Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 28.11.2013, 16:47   #1
Penelope8282
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



Huhu,
seit ein paar Tagen habe ich ein paar Probleme mit Mozilla. Ständig öffnen sich Fenster (akamaihd.net) die aber dann auch nicht richtig angezeigt werden können. Wernebanner und gewisse Textanzeigen sind ganz verschwunden, Seiten dadurch anders aufgebaut und es steht überall von Ad´sby PlusHD. Ich weiss dass HD nerviger Adware ist und eigentlich habe ich es nicht aktiviert aber dennoch habe ich dadurch mit Mozilla Probleme. Vor allem nervt dass sich ständig neue Fenster öffnen. Jemand ne Idee wie ich das loswerden kann und das meine Seiten wieder richtig angezeigt werden?


Alt 28.11.2013, 17:28   #2
M-K-D-B
/// TB-Ausbilder
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6






Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 4 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo.
    Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort zu starten!
    Ich kann Dir niemals eine Garantie geben, dass auch ich alles finde. Eine Formatierung ist meist der schnellere und immer der sicherste Weg.
    Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass Du clean bist.





Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________


Alt 28.11.2013, 17:46   #3
Penelope8282
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-11-2013 01
Ran by Sonne (administrator) on HARLEY-DAVIDSON on 28-11-2013 17:44:31
Running from C:\Users\Sonne\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHndHkb.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Conduit) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
(Conduit) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
(Conduit) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe
(Conduit) C:\Users\Sonne\Desktop\AdwCleaner_brff.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\Sonne\Desktop\FRST64(1).exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-09] (Synaptics Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [PfNet] - C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6310912 2010-06-24] (FUJITSU LIMITED)
HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [188264 2009-07-30] (FUJITSU LIMITED)
HKLM\...\Run: [FDM7] - C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164712 2009-11-26] (FUJITSU LIMITED)
HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [157544 2009-10-15] (FUJITSU LIMITED)
HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [35176 2009-10-15] (FUJITSU LIMITED)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor)
HKLM\...\Run: [ConMgr] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe [535440 2009-12-24] (CSR, plc)
HKLM\...\Run: [CSRSkype] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe [431504 2009-12-24] (CSR, plc)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_Plugin.exe -update plugin [829832 2013-10-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LoadFUJ02E3] - C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe [36712 2009-10-08] (FUJITSU LIMITED)
HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [47976 2009-10-09] (FUJITSU LIMITED)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1316640 2013-10-31] (Conduit)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1008928 2013-10-31] (Conduit)
Startup: C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&q={searchTerms}&SSPV=
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default
FF NetworkProxy: "type", 0
FF Homepage: hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV=
FF SelectedSearchEngine: Conduit Search
FF NewTab: hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: Plus-HD-1.6 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com
FF Extension: Plus-HD-2.5 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\75c9b989-a6e6-4455-971f-45304161eb23@02648b91-49b2-4d7f-99ef-7e959a8e6505.com
FF Extension: noscript - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: Adblock Plus - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

Chrome: 
=======
CHR HomePage: http:\/\/search.conduit.com\/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV=
CHR RestoreOnStartup: "http:\/\/search.conduit.com\/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV="],"restore_on_startup":4},"tabs":{"use_compact_navigation_bar":false,"use_vertical_tabs":false},"webkit":{"webprefs":{"allow_running_insecure_content"
CHR Extension: (DealPly Shopping) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma\3.5.3.0_0
CHR Extension: (Plus-HD-2.5) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0
CHR Extension: (Plus-HD-1.6) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [1735968 2013-10-31] (Conduit)
R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [330240 2010-06-24] (FUJITSU LIMITED)
R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2009-07-30] (FUJITSU LIMITED)
R2 VFPRadioSupportService; C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [145840 2009-12-24] (CSR, plc)

