=31/05/2013</baddata><gooddata>www.google.com</gooddata><hash>45a5d17f97e449edb6faf04ba2621ee2</hash></data>
<folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder>
<folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder>
<folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\D59E0BB400B9476EB0564E8D56C48B04</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder>
<folder><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\F31A901D6C9C490A932D30C45DE6DE96</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></folder>
<folder><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></folder>
<folder><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></folder>
<folder><path>C:\Program Files (x86)\Softonic\Softonic</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></folder>
<folder><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></folder>
<folder><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></folder>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicTlbr.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7674aca4205bd066b1ddcb59f50d946c</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\bh\Softonic.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>7c6ed47c067504327f1080a4a062b14f</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\D59E0BB400B9476EB0564E8D56C48B04\DeltaTB.exe</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>b436a2ae3b4094a2628e61a3eb1612ee</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\F31A901D6C9C490A932D30C45DE6DE96\DeltaTB.exe</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>cb1fa3add8a36acc8b650bf9827f3ac6</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\softonic.xml</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>3bafa9a783f8ac8a376c9eea3cc638c8</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\babylon.xml</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>30ba2e22087359dd8e3c7d0e41c125db</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\searchplugins\Web Search.xml</path><vendor>PUP.Optional.WebSearch.A</vendor><action>success</action><hash>32b8490767144de930b3e2aac24034cc</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\3710.ico</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\EBB77268-338F-4C6A-8590-AD88FED26F4A</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\Installer.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\OpenCandy\62CAB8BDA55247108059E75231463368\OCBrowserHelper_1.0.6.128.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>4b9f5df32b50a49249960e5fb84a8a76</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\appCntrl.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.html</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\bg.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CrmAdpt.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\ct.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\CTB.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\dpk.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.htm</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\hprtkMsg.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\json2.min.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\logo.png</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\manifest.json</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Users\Libelle\AppData\Local\Google\Chrome\User Data\default\extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0\pref.json</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>41a9410f641763d390151b5a59a92fd1</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\escortShld.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\softonic.crx</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicApp.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\SoftonicEng.dll</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonicsrv.exe</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file>
<file><path>C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\uninstall.exe</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>46a49cb4057636002185cda860a2e020</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.aflt&quot;, &quot;babsst&quot;);</baddata><gooddata></gooddata><hash>a84286cadd9e82b4c20c452c5da726da</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.babExt&quot;, &quot;&quot;);</baddata><gooddata></gooddata><hash>1fcb321e24573600ca04e38e63a1ac54</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.babTrack&quot;, &quot;affID=110819&amp;tt=100512_4_&quot;);</baddata><gooddata></gooddata><hash>43a7f9579edd59ddbc12e68b5ba945bb</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.hardId&quot;, &quot;fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>eefcd27e5d1ec274ece21a57f60e9070</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.id&quot;, &quot;fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>86640c44601bd363b11d383956ae1ee2</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.instlDay&quot;, &quot;15472&quot;);</baddata><gooddata></gooddata><hash>f2f887c9dc9f8ea8be10640d5da740c0</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.instlRef&quot;, &quot;sst&quot;);</baddata><gooddata></gooddata><hash>17d394bca0db61d509c5f37e9a6a4cb4</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.newTab&quot;, true);</baddata><gooddata></gooddata><hash>7a7074dcb9c200363c924e2341c3d32d</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.newTabUrl&quot;, &quot;hxxp://search.babylon.com/?affID=110819&amp;tt=100512_4_&amp;babsrc=NT_ss&amp;mntrId=fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>2ebca1af74078babb01e89e89272b44c</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.prdct&quot;, &quot;BabylonToolbar&quot;);</baddata><gooddata></gooddata><hash>2fbb4010b7c43ef8b816620fbe467888</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.prtnrId&quot;, &quot;babylon&quot;);</baddata><gooddata></gooddata><hash>29c190c0463579bdbf0fc1b059ab3bc5</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.smplGrp&quot;, &quot;none&quot;);</baddata><gooddata></gooddata><hash>de0c5df3a8d376c022ac98d9e222926e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.srcExt&quot;, &quot;ss&quot;);</baddata><gooddata></gooddata><hash>29c1034da9d220160ac480f159abb54b</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.tlbrId&quot;, &quot;tb9&quot;);</baddata><gooddata></gooddata><hash>f1f9f45c2f4ca88eba14640da65e768a</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.vrsn&quot;, &quot;1.5.3.17&quot;);</baddata><gooddata></gooddata><hash>00ea0f41b6c568ce1ab497daa460c23e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.vrsnTs&quot;, &quot;1.5.3.1720:58:29&quot;);</baddata><gooddata></gooddata><hash>4d9d5ff11d5e6dc9dbf31e53d034f50b</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.vrsni&quot;, &quot;1.5.3.17&quot;);</baddata><gooddata></gooddata><hash>2bbff65af5865bdb5b730b66699bf50b</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.admin&quot;, false);</baddata><gooddata></gooddata><hash>58925cf48dee7eb802cd135e9470fd03</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.aflt&quot;, &quot;SD&quot;);</baddata><gooddata></gooddata><hash>db0f450b1a618babcf006b0649bb728e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.appId&quot;, &quot;{7ABBFE1C-E485-44AA-8F36-353751B4124D}&quot;);</baddata><gooddata></gooddata><hash>b03ad9771e5d4de9359ac2af4abab749</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.autoRvrt&quot;, &quot;false&quot;);</baddata><gooddata></gooddata><hash>db0f91bf16658aaca926353cff050ef2</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.dfltLng&quot;, &quot;de&quot;);</baddata><gooddata></gooddata><hash>43a7321e15666ccadff0d69bc440bb45</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.dfltSrch&quot;, true);</baddata><gooddata></gooddata><hash>4e9cb0a0b3c83501339c6e0334d0a25e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.dnsErr&quot;, true);</baddata><gooddata></gooddata><hash>9c4e410f9eddfa3cb11e9dd43dc713ed</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.excTlbr&quot;, false);</baddata><gooddata></gooddata><hash>49a189c79ae1dc5a20af561b9371fb05</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.ffxUnstlRst&quot;, false);</baddata><gooddata></gooddata><hash>11d94010d2a97abc8649b3be14f0af51</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.hmpg&quot;, true);</baddata><gooddata></gooddata><hash>19d1d080f18a0432dcf3d29f6a9a02fe</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.hmpgUrl&quot;, &quot;hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&amp;cc=&amp;mi=fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>5991b29eb8c3ae8802cd9ad74eb6758b</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.hpOld0&quot;, &quot;hxxp://www.google.at|hxxp://de.pons.eu/&quot;);</baddata><gooddata></gooddata><hash>8d5d07496a115adc13bc521fbe460cf4</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.id&quot;, &quot;fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>7476c28e92e9ef47854acaa7679d1ee2</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.instlDay&quot;, &quot;15874&quot;);</baddata><gooddata></gooddata><hash>2bbf3c14c4b761d511be0170fc08bb45</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.instlRef&quot;, &quot;MOY00006&quot;);</baddata><gooddata></gooddata><hash>7e6c58f82f4cd363d3fc51201de7d828</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.kw_url&quot;, &quot;hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=2&amp;cc=&amp;mi=fce15e28000000000000002522ce01c6&amp;q=&quot;);</baddata><gooddata></gooddata><hash>17d3222e85f6c76f7f5072ff1ee6a35d</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.newTab&quot;, true);</baddata><gooddata></gooddata><hash>cf1b29278af15dd9cd02d899a262dc24</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.newTabUrl&quot;, &quot;hxxp://search.softonic.com/MOY00006/tb_v1/?SearchSource=15&amp;cc=&amp;mi=fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>8a60193753286cca16b9b4bd04007789</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.prdct&quot;, &quot;Softonic&quot;);</baddata><gooddata></gooddata><hash>ca20f858e398cb6b6669e48d788cd32d</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.prtnrId&quot;, &quot;softonic&quot;);</baddata><gooddata></gooddata><hash>1bcf81cf700b5fd7ffd0a9c8f11338c8</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.rvrt&quot;, &quot;false&quot;);</baddata><gooddata></gooddata><hash>3fabe16f89f245f1339c125fd82ceb15</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.smplGrp&quot;, &quot;none&quot;);</baddata><gooddata></gooddata><hash>7476de72c7b4c96da728b2bf8183e719</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.srchPrvdr&quot;, &quot;Search the web (Softonic)&quot;);</baddata><gooddata></gooddata><hash>cd1dc38df9823402973884edab59ec14</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.tlbrId&quot;, &quot;BASEirobinhoodActive&quot;);</baddata><gooddata></gooddata><hash>8d5d1040413a2f07a32c5b16bb4936ca</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.tlbrSrchUrl&quot;, &quot;hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=1&amp;cc=&amp;mi=fce15e28000000000000002522ce01c6&amp;q=&quot;);</baddata><gooddata></gooddata><hash>30ba1a36fb80d85ed3fccea3749054ac</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.vrsn&quot;, &quot;1.8.19.3&quot;);</baddata><gooddata></gooddata><hash>5694d27e512ad660418e125f798bc739</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.vrsnTs&quot;, &quot;1.8.19.39:56:28&quot;);</baddata><gooddata></gooddata><hash>a3475ff1c8b382b4fcd3096880842ad6</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Softonic.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.Softonic.vrsni&quot;, &quot;1.8.19.3&quot;);</baddata><gooddata></gooddata><hash>509ab0a095e6af8728a7a9c85ba96997</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.FaceMoods.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.facemoods.aflt&quot;, &quot;_#ironto&quot;);</baddata><gooddata></gooddata><hash>5892d27ee99246f0953fea87758f58a8</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.FaceMoods.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.facemoods.firstRun&quot;, false);</baddata><gooddata></gooddata><hash>8367f85879022c0ad004a5ccd82cc937</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.FaceMoods.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.facemoods.lastActv&quot;, &quot;14&quot;);</baddata><gooddata></gooddata><hash>8664d17f720942f472622b4617ed9a66</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.admin&quot;, false);</baddata><gooddata></gooddata><hash>86647ad6ef8c82b47a5beb862bd958a8</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.aflt&quot;, &quot;babsst&quot;);</baddata><gooddata></gooddata><hash>608a8bc507749b9b6c69a7ca33d1c838</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.appId&quot;, &quot;{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}&quot;);</baddata><gooddata></gooddata><hash>1dcdd47c6a11bd790fc65c15f311a858</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.autoRvrt&quot;, &quot;false&quot;);</baddata><gooddata></gooddata><hash>c52589c7aad175c16c69e78a16eebd43</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.dfltLng&quot;, &quot;de&quot;);</baddata><gooddata></gooddata><hash>bb2f1f315c1fea4c845120519272e719</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.excTlbr&quot;, false);</baddata><gooddata></gooddata><hash>777389c7d1aa2d09736276fbde26aa56</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.ffxUnstlRst&quot;, true);</baddata><gooddata></gooddata><hash>539727295922e4523e97e9885fa56c94</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.id&quot;, &quot;fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>b8329db37ffc003642935e13ca3ad828</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.instlDay&quot;, &quot;15925&quot;);</baddata><gooddata></gooddata><hash>d31769e77902b6805184ee8345bfc23e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.instlRef&quot;, &quot;sst&quot;);</baddata><gooddata></gooddata><hash>5a9084cc403b5dd94d8895dc5fa50cf4</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.newTab&quot;, false);</baddata><gooddata></gooddata><hash>59911e32314a0234dff6521f7a8a5ca4</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.prdct&quot;, &quot;delta&quot;);</baddata><gooddata></gooddata><hash>bf2b6ae6b6c540f6ffd6571af50f639d</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.prtnrId&quot;, &quot;delta&quot;);</baddata><gooddata></gooddata><hash>33b79eb263186dc918bd7ff248bc46ba</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.rvrt&quot;, &quot;false&quot;);</baddata><gooddata></gooddata><hash>db0fcd831d5e65d1b91cda97857f27d9</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.smplGrp&quot;, &quot;none&quot;);</baddata><gooddata></gooddata><hash>2dbdff51522981b5419499d8857f28d8</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.tlbrId&quot;, &quot;base&quot;);</baddata><gooddata></gooddata><hash>1ecc56fa8deeb185ce0796dbc83cad53</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.tlbrSrchUrl&quot;, &quot;&quot;);</baddata><gooddata></gooddata><hash>8961a5abe299a2942ca93938e51f4bb5</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.vrsn&quot;, &quot;1.8.22.0&quot;);</baddata><gooddata></gooddata><hash>569479d75b203afc5184ee8313f142be</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.vrsnTs&quot;, &quot;1.8.22.015:56:44&quot;);</baddata><gooddata></gooddata><hash>0dddde7284f70e2807ce472a1fe5ea16</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta.vrsni&quot;, &quot;1.8.22.0&quot;);</baddata><gooddata></gooddata><hash>dc0e59f70b7059ddbc197cf5a75ddd23</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta_i.babExt&quot;, &quot;&quot;);</baddata><gooddata></gooddata><hash>effb76da2a51ca6ce6eff1800004d22e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta_i.babTrack&quot;, &quot;affID=121564&amp;tt=070813_wt3&amp;tsp=4968&quot;);</baddata><gooddata></gooddata><hash>04e670e01269da5c5d7880f1fd0732ce</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js</path><vendor>PUP.Optional.Delta.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.delta_i.srcExt&quot;, &quot;ss&quot;);</baddata><gooddata></gooddata><hash>dd0db7993c3f7fb794411d54c63ef20e</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.babTrack&quot;, &quot;affID=110819&amp;tt=100512_4_&quot;);</baddata><gooddata></gooddata><hash>8f5b78d87b003afc2c1cf47d0004eb15</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.babExt&quot;, &quot;&quot;);</baddata><gooddata></gooddata><hash>6486aca4007bb38314346908ab59ce32</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.srcExt&quot;, &quot;ss&quot;);</baddata><gooddata></gooddata><hash>06e4e46c6912ab8b92b683ee6e96d62a</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.id&quot;, &quot;fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>35b52e22daa1a78f390f710051b340c0</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.hardId&quot;, &quot;fce15e28000000000000002522ce01c6&quot;);</baddata><gooddata></gooddata><hash>37b39bb5eb908fa7fa4ed79a30d4c33d</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.instlDay&quot;, &quot;15472&quot;);</baddata><gooddata></gooddata><hash>c02a5ff1fb80102607416b06b64e0000</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.vrsn&quot;, &quot;1.5.3.17&quot;);</baddata><gooddata></gooddata><hash>86640c44f9825ed84cfc274a22e201ff</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.vrsni&quot;, &quot;1.5.3.17&quot;);</baddata><gooddata></gooddata><hash>8b5ff55b80fb092dee5a7df4ff059868</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.vrsnTs&quot;, &quot;1.5.3.1720:58:29&quot;);</baddata><gooddata></gooddata><hash>23c729274239989e80c82849a16335cb</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.prtnrId&quot;, &quot;babylon&quot;);</baddata><gooddata></gooddata><hash>cf1bbd93562561d54cfc4e23d52f946c</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.prdct&quot;, &quot;BabylonToolbar&quot;);</baddata><gooddata></gooddata><hash>2ebcc987671446f0ec5c8fe219ebac54</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.aflt&quot;, &quot;babsst&quot;);</baddata><gooddata></gooddata><hash>07e30f414536082e3612b8b9986cc33d</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.smplGrp&quot;, &quot;none&quot;);</baddata><gooddata></gooddata><hash>3eac331d2f4c290db4946011e81cab55</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.tlbrId&quot;, &quot;tb9&quot;);</baddata><gooddata></gooddata><hash>de0c62eeabd0ff3749ff650c7f8538c8</hash></file>
<file><path>C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref(&quot;extensions.BabylonToolbar_i.instlRef&quot;, &quot;sst&quot;);</baddata><gooddata></gooddata><hash>f7f34010156694a2d870ef8227dd8d73</hash></file>
</items>
</mbam-log>
         