==================== Drivers (Whitelisted) ====================

R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2009-12-24] (CSR, plc)
R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED)
R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
R4 GEARAspiWDM; system32\DRIVERS\GEARAspiWDM.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-28 17:44 - 2013-11-28 17:44 - 01958850 _____ (Farbar) C:\Users\Sonne\Desktop\FRST64(1).exe
2013-11-28 17:44 - 2013-11-28 17:44 - 00014781 _____ C:\Users\Sonne\Desktop\FRST.txt
2013-11-28 16:35 - 2013-11-28 16:39 - 00000000 ____D C:\Users\Sonne\AppData\Local\Mobogenie
2013-11-28 16:35 - 2013-11-28 16:36 - 00000000 ____D C:\Users\Sonne\AppData\Roaming\newnext.me
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\SearchProtect
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\.android
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 _____ C:\Users\Sonne\daemonprocess.txt
2013-11-28 16:34 - 2013-11-28 16:34 - 01125984 _____ (Conduit) C:\Users\Sonne\Desktop\AdwCleaner_brff.exe
2013-11-22 21:56 - 2013-11-28 16:01 - 00001008 _____ C:\Windows\setupact.log
2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log
2013-11-20 10:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-16 11:45 - 2013-11-16 11:51 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka
2013-11-13 09:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 09:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 09:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 09:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-13 09:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 09:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 09:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-13 09:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 09:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-13 09:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-13 09:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-13 09:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 09:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-13 09:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-13 09:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 09:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 09:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 09:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 09:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 09:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 09:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 09:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 09:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-13 09:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-13 09:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-13 09:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-13 09:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 09:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys

==================== One Month Modified Files and Folders =======

2013-11-28 17:45 - 2013-11-28 17:44 - 00014781 _____ C:\Users\Sonne\Desktop\FRST.txt
2013-11-28 17:44 - 2013-11-28 17:44 - 01958850 _____ (Farbar) C:\Users\Sonne\Desktop\FRST64(1).exe
2013-11-28 17:41 - 2013-03-28 19:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-28 17:22 - 2011-09-30 22:16 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-28 16:39 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\Mobogenie
2013-11-28 16:36 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Roaming\newnext.me
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\SearchProtect
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\.android
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Program Files (x86)\SearchProtect
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 _____ C:\Users\Sonne\daemonprocess.txt
2013-11-28 16:35 - 2013-10-02 19:36 - 00000000 ____D C:\Users\Sonne\AppData\Local\cache
2013-11-28 16:35 - 2011-09-30 22:23 - 00000000 ____D C:\Users\Sonne
2013-11-28 16:34 - 2013-11-28 16:34 - 01125984 _____ (Conduit) C:\Users\Sonne\Desktop\AdwCleaner_brff.exe
2013-11-28 16:01 - 2013-11-22 21:56 - 00001008 _____ C:\Windows\setupact.log
2013-11-28 14:55 - 2013-06-07 20:17 - 01918745 _____ C:\Windows\WindowsUpdate.log
2013-11-28 14:55 - 2011-09-30 22:16 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-25 14:29 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-25 14:29 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log
2013-11-22 20:54 - 2011-02-14 13:43 - 00000000 ____D C:\Windows\Panther
2013-11-21 08:25 - 2012-04-26 20:52 - 00006144 ____H C:\Users\Sonne\Desktop\photothumb.db
2013-11-20 13:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-20 10:15 - 2011-02-14 13:57 - 00697322 _____ C:\Windows\system32\perfh007.dat
2013-11-20 10:15 - 2011-02-14 13:57 - 00148328 _____ C:\Windows\system32\perfc007.dat
2013-11-20 10:15 - 2009-07-14 06:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-20 10:09 - 2011-09-30 22:34 - 00001431 _____ C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-20 10:08 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-20 10:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-17 21:01 - 2011-09-30 22:24 - 00000000 ____D C:\Users\Sonne\AppData\Local\Windows Live
2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-16 11:51 - 2013-11-16 11:45 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka
2013-11-15 15:25 - 2013-09-09 14:44 - 00002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-13 10:40 - 2013-07-09 10:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-11 05:50 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-04 01:13 - 2011-04-16 11:56 - 01591930 _____ C:\Windows\SysWOW64\PerfStringBackup.INI