AdwCleaner:

AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.208 - Bericht erstellt am 13/05/2014 um 11:44:53
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Libelle - PC
# Gestartet von : C:\Users\Libelle\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\DeviceVM
Ordner Gelöscht : C:\Program Files (x86)\Softonic
Ordner Gelöscht : C:\Users\Libelle\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\Libelle\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Libelle\AppData\Roaming\DeviceVM
Ordner Gelöscht : C:\Users\Libelle\AppData\Roaming\dvdvideosoftiehelpers
Datei Gelöscht : C:\Users\Libelle\Desktop\Youtube.lnk
Datei Gelöscht : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\invalidprefs.js
Datei Gelöscht : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_clonedvd_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_clonedvd_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-youtube-download_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-youtube-download_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Softonic

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Mozilla Firefox v29.0.1 (de)

[ Datei : C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\nzf25kdk.default\prefs.js ]

Zeile gelöscht : user_pref("bearsharemediabar.Var1", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var10", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var2", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var3", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var4", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var5", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var6", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var7", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var8", "0");
Zeile gelöscht : user_pref("bearsharemediabar.Var9", "0");
Zeile gelöscht : user_pref("bearsharemediabar.firstlaunch", "0");
Zeile gelöscht : user_pref("bearsharemediabar.guid", "%7B2C1A1497-5376-0D55-73B6-2E42CF04E463%7D");
Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.babExt", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=100512_4_");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.hardId", "fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.id", "fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.instlDay", "15472");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", true);
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=110819&tt=100512_4_&babsrc=NT_ss&mntrId=fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1720:58:29");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Zeile gelöscht : user_pref("extensions.Softonic.admin", false);
Zeile gelöscht : user_pref("extensions.Softonic.aflt", "SD");
Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true);
Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false);
Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false);
Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true);
Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=13&cc=&mi=fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.Softonic.hpOld0", "hxxp://www.google.at|hxxp://de.pons.eu/");
Zeile gelöscht : user_pref("extensions.Softonic.id", "fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "15874");
Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00006");
Zeile gelöscht : user_pref("extensions.Softonic.kw_url", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=2&cc=&mi=fce15e28000000000000002522ce01c6&q=");
Zeile gelöscht : user_pref("extensions.Softonic.newTab", true);
Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00006/tb_v1/?SearchSource=15&cc=&mi=fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false");
Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "BASEirobinhoodActive");
Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=1&cc=&mi=fce15e28000000000000002522ce01c6&q=");
Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.19.3");
Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.19.39:56:28");
Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.19.3");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "fce15e28000000000000002522ce01c6");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15925");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.22.0");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.22.015:56:44");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.22.0");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121564&tt=070813_wt3&tsp=4968");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.facemoods.aflt", "_#ironto");
Zeile gelöscht : user_pref("extensions.facemoods.firstRun", false);
Zeile gelöscht : user_pref("extensions.facemoods.lastActv", "14");
Zeile gelöscht : user_pref("extensions.ffxtlbr@delta.com.install-event-fired", true);
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", true);
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "at");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "snapdoocyb");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "e2104eac-9743-4275-82eb-98b205103149");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "31/05/2013");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "snapdoocyb");

-\\ Google Chrome v

*************************

AdwCleaner[R0].txt - [14807 octets] - [13/05/2014 11:37:10]
AdwCleaner[S0].txt - [14322 octets] - [13/05/2014 11:44:53]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14383 octets] ##########
         
--- --- ---


Junkware Removal Tool:
JRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Libelle on 13.05.2014 at 11:49:02,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4118839908-2255762619-2302489997-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E17E02ED-3C1F-4989-A889-B0611CDF9C26}



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [File] C:\user.js
Emptied folder: C:\Users\Libelle\AppData\Roaming\mozilla\firefox\profiles\nzf25kdk.default\minidumps [159 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.05.2014 at 11:59:02,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---



Und hier noch FRST (ist hier alles ok mit dem Scan, dass das nur so ein kurzer Bericht nur mit Datum ist?):

Code:
ATTFilter

LastRegBack: 2014-05-09 10:46

==================== End Of Log ============================
         

Wie sieht es denn jetzt aus? Wie gesagt, ich kann das hier alles nicht wirklich deuten... Könntest du mir vielleicht sagen, welches Programm ich in Zukunft nutzen könnte, um soviel Adware wie jetzt zu vermeiden? Gibt es da irgendein Programm, mit dem ich regelmäßig scannen bzw. dann Gefundenes auch (gefahrlos...) entfernen könnte?

Vielen Dank für deine Hilfe und viele Grüße,
jvc





Hallo nochmal,

ich hätte noch eine kleine Ergänzung: ich wollte vorhin ein Video auf der Seite einer ausländischen Tageszeitung ansehen, als der Flashplayer schon wieder abgestürzt ist (wie gesagt, ich weiß leider nicht, ob die beiden Probleme zusammenhängen). Das mit den Abstürzen des Flashplayers (immer bei Internetvidos) geht nun schon seit vielen Monaten so...
Diesmal kamen folgende Fehlermeldungen:

1.
Warnung: nicht antwortendes Plugin
Shockwave Flash ist möglicherweise beschäftigt oder reagiert nicht mehr. Sie können das Plugin jetzt stoppen oder fortsetzen, um zu sehen, ob das Plugin weiter arbeitet.
-> ich gehe dann immer auf "stoppen", sonst geht nämlich gar nichts mehr.

Dann kam die 2. Meldung:
Warnung: Nicht antwortendes Skript
Ein Script auf dieser Seite ist eventuell beschäftigt oder es antwortet nicht mehr. Sie können das Skript jetzt stoppen oder fortsetzen, um zu sehen, ob das Skript fertig wird.
Skript: https://apis.google.com/js/plusone.js:13
-> auch hier gehe ich dann auf "stoppen", da sonst nichts mehr geht

Und dann noch die 3. Meldung - das kleine graue Flashplayer-Fenster mit einem nach unten gerichteten Smiley und folgender Text (kenn ich inzw. schon auswendig... ;-) ):
Das Plugin "Adobe Flash" ist abgestürzt. Firefox stürzt ständig ab, um es erneut zu versuchen.


Oft kommt auch nur die 3. Meldung alleine. Ich habe schon viele Flashplayer-Versionen ausprobiert, x-mal neu installiert (vorher komplett deinstalliert) und auch Firefox neu installiert, bisher war alles umsonst. Ich habe auch viel in Foren gelesen, jedoch nie eine Lösung gefunden, was bei anderen geholfen hat, nützte bei mir nie etwas.

Wie gesagt, ich weiß ja nicht, ob die Probleme zusammengehören, ich wollte dir die Fehlermeldungen nur aufschreiben, vielleicht ist das für dich ja ein Hinweis auf etwas.

Vielen Dank und noch einen schönen Tag,
jvc







Hallo schrauber, jetzt muss ich leider nochmal ein Update machen...
Falls das für dich wichtig ist, Firefox ist vorhin wieder abgestürzt - mit der üblichen Meldung (Entschuldigung, das hätte nicht passieren dürfen), danach schließen sich alle geöffneten Firefox-Fenster.

Ich dachte, vielleicht ist das wichtig für dich als Info...
Dankeschön und noch einen schönen Abend,
jvc


Alt 14.05.2014, 19:16   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Revo Uninstaller - Download - Filepony
damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.

Dann:
https://support.mozilla.org/de/kb/fi...einfach-loesen


Scan auf Reste:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
--> Firefox stürzt ständig ab

Alt 15.05.2014, 13:56   #7
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo schrauber,

vielen Dank für deine Nachricht! Ich hätte jetzt noch eine Frage, bevor ich alle Schritte durchführe: wenn ich Firefox deinstalliere, werden dann alle meine gespeicherten Links gelöscht? Es sind nämlich ziemlich viele und die müsste ich dann vorher irgendwie sichern...

Dankeschön!
jvc

Alt 16.05.2014, 11:16   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Die kannste vorher exportieren, aber sonst bitte nichts aus Firefox speichern.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 17.05.2014, 14:22   #9
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo schrauber,

habe nun versucht, das zu machen, was du mir beschrieben hast - leider gab es schon beim ersten Schritt ein mittelmäßiges Drama. Ich habe Firefox mit dem Revo Uninstaller entfernt, gegen Ende des Vorgangs kamen jedoch einige Fragen (es kamen 2 Listen mit Dateien, die Frage war, ob ich die alle entfernen möchte (ich glaube auch Registry-Einträge, weiß es jedoch nicht mehr genau) - da du geschrieben hast, keine Daten behalten, hab ich sämtliche Dateien markiert und gelöscht). Das hat dann soweit auch funktioniert. Dann wollte ich jedoch mit dem Internet Explorer (den ich sonst nie benutze) Firefox downloaden, der Explorer funktionierte jedoch überhaupt nicht richtig! Es ließen sich keine Seiten laden (Internet-Verbindung war jedoch ok, ich konnte meine Mails abrufen), nach einer halben Stunde hat er dann irgendwann Google geladen, ich konnte jedoch keine einzige Seite daraus öffnen. Ich habe dann irgendwann gemerkt, dass ich zwar jeweils die Startseiten laden konnte (zb Google, Tageszeitungen, Mozilla), aber wenn ich innerhalb dieser Seiten eine weitere Seite öffnen wollte, tat sich einfach gar nichts, es öffnete sich ein leeres Fenster, aber nichts ladete (daher große Panik bei mir, weil ich das Internet beruflich dringend brauche).
Ich habe dann über meinen alten Laptop das Firefox-Setup heruntergeladen und das dann installiert. Jetzt funktioniert wieder alles, allerdings glaube ich, dass vorher schon beim Deinstallieren etwas schief gegangen ist, denn nach der Firefox-Installation waren weder meine Links gelöscht noch sonstige Einstellungen (Add-ons), es sah alles aus wie vorher...