Some content of TEMP:
====================
C:\Users\Sonne\AppData\Local\Temp\nsc9D1D.exe
C:\Users\Sonne\AppData\Local\Temp\nsnE018.exe
C:\Users\Sonne\AppData\Local\Temp\nsnE325.exe
C:\Users\Sonne\AppData\Local\Temp\nssA03A.exe
C:\Users\Sonne\AppData\Local\Temp\nsx9A8D.exe
C:\Users\Sonne\AppData\Local\Temp\nsxE622.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-20 10:57

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 28.11.2013, 17:54   #4
M-K-D-B
/// TB-Ausbilder
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



Servus,




Schritt 1
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).





Schritt 2

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.






Schritt 3
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.







Schritt 4
Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
  • Bitte deaktiviere während des Scans alle Virenscanner, da sie das Ergebnis beeinflussen
  • Starte Zoek.exe mit einem Doppelklick.
  • Achtung: Das folgende Skript wurde nur für diesen speziellen Fall geschrieben und könnte andere Computer beschädigen.
  • Kopiere den Text der folgenden Box in das Skriptfenster von zoek:
    Code:
    ATTFilter
    FFdefaults;
    CHRdefaults;
    iedefaults;
    emptyclsid;
    autoclean;
             
  • Nun klicke auf "Run script" und sei geduldig bis das Skript durchläuft.
  • Wenn das Tool fertig ist wird sich Notepad mit dem Logfile öffnen (ggf. erst nach einem Neustart). Das Log befindet sich aber auch noch unter c:
  • Bitte poste mir das ZOEK-Log (möglichst in CODE-Tags - #-Symbol im Antwortfenster klicken)





Bitte poste mit deiner nächsten Antwort
  • die Logdatei von AdwCleaner,
  • die Logdatei von JRT,
  • die Logdatei von MBAM,
  • die Logdatei von Zoek.

Alt 29.11.2013, 13:14   #5
Penelope8282
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.013 - Bericht erstellt am 28/11/2013 um 19:05:52
# Updated 24/11/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Sonne - HARLEY-DAVIDSON
# Gestartet von : C:\Users\Sonne\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****

Dienst Gelöscht : CltMngSvc

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Program Files (x86)\Searchprotect
Ordner Gelöscht : C:\Users\Sonne\AppData\Local\Searchprotect
Ordner Gelöscht : C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma
Ordner Gelöscht : C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh
Datei Gelöscht : C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
Datei Gelöscht : C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\searchplugins\conduit-search.xml
Datei Gelöscht : C:\Windows\System32\Tasks\Dealply
Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate
Datei Gelöscht : C:\Windows\System32\Tasks\QtraxPlayer

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Plus-HD-1.6
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v25.0.1 (de)

[ Datei : C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\prefs.js ]

Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Conduit Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3317209&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP42C37008-C93C-4910-89DF-3E4D96AFBA51&SSPV=");
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.js", "\n\n  /************************************************************************************\[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.a6c937ed6be664f729a60ce5789cc7f0953ba67122cae46e2b82195baea44e049com32002.32002.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.js", "\n\n  /************************************************************************************\[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_1.code", "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return app[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_102.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_119.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_120.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_123.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_13.name", "CrossriderAppUtils");
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_138.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_14.name", "CrossriderUtils");
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_155.code", "if (typeof appAPI.internal.monetization === \"undefined\") {\n    appAP[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_22.code", "(function(a){appAPI.queueManager={queue:[],register:function(b){this.que[...]
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_78.name", "CrossriderInfo");
Zeile gelöscht : user_pref("extensions.a75c9b989a6e64455971f45304161eb2302648b9149b24d7f99ef7e959a8e6505com33438.33438.plugins.plugin_92.code", "if(typeof appAPI.internal.monetization===\"undefined\"){appAPI.internal.[...]
Zeile gelöscht : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc");
Zeile gelöscht : user_pref("extentions.webcake.installId", "4fc5a929-8db3-4ed8-ab9d-4deb15a91b9f");