Die weiteren Scans habe ich jetzt daher nicht gemacht, da ich nicht glaube, dass das richtig funktioniert hat. Ich weiß nicht, ob ich mich das mit Revo noch einmal traue, ich glaube, ich bräuchte genauere Anweisungen, was ich während dieses Prozesses ganz genau anklicken soll, da ich mich damit nicht auskenne.

Ich kann mir auch nicht erklären, warum nachher der Internet Explorer nicht funktioniert hat, ich hätte nicht einmal im Internet recherchieren und nach Lösungen suchen können...
Der Internet Explorer funktioniert übrigens immer noch nicht, meistens kommt folgende Meldung: Die Navigation zu der Webseite wurde abgebrochen (oder einfach gar nichts und er versucht auch gar nicht, eine Seite zu laden)

Vielen Dank!!

Geändert von jvc (17.05.2014 um 14:29 Uhr)

Alt 18.05.2014, 12:24   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hast Du den Firefox auch nach dem neuen INstallieren zurückgesetzt wie oben angegeben??
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 18.05.2014, 14:18   #11
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo,
also, ich hab nur den ersten Schritt gemacht (mit dem Revo Uninstaller), da dann bei Firefox noch alle Daten wie vorher vorhanden waren, habe ich nicht mehr weitergemacht, da ich dachte, es hat nicht funktioniert und ich frage besser vorher bei dir nach..

Was meinst du, was ich jetzt am Besten machen soll? Vielen Dank und einen schönen Sonntag!

Alt 19.05.2014, 09:34   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



FF zurücksetzen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 19.05.2014, 17:42   #13
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo schrauber,

danke für die Antwort, aber was bedeutet Firefox zurücksetzen..? Soll ich danach mit den restlichen Schritten weitermachen (das hier https://support.mozilla.org/de/kb/fi...einfach-loesen, ESET und Security Check)?

Danke!

Geändert von jvc (19.05.2014 um 17:49 Uhr)

Alt 20.05.2014, 11:48   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Der von dir zitierte Link zeigt doch das Zurücksetzen von Firefox . Ja mach das alles.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.05.2014, 18:11   #15
jvc
 
Firefox stürzt ständig ab - Standard

Firefox stürzt ständig ab



Hallo schrauber,

vielen Dank für deine Antwort, jetzt hab ich's verstanden!! ;-)

Hier kommt erstmal der ESET Scan, es gab 10 Funde, der Rest kommt dann gleich

Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=a6bcec977effcd4a913ae78ed3c960e7
# engine=18336
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=false
# utc_time=2014-05-20 04:55:21
# local_time=2014-05-20 06:55:21 (+0100, Mitteleuropäische Sommerzeit)
# country="Austria"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 76 376728 2077420 0 0
# compatibility_mode=5893 16776573 100 94 17392 152234771 0 0
# scanned=211549
# found=10
# cleaned=0
# scan_time=11152
sh=095DF1429E4F8DBE71EE72AEE04090E6A8F35931 ft=1 fh=749ee4b2bcea0726 vn="Variante von Win32/DownloadSponsor.A evtl. uner-wünschte Anwendung" ac=I fn="E:\Downloads Programme\PDF24 Creator.exe"
sh=49892F2B31FDE87333BA9AD84222DA7493E6AC98 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Babylon.F evtl. uner-wünschte Anwendung" ac=I fn="E:\PC\Backup Set 2012-04-23 110626\Backup Files 2012-06-01 121107\Backup files 1.zip"
sh=C6BC5D1905E0D1708C558B868AD764E1B6FF3DFB ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\PC\Backup Set 2012-04-23 110626\Backup Files 2012-09-01 131437\Backup files 3.zip"
sh=F966F62E111A5C3E7A15687419EE8D2A71B6A7C4 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="E:\PC\Backup Set 2012-10-01 113843\Backup Files 2012-10-01 113843\Backup files 5.zip"
sh=0B81499A6E75C8860868AEA41018272A33FCEB48 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2013-06-01 102200\Backup Files 2013-06-01 102200\Backup files 1.zip"
sh=E7063D47F1D2936DF344F039F1C9FA4857C3E8C1 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2013-09-01 122740\Backup Files 2013-09-01 122740\Backup files 1.zip"
sh=276C8018079581296B484C1E25E483F437C6D7C9 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2013-11-01 123144\Backup Files 2013-11-01 123144\Backup files 1.zip"
sh=7CAABE77E57FF26D357C22279B91FD926BA4B0CC ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2014-01-01 125203\Backup Files 2014-01-01 125203\Backup files 1.zip"
sh=8FBA19CF36F8D7440DB7EB21DB3A147DA0E6DEF8 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2014-03-01 102548\Backup Files 2014-03-01 102548\Backup files 1.zip"
sh=C9FD395FFDA8587F0656929505273AF55AA25A1F ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung" ac=I fn="E:\PC\Backup Set 2014-05-01 120325\Backup Files 2014-05-01 120325\Backup files 2.zip"
         

Hier das Ergebnis von SecurityCheck:

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.83  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Spybot - Search & Destroy 
 Adobe Flash Player 13.0.0.214  
 Adobe Reader XI  
 Mozilla Firefox (29.0.1) 
 Mozilla Thunderbird (24.5.0) 
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Spybot Teatimer.exe is disabled! 
 Malwarebytes Anti-Malware mbamscheduler.exe   
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         

Und hier noch FRST.log

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by Libelle (administrator) on PC on 20-05-2014 19:21:11
Running from C:\Users\Libelle\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Informatic Ltd.) C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Geek Software GmbH) E:\Programme\PDF24\pdf24.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe
(Adobe Systems Inc.) E:\Programme\Adobe Pro\Acrobat\acrotray.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(FNet Co., Ltd.) C:\Program Files (x86)\XFastUsb\XFastUsb.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\AmbRunE.dll [17920 2009-02-26] (Creative Technology Ltd.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3019376 2011-02-22] (VIA)
HKLM-x32\...\Run: [XFastUsb] => C:\Program Files (x86)\XFastUsb\XFastUsb.exe [4942336 2012-04-18] (FNet Co., Ltd.)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe [241789 2009-05-04] (Creative Technology Ltd)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office 2010\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-26] (AVAST Software)
HKLM-x32\...\Run: [PDFPrint] => E:\Programme\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => E:\Programme\Adobe Pro\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4118839908-2255762619-2302489997-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2068856 2011-10-12] (Flexera Software LLC.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ORFO Agent.lnk
ShortcutTarget: ORFO Agent.lnk -> C:\Program Files (x86)\Informatic\ORFO 9.0\orfagent.exe (Informatic Ltd.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3097DBB87D1DCD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK
SearchScopes: HKCU - {D4DC2C6E-7CE3-47a9-9224-D11F8999EB99} URL = http://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Dragon NaturallySpeaking Rich Internet Application Support - Extension - {73A89C60-CF59-4EC7-9215-9B7EF05ECEA4} - E:\Dragon Naturally Speaking 12 Deutsch\Program\ieShim.dll (Nuance Communications, Inc.)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{EDEF3BBF-1341-4E63-9148-8934BB617129}: [NameServer]130.244.127.161,130.244.127.169