-\\ Google Chrome v31.0.1650.57

[ Datei : C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : homepage
Gelöscht : icon_url

*************************

AdwCleaner[R0].txt - [9649 octets] - [28/11/2013 19:05:13]
AdwCleaner[S0].txt - [8724 octets] - [28/11/2013 19:05:52]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8784 octets] ##########
         
--- --- ---


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Sonne on 28.11.2013 at 19:11:16,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?

Value Name Type Value Data
========================================================================================
NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l




~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\firstsearch



~~~ Files

Successfully deleted: [File] "C:\Users\Sonne\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Sonne\AppData\Roaming\zip opener packages"
Successfully deleted: [Folder] "C:\Users\Sonne\music\qtrax media library"



~~~ FireFox

Successfully deleted: [Folder] C:\Users\Sonne\AppData\Roaming\mozilla\firefox\profiles\dxajxy9v.default\extensions\6c937ed6-be66-4f72-9a60-ce5789cc7f09@53ba6712-2cae-46e2-b821-95baea44e049.com
Successfully deleted: [Folder] C:\Users\Sonne\AppData\Roaming\mozilla\firefox\profiles\dxajxy9v.default\extensions\75c9b989-a6e6-4455-971f-45304161eb23@02648b91-49b2-4d7f-99ef-7e959a8e6505.com
Emptied folder: C:\Users\Sonne\AppData\Roaming\mozilla\firefox\profiles\dxajxy9v.default\minidumps [11 files]



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Sonne\appdata\local\Google\Chrome\User Data\Default\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma
Successfully deleted: [Folder] C:\Users\Sonne\appdata\local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.11.2013 at 19:17:50,40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.11.28.09

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
Sonne :: HARLEY-DAVIDSON [Administrator]

28.11.2013 19:21:13
mbam-log-2013-11-28 (19-21-13).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 231094
Laufzeit: 3 Minute(n), 31 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 1
C:\Users\Sonne\AppData\Local\Temp\CT3317209 (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 10
C:\$RECYCLE.BIN\S-1-5-21-2983943463-2176006230-4185877932-1001\$RL3VN7J.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsc9D1D.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsnE018.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsnE325.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nssA03A.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsx9A8D.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsxE622.exe (PUP.Optional.SearchProtect.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsn6539.tmp\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\nsn6539.tmp\BI\BI.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Sonne\AppData\Local\Temp\CT3317209\ddt.csf (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

Zoek.exe Version 4.0.0.5 Updated 24-November-2013
Tool run by Sonne on 28.11.2013 at 19:35:27,09.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Sonne\Desktop\zoekzip\zoek.exe [Script inserted]

==== System Restore Info ======================

28.11.2013 19:37:00 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\prefs.js:
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\prefs.js:

ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1943_.backup

==== Deleting Files \ Folders ======================

C:\Users\Sonne\daemonprocess.txt deleted
C:\Users\Sonne\.android deleted
C:\Users\Sonne\AppData\Roaming\newnext.me deleted
C:\Users\Sonne\AppData\Local\Mobogenie deleted
C:\Users\Sonne\AppData\Local\emaze deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\PackageAware deleted
C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Create Amazing Presentations.lnk deleted
"C:\Users\Sonne\AppData\Roaming\Uhheom\yzav.ibu" deleted
"C:\Users\Sonne\AppData\Roaming\Viemez\ezsel.iqa" deleted
"C:\Users\Sonne\AppData\Roaming\Xouwy" deleted
"C:\Users\Sonne\AppData\Roaming\Uhheom" deleted
"C:\Users\Sonne\AppData\Roaming\Viemez" deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default
- Visualisateur 3D de 20-20 - %ProfilePath%\extensions\2020Player_IKEA@2020Technologies.com
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default
4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash
D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System


==== Chrome Look ======================

Plus-HD-2.5 - Sonne - Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd

==== Chrome Fix ======================

C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\iefogiieekeeeeaiklglonbockmhmkgd deleted successfully
C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0.localstorage deleted successfully
C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0.localstorage-journal deleted successfully
C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_iefogiieekeeeeaiklglonbockmhmkgd_0 deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{ABEC6EA7-E055-4279-AEF4-75C6572FA32E} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7FTSG_deDE451"

==== Reset Google Chrome ======================

C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Sonne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Sonne\AppData\Local\Mozilla\Firefox\Profiles\dxajxy9v.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Sonne\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 28.11.2013 at 19:51:12,15 ======================

Wie geht es denn nun weiter?


Alt 29.11.2013, 14:34   #6
M-K-D-B
/// TB-Ausbilder
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



Servus,



Wir spüren die letzten Reste auf, damit wir sie später entfernen können:





Schritt 1
Kontrollscan mit FRST
Führe wie zuvor beschrieben einen Scan mit FRST aus.
Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan.
Es werden wieder zwei Logdateien erzeugt. Poste mir diese.





Schritt 2
Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:
    ATTFilter
    :dir
    C:\Users\Sonne\AppData\Roaming
    
    :filefind
    *Searchprotect*
    *Dealply*
    *Qtrax*
    *conduit*
    *Zip Opener Packages*
    *Plus-HD*
    *Crossrider*
    *newnext.me*
    *NextLive*
    
    :folderfind
    *Searchprotect*
    *Dealply*
    *Qtrax*
    *conduit*
    *Zip Opener Packages*
    *Plus-HD*
    *Crossrider*
    *newnext.me*
    *NextLive*
    
    :regfind
    Searchprotect
    Dealply
    Qtrax
    conduit
    Zip Opener Packages
    Plus-HD
    Crossrider
    newnext.me
    NextLive
             
  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.








Gibt es noch Probleme mit Malware? Wenn ja, welche?
Wie läuft der Rechner derzeit?






Bitte poste mit deiner nächsten Antwort
  • die beiden Logdateien von FRST,
  • die Logdatei von SystemLook,
  • die Beantwortung der gestellten Fragen.

Alt 30.11.2013, 10:08   #7
Penelope8282
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-11-2013
Ran by Sonne (administrator) on HARLEY-DAVIDSON on 30-11-2013 10:06:37
Running from C:\Users\Sonne\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHndHkb.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CSR, plc) C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe
(FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.exe
(FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
() C:\Program Files (x86)\PhotoScape\PhotoScape.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-09] (Synaptics Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [PfNet] - C:\Program Files\Fujitsu\Plugfree NETWORK\PfNet.exe [6310912 2010-06-24] (FUJITSU LIMITED)
HKLM\...\Run: [PSUTility] - C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [188264 2009-07-30] (FUJITSU LIMITED)
HKLM\...\Run: [FDM7] - C:\Program Files\Fujitsu\FDM7\FdmDaemon.exe [164712 2009-11-26] (FUJITSU LIMITED)
HKLM\...\Run: [LoadFujitsuQuickTouch] - C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [157544 2009-10-15] (FUJITSU LIMITED)
HKLM\...\Run: [LoadBtnHnd] - C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe [35176 2009-10-15] (FUJITSU LIMITED)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor)
HKLM\...\Run: [ConMgr] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\ConMgr.exe [535440 2009-12-24] (CSR, plc)
HKLM\...\Run: [CSRSkype] - C:\Program Files\CSR\Bluetooth Feature Pack 5.0\CSRSkype.exe [431504 2009-12-24] (CSR, plc)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKLM-x32\...\Run: [LoadFUJ02E3] - C:\Program Files (x86)\Fujitsu\FUJ02E3\FUJ02E3.exe [36712 2009-10-08] (FUJITSU LIMITED)
HKLM-x32\...\Run: [IndicatorUtility] - C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [47976 2009-10-09] (FUJITSU LIMITED)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [ ] ()
Startup: C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: noscript - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: Adblock Plus - C:\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Chrome In-App Payments service) - C:\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [330240 2010-06-24] (FUJITSU LIMITED)
R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63336 2009-07-30] (FUJITSU LIMITED)
R2 VFPRadioSupportService; C:\Program Files\CSR\Bluetooth Feature Pack 5.0\VFPRadioSupportService.exe [145840 2009-12-24] (CSR, plc)