FireFox:
========
FF ProfilePath: C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\dhylyhti.default-1400592478296
FF Homepage: www.google.at | hxxp://de.pons.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.669 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - E:\Programme\Adobe Pro\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: nuance.com/DragonRIAPlugin - E:\DRAGON~4\Program\npDgnRia.dll (Nuance Communications Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Classic Theme Restorer - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\dhylyhti.default-1400592478296\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-20]
FF Extension: Adblock Plus - C:\Users\Libelle\AppData\Roaming\Mozilla\Firefox\Profiles\dhylyhti.default-1400592478296\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-20]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: No Name - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-06-24]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-04-19]
FF HKLM-x32\...\Firefox\Extensions: [jid0-lmZNVK7a82O8cufhdfB9dUDfA2w@jetpack] - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi
FF Extension: Dragon NaturallySpeaking Rich Internet Application Support - E:\Dragon Naturally Speaking 12 Deutsch\Program\ffShim.xpi [2013-02-11]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - E:\Programme\Adobe Pro\Acrobat\Browser\WCFirefoxExtn [2014-04-22]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - E:\Programme\Adobe Pro\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21]
CHR HKLM-x32\...\Chrome\Extension: [mikhcaiakabeeokmenglcdebplfdjicn] - E:\Dragon Naturally Speaking 12 Deutsch\Program\chromeShim.crx [2013-02-11]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-26] (AVAST Software)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office 2010\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S4 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-02-17] (VIA Technologies, Inc.)

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-26] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-26] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-26] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-26] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-26] ()
R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2012-04-18] (FNet Co., Ltd.)
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-04-18] (FNet Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-20 19:21 - 2014-05-20 19:21 - 00018168 _____ () C:\Users\Libelle\Desktop\FRST.txt
2014-05-20 19:21 - 2014-05-20 19:21 - 00000000 ____D () C:\Users\Libelle\Desktop\FRST-OlderVersion
2014-05-20 19:13 - 2014-05-20 19:13 - 00854367 _____ () C:\Users\Libelle\Desktop\SecurityCheck.exe
2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Downloads\esetsmartinstaller_deu(1).exe
2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Desktop\esetsmartinstaller_deu.exe
2014-05-20 15:28 - 2014-05-20 15:28 - 00000000 ____D () C:\Users\Libelle\Desktop\Alte Firefox-Daten
2014-05-17 15:06 - 2014-05-17 15:06 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-17 15:06 - 2014-05-17 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-17 13:34 - 2014-05-17 13:34 - 00000729 _____ () C:\Users\Libelle\Desktop\Revo Uninstaller.lnk
2014-05-17 13:33 - 2014-05-17 13:33 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Libelle\Desktop\revosetup95.exe
2014-05-17 13:20 - 2014-05-17 13:20 - 00120822 _____ () C:\Users\Libelle\Desktop\bookmarks-2014-05-17.json
2014-05-17 13:16 - 2014-05-17 13:16 - 00000676 _____ () C:\Users\Libelle\Desktop\Youtube.lnk
2014-05-15 05:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 05:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 05:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 05:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 05:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 05:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-15 04:55 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 04:55 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 04:55 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 04:55 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 04:55 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 04:55 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 04:55 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 04:55 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 04:55 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 04:55 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-15 04:55 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-15 04:55 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 04:55 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-15 04:55 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 04:55 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 04:55 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 04:55 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 04:55 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 04:55 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 04:55 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 04:55 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 04:55 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 04:55 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-15 04:55 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-15 04:55 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-15 04:55 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-15 04:55 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-15 04:55 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 11:49 - 2014-05-13 11:49 - 00000000 ____D () C:\Windows\ERUNT
2014-05-13 11:48 - 2014-05-13 11:48 - 01016261 _____ (Thisisu) C:\Users\Libelle\Desktop\JRT.exe
2014-05-13 11:37 - 2014-05-13 11:44 - 00000000 ____D () C:\AdwCleaner
2014-05-13 11:37 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-13 11:36 - 2014-05-13 11:36 - 01325827 _____ () C:\Users\Libelle\Desktop\adwcleaner.exe
2014-05-13 11:24 - 2014-05-20 19:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-13 11:24 - 2014-05-13 11:24 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-13 11:24 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-13 11:24 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-13 11:24 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-12 11:13 - 2014-05-12 11:13 - 00024191 _____ () C:\ComboFix.txt
2014-05-12 11:04 - 2014-05-12 11:13 - 00000000 ____D () C:\Qoobox
2014-05-12 11:04 - 2014-05-12 11:11 - 00000000 ____D () C:\Windows\erdnt
2014-05-12 11:04 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-12 11:04 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-12 11:04 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-12 11:04 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-12 11:04 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-12 11:04 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-12 11:04 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-12 11:04 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-12 11:02 - 2014-05-12 11:03 - 05200347 ____R (Swearware) C:\Users\Libelle\Desktop\ComboFix.exe
2014-05-11 19:14 - 2014-05-11 19:14 - 00380416 _____ () C:\Users\Libelle\Desktop\Gmer-19357.exe
2014-05-11 19:02 - 2014-05-11 19:02 - 00380416 _____ () C:\Users\Libelle\Downloads\Gmer-19357.exe
2014-05-11 18:53 - 2014-05-20 19:21 - 00000000 ____D () C:\FRST
2014-05-11 18:51 - 2014-05-11 18:38 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe
2014-05-11 18:50 - 2014-05-20 19:21 - 02067456 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe
2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList
2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-05-07 18:24 - 2014-05-07 18:25 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-04 23:32 - 2014-05-20 18:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-04 23:32 - 2014-05-14 19:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-04 23:32 - 2014-05-14 19:28 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-04 23:32 - 2014-05-14 19:28 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-30 10:52 - 2014-05-15 14:18 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-29 23:43 - 2014-04-30 08:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex
2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-22 11:30 - 2014-04-26 09:51 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-04-22 11:30 - 2014-04-26 09:51 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-04-22 11:30 - 2014-04-26 09:51 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24