==================== Drivers (Whitelisted) ====================

R3 BthAvrcp; C:\Windows\System32\DRIVERS\BthAvrcp.sys [34704 2009-12-24] (CSR, plc)
R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED)
R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-30 10:06 - 2013-11-30 10:07 - 00011511 _____ C:\Users\Sonne\Downloads\FRST.txt
2013-11-30 10:06 - 2013-11-30 10:06 - 01959024 _____ (Farbar) C:\Users\Sonne\Downloads\FRST64.exe
2013-11-30 10:04 - 2013-11-30 10:04 - 00165376 _____ C:\Users\Sonne\Downloads\SystemLook_x64.exe
2013-11-28 19:45 - 2013-11-28 19:35 - 00024064 _____ C:\Windows\zoek-delete.exe
2013-11-28 19:36 - 2013-11-28 19:51 - 00006657 _____ C:\zoek-results.log
2013-11-28 19:35 - 2013-11-28 19:44 - 00000000 ____D C:\zoek_backup
2013-11-28 19:35 - 2013-11-28 19:35 - 00000000 ____D C:\Users\Sonne\Desktop\zoekzip
2013-11-28 19:33 - 2013-11-28 19:34 - 04050563 _____ C:\Users\Sonne\Desktop\zoekzip.zip
2013-11-28 19:33 - 2013-11-28 19:33 - 04186953 _____ C:\Users\Sonne\Desktop\zoek.rar
2013-11-28 19:20 - 2013-11-28 19:20 - 00001079 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-28 19:19 - 2013-11-28 19:19 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sonne\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-28 19:07 - 2013-11-28 19:50 - 00004180 _____ C:\Windows\PFRO.log
2013-11-28 19:05 - 2013-11-28 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-28 19:04 - 2013-11-28 19:04 - 01091882 _____ C:\Users\Sonne\Desktop\adwcleaner.exe
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext
2013-11-22 21:56 - 2013-11-29 18:14 - 00001624 _____ C:\Windows\setupact.log
2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log
2013-11-20 10:03 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-16 11:45 - 2013-11-16 11:51 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka
2013-11-13 09:17 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 09:17 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 09:17 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 09:17 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-13 09:17 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 09:17 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 09:17 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-13 09:17 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 09:17 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-13 09:17 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-13 09:17 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-13 09:17 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 09:17 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-13 09:17 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-13 09:17 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 09:17 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 09:17 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 09:17 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 09:17 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 09:17 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 09:17 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 09:17 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 09:17 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-13 09:17 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-13 09:17 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-13 09:17 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-13 09:17 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 09:17 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys

==================== One Month Modified Files and Folders =======

2013-11-30 10:07 - 2013-11-30 10:06 - 00011511 _____ C:\Users\Sonne\Downloads\FRST.txt
2013-11-30 10:06 - 2013-11-30 10:06 - 01959024 _____ (Farbar) C:\Users\Sonne\Downloads\FRST64.exe
2013-11-30 10:05 - 2013-06-07 20:17 - 02001015 _____ C:\Windows\WindowsUpdate.log
2013-11-30 10:04 - 2013-11-30 10:04 - 00165376 _____ C:\Users\Sonne\Downloads\SystemLook_x64.exe
2013-11-30 10:04 - 2011-09-30 22:16 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-30 10:03 - 2013-03-28 19:47 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-30 10:03 - 2011-09-30 22:24 - 00000000 ____D C:\Users\Sonne\AppData\Local\Windows Live
2013-11-29 18:14 - 2013-11-22 21:56 - 00001624 _____ C:\Windows\setupact.log
2013-11-29 14:22 - 2011-09-30 22:16 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-28 19:58 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-28 19:58 - 2009-07-14 05:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-28 19:51 - 2013-11-28 19:36 - 00006657 _____ C:\zoek-results.log
2013-11-28 19:50 - 2013-11-28 19:07 - 00004180 _____ C:\Windows\PFRO.log
2013-11-28 19:50 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-28 19:44 - 2013-11-28 19:35 - 00000000 ____D C:\zoek_backup
2013-11-28 19:43 - 2011-09-30 22:23 - 00000000 ____D C:\Users\Sonne
2013-11-28 19:36 - 2011-02-14 13:57 - 00697322 _____ C:\Windows\system32\perfh007.dat
2013-11-28 19:36 - 2011-02-14 13:57 - 00148328 _____ C:\Windows\system32\perfc007.dat
2013-11-28 19:36 - 2009-07-14 06:13 - 01614036 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-28 19:35 - 2013-11-28 19:45 - 00024064 _____ C:\Windows\zoek-delete.exe
2013-11-28 19:35 - 2013-11-28 19:35 - 00000000 ____D C:\Users\Sonne\Desktop\zoekzip
2013-11-28 19:34 - 2013-11-28 19:33 - 04050563 _____ C:\Users\Sonne\Desktop\zoekzip.zip
2013-11-28 19:33 - 2013-11-28 19:33 - 04186953 _____ C:\Users\Sonne\Desktop\zoek.rar
2013-11-28 19:20 - 2013-11-28 19:20 - 00001079 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-28 19:20 - 2011-10-01 14:53 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-28 19:19 - 2013-11-28 19:19 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Sonne\Desktop\mbam-setup-1.75.0.1300.exe
2013-11-28 19:10 - 2013-07-17 20:09 - 01034531 _____ (Thisisu) C:\Users\Sonne\Desktop\JRT.exe
2013-11-28 19:05 - 2013-11-28 19:05 - 00000000 ____D C:\AdwCleaner
2013-11-28 19:04 - 2013-11-28 19:04 - 01091882 _____ C:\Users\Sonne\Desktop\adwcleaner.exe
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\Documents\Mobogenie
2013-11-28 16:35 - 2013-11-28 16:35 - 00000000 ____D C:\Users\Sonne\AppData\Local\genienext
2013-11-28 16:35 - 2013-10-02 19:36 - 00000000 ____D C:\Users\Sonne\AppData\Local\cache
2013-11-22 21:56 - 2013-11-22 21:56 - 00000000 _____ C:\Windows\setuperr.log
2013-11-22 20:54 - 2011-02-14 13:43 - 00000000 ____D C:\Windows\Panther
2013-11-21 08:25 - 2012-04-26 20:52 - 00006144 ____H C:\Users\Sonne\Desktop\photothumb.db
2013-11-20 13:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-20 10:09 - 2011-09-30 22:34 - 00001431 _____ C:\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-20 10:05 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-20 09:59 - 2013-11-20 09:59 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-20 09:59 - 2013-11-20 09:59 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-20 09:59 - 2013-11-20 09:59 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-20 09:59 - 2013-11-20 09:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-20 09:59 - 2013-11-20 09:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-20 09:59 - 2013-11-20 09:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-20 09:59 - 2013-11-20 09:59 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-20 09:59 - 2013-11-20 09:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-16 13:17 - 2013-11-16 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-16 11:51 - 2013-11-16 11:45 - 00000000 ____D C:\Users\Sonne\Desktop\Neil Sedaka
2013-11-15 15:25 - 2013-09-09 14:44 - 00002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-13 10:40 - 2013-07-09 10:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-11 05:50 - 2010-11-21 04:27 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-04 01:13 - 2011-04-16 11:56 - 01591930 _____ C:\Windows\SysWOW64\PerfStringBackup.INI