==================== One Month Modified Files and Folders =======

2014-05-20 19:21 - 2014-05-20 19:21 - 00018168 _____ () C:\Users\Libelle\Desktop\FRST.txt
2014-05-20 19:21 - 2014-05-20 19:21 - 00000000 ____D () C:\Users\Libelle\Desktop\FRST-OlderVersion
2014-05-20 19:21 - 2014-05-11 18:53 - 00000000 ____D () C:\FRST
2014-05-20 19:21 - 2014-05-11 18:50 - 02067456 _____ (Farbar) C:\Users\Libelle\Desktop\FRST64.exe
2014-05-20 19:13 - 2014-05-20 19:13 - 00854367 _____ () C:\Users\Libelle\Desktop\SecurityCheck.exe
2014-05-20 19:11 - 2013-03-04 22:40 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-20 19:01 - 2014-05-13 11:24 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-20 18:28 - 2014-05-04 23:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-20 15:45 - 2012-04-18 22:45 - 01420435 _____ () C:\Windows\WindowsUpdate.log
2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Downloads\esetsmartinstaller_deu(1).exe
2014-05-20 15:38 - 2014-05-20 15:38 - 02347384 _____ (ESET) C:\Users\Libelle\Desktop\esetsmartinstaller_deu.exe
2014-05-20 15:36 - 2011-04-12 09:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-05-20 15:36 - 2011-04-12 09:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-05-20 15:36 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-20 15:28 - 2014-05-20 15:28 - 00000000 ____D () C:\Users\Libelle\Desktop\Alte Firefox-Daten
2014-05-20 13:06 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-20 13:06 - 2009-07-14 06:45 - 00022064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-20 12:59 - 2013-03-04 22:40 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-20 12:59 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-20 12:59 - 2009-07-14 06:51 - 00164725 _____ () C:\Windows\setupact.log
2014-05-20 01:38 - 2012-04-22 14:10 - 00000000 ____D () C:\Users\Libelle\Desktop\Lydia
2014-05-19 20:36 - 2012-09-08 14:45 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Skype
2014-05-18 11:28 - 2012-05-03 11:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-17 15:30 - 2012-04-19 11:46 - 00000000 ____D () C:\Users\Libelle\Desktop\Utilities
2014-05-17 15:06 - 2014-05-17 15:06 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-17 15:06 - 2014-05-17 15:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-17 13:34 - 2014-05-17 13:34 - 00000729 _____ () C:\Users\Libelle\Desktop\Revo Uninstaller.lnk
2014-05-17 13:33 - 2014-05-17 13:33 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Libelle\Desktop\revosetup95.exe
2014-05-17 13:20 - 2014-05-17 13:20 - 00120822 _____ () C:\Users\Libelle\Desktop\bookmarks-2014-05-17.json
2014-05-17 13:16 - 2014-05-17 13:16 - 00000676 _____ () C:\Users\Libelle\Desktop\Youtube.lnk
2014-05-17 13:14 - 2012-06-24 16:12 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\vlc
2014-05-16 10:56 - 2013-06-13 16:03 - 00000000 ____D () C:\Windows\rescache
2014-05-15 14:22 - 2014-03-22 22:35 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-15 14:22 - 2012-04-19 14:20 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-05-15 14:22 - 2012-04-19 14:20 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-05-15 14:19 - 2012-04-18 16:36 - 00000000 ___RD () C:\Users\Libelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 14:19 - 2012-04-18 16:36 - 00000000 ___RD () C:\Users\Libelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:18 - 2014-04-30 10:52 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 05:43 - 2012-05-28 15:40 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 05:41 - 2013-07-25 11:06 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 05:40 - 2012-04-19 13:54 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 19:28 - 2014-05-04 23:32 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-14 19:28 - 2014-05-04 23:32 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-14 19:28 - 2014-05-04 23:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 11:49 - 2014-05-13 11:49 - 00000000 ____D () C:\Windows\ERUNT
2014-05-13 11:48 - 2014-05-13 11:48 - 01016261 _____ (Thisisu) C:\Users\Libelle\Desktop\JRT.exe
2014-05-13 11:45 - 2010-11-21 05:47 - 00907418 _____ () C:\Windows\PFRO.log
2014-05-13 11:44 - 2014-05-13 11:37 - 00000000 ____D () C:\AdwCleaner
2014-05-13 11:36 - 2014-05-13 11:36 - 01325827 _____ () C:\Users\Libelle\Desktop\adwcleaner.exe
2014-05-13 11:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources
2014-05-13 11:24 - 2014-05-13 11:24 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-13 11:24 - 2014-05-13 11:24 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-05-12 11:13 - 2014-05-12 11:13 - 00024191 _____ () C:\ComboFix.txt
2014-05-12 11:13 - 2014-05-12 11:04 - 00000000 ____D () C:\Qoobox
2014-05-12 11:11 - 2014-05-12 11:04 - 00000000 ____D () C:\Windows\erdnt
2014-05-12 11:11 - 2012-05-12 21:03 - 00000000 ____D () C:\Users\Libelle\AppData\Local\CrashDumps
2014-05-12 11:11 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-05-12 11:03 - 2014-05-12 11:02 - 05200347 ____R (Swearware) C:\Users\Libelle\Desktop\ComboFix.exe
2014-05-11 19:14 - 2014-05-11 19:14 - 00380416 _____ () C:\Users\Libelle\Desktop\Gmer-19357.exe
2014-05-11 19:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-11 19:02 - 2014-05-11 19:02 - 00380416 _____ () C:\Users\Libelle\Downloads\Gmer-19357.exe
2014-05-11 18:38 - 2014-05-11 18:51 - 00050477 _____ () C:\Users\Libelle\Desktop\Defogger.exe
2014-05-11 18:38 - 2014-05-11 18:38 - 00000000 _____ () C:\Users\Libelle\defogger_reenable
2014-05-11 18:38 - 2012-04-18 16:36 - 00000000 ____D () C:\Users\Libelle
2014-05-11 18:20 - 2012-07-17 22:28 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-09 11:06 - 2013-03-04 22:40 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-09 11:06 - 2013-03-04 22:40 - 00003856 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-09 08:14 - 2014-05-15 04:55 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 04:55 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieUserList
2014-05-08 15:31 - 2014-05-08 15:31 - 00000000 __SHD () C:\Users\Libelle\AppData\Local\EmieSiteList
2014-05-07 18:25 - 2014-05-07 18:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-05-07 18:25 - 2014-05-07 18:24 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-06 06:40 - 2014-05-15 05:42 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 05:42 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 05:42 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 05:42 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-04 23:32 - 2012-04-19 11:29 - 00000000 ____D () C:\Downloads Programme
2014-05-04 23:32 - 2012-04-18 18:46 - 00000000 ____D () C:\Users\Libelle\AppData\Local\Adobe
2014-05-04 23:30 - 2012-04-18 18:26 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-04-30 08:59 - 2014-04-29 23:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-26 17:51 - 2014-04-26 17:51 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-26 17:51 - 2014-04-26 17:51 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-26 17:51 - 2013-03-21 15:18 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-26 17:51 - 2013-03-21 15:18 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-26 17:51 - 2012-04-19 14:20 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400156538465
2014-04-26 17:51 - 2012-04-19 14:20 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400156538465
2014-04-26 17:51 - 2012-04-19 14:20 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-26 17:51 - 2012-04-19 14:20 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-26 17:51 - 2012-04-19 14:20 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-26 09:51 - 2014-04-22 11:30 - 00002453 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2014-04-26 09:51 - 2014-04-22 11:30 - 00001784 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2014-04-26 09:51 - 2014-04-22 11:30 - 00001661 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2014-04-26 09:48 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-04-22 17:40 - 2009-07-14 06:45 - 00399824 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-22 13:59 - 2012-04-18 23:36 - 00101920 _____ () C:\Users\Libelle\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-22 11:35 - 2014-04-22 11:35 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\PDAppFlex
2014-04-22 11:32 - 2012-04-18 18:26 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\Adobe
2014-04-22 11:31 - 2014-04-22 11:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-22 11:31 - 2012-04-18 18:26 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-22 11:30 - 2014-04-22 11:30 - 00001652 _____ () C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000818 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
2014-04-22 11:14 - 2014-04-22 11:14 - 00000000 ____D () C:\Users\Libelle\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\Users\Libelle\AppData\Local\PDF24
2014-04-21 22:22 - 2014-04-21 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2014-04-20 01:57 - 2013-12-18 00:20 - 00000000 ____D () C:\Users\Libelle\Desktop\jin shin

Files to move or delete:
====================
C:\ProgramData\ezsid.dat


Some content of TEMP:
====================
C:\Users\Libelle\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe
[2014-05-15 04:55] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-05-19 19:16

==================== End Of Log ============================
         
--- --- ---



Was sagen dir denn die Ergebnisse? Wie gesagt, ich kann das ja alles nicht deuten...
Ich probiere jetzt mal 2-3 Tage, dann würde ich dir wieder Bescheid geben, wie Firefox läuft (außer wir müssen vorher noch etwas reparieren aufgrund der Logs)

Dankeschön!!

Geändert von jvc (20.05.2014 um 18:23 Uhr)

Antwort

Themen zu Firefox stürzt ständig ab
absturz, adobe flashplayer, antivirus, association, bildschirm, blockiert, browser, dvdvideosoft ltd., excel, firefox, flash player, google, helper, home, homepage, hängt, iexplore.exe, mp3, object, problem, programm, registry, safer networking, security, software, super, svchost.exe, system, trojaner, virus




Ähnliche Themen: Firefox stürzt ständig ab


  1. Firefox stürzt ständig ab und WLAN geht nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 08.11.2015 (16)
  2. Windows 7: Mozilla Firefox stürzt ständig ab, PC-Ahnen startet nicht
    Plagegeister aller Art und deren Bekämpfung - 17.09.2015 (26)
  3. Mozilla Firefox stürzt ständig ab
    Plagegeister aller Art und deren Bekämpfung - 16.07.2015 (11)
  4. Vista 64bit - Mozilla Firefox stürzt ständig ab
    Log-Analyse und Auswertung - 15.04.2015 (9)
  5. Firefox stürzt ständig ab/System voll mit Malware
    Plagegeister aller Art und deren Bekämpfung - 28.04.2014 (21)
  6. Firefox stürzt ständig ab und ab und zu ist ein bluescreen dabei
    Plagegeister aller Art und deren Bekämpfung - 06.03.2014 (14)
  7. Firefox stürzt ständig ab und Google findet Seiten nicht
    Log-Analyse und Auswertung - 17.01.2014 (9)
  8. Adware?! Firefox stürzt ständig ab-Avira findet nichts!
    Plagegeister aller Art und deren Bekämpfung - 05.01.2014 (10)
  9. Adware Heruntergeladen - Firefox stürzt ständig ab.
    Log-Analyse und Auswertung - 04.01.2014 (25)
  10. Firefox stürzt ständig ab !
    Plagegeister aller Art und deren Bekämpfung - 22.11.2013 (13)
  11. TR/Boigy.J' [trojan] Firefox stürzt ständig ab
    Plagegeister aller Art und deren Bekämpfung - 26.06.2013 (23)
  12. pesfdisk.exe -firefox stürzt ständig ab wie nie zuvor
    Plagegeister aller Art und deren Bekämpfung - 01.04.2013 (3)
  13. TROJANER? Firefox stürzt ständig ab, Pop-ups trotz Adblock Plus
    Plagegeister aller Art und deren Bekämpfung - 03.10.2012 (11)
  14. Virus blockiert Antiviren Sites; Firefox stürzt ständig ab
    Log-Analyse und Auswertung - 07.09.2012 (11)
  15. Firefox stürzt beim Start ständig ab
    Log-Analyse und Auswertung - 05.10.2010 (1)
  16. pc viel zu langsam und (beim hochfahren ) und FireFox stürzt ständig ab
    Log-Analyse und Auswertung - 07.11.2009 (1)
  17. Firefox stürzt ständig ab
    Log-Analyse und Auswertung - 15.10.2009 (2)

Zum Thema Firefox stürzt ständig ab - Hallo, da ihr mir schon ein paar Mal super geholfen habt, wende ich mich nun erneut mit einem Problem an euch und würde mich freuen, falls ihr mir weiterhelfen könnt. - Firefox stürzt ständig ab...
Archiv
Du betrachtest: Firefox stürzt ständig ab auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.