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-30 10:03

==================== End Of Log ============================
         
--- --- ---

Alt 30.11.2013, 10:17   #8
Penelope8282
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



fertig

SystemLook 30.07.11 by jpshortstuff
Log created at 10:08 on 30/11/2013 by Sonne
Administrator - Elevation successful

========== dir ==========

C:\Users\Sonne\AppData\Roaming - Parameters: "(none)"

---Files---
WBPU-TTL.DAT --a---- 5 bytes [09:07 27/06/2013] [09:07 27/06/2013]

---Folders---
Adobe d------ [21:41 30/09/2011]
Apple Computer d------ [08:59 01/04/2012]
CyberLink d------ [18:09 04/10/2011]
Fujitsu d------ [21:34 30/09/2011]
Google d------ [21:38 30/09/2011]
Identities d------ [21:34 30/09/2011]
Macromedia d------ [21:41 30/09/2011]
Malwarebytes d------ [13:54 01/10/2011]
Media Center Programs d------ [21:23 30/09/2011]
Microsoft d---s-- [21:23 30/09/2011]
Mozilla d------ [21:46 30/09/2011]
Nero d------ [09:25 01/10/2011]
OpenOffice.org d------ [10:02 02/04/2012]
PhotoScape d------ [09:51 02/04/2012]
Skype d------ [15:49 25/02/2013]
SoftGrid Client d------ [08:12 28/03/2012]
Sony Corporation d------ [13:50 02/10/2011]
TeamViewer d------ [15:47 17/11/2012]
TP d------ [08:11 28/03/2012]
Windows Live Writer d------ [09:19 05/04/2012]

========== filefind ==========

Searching for "*Searchprotect*"
No files found.

Searching for "*Dealply*"
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\102_dealply_m.js.vir --a---- 1768 bytes [13:44 09/09/2013] [13:44 09/09/2013] AC4A6605DB6DAB94639294F200DBDFDD
C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\Dealply.vir --a---- 3520 bytes [08:07 27/06/2013] [08:07 27/06/2013] 2DC2147D8C911D37863228171025B1E2
C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\DealPlyUpdate.vir --a---- 3366 bytes [08:07 27/06/2013] [08:07 27/06/2013] 0C76158AD070A057CF11EB0C937B3FC2
C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\102_dealply_m.js --a---- 1768 bytes [18:44 28/11/2013] [13:44 09/09/2013] AC4A6605DB6DAB94639294F200DBDFDD

Searching for "*Qtrax*"
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk.vir --a---- 2393 bytes [08:07 27/06/2013] [08:07 27/06/2013] FC96415FD98CF4C86D5553EB065B0072
C:\AdwCleaner\Quarantine\C\Windows\System32\Tasks\QtraxPlayer.vir --a---- 3818 bytes [08:07 27/06/2013] [08:07 27/06/2013] 9E6E6756546E52499D9D8FB0678983B6
C:\Users\Sonne\AppData\Local\Microsoft\Silverlight\OutOfBrowser\3905286838.portal.qtrax.com\3905286838.portal.qtrax.com.ico --a---- 26777 bytes [08:07 27/06/2013] [08:07 27/06/2013] 965D9ED9252B16ABD3492C7E54379540

Searching for "*conduit*"
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Roaming\Mozilla\Firefox\Profiles\dxajxy9v.default\searchplugins\conduit-search.xml.vir --a---- 975 bytes [15:35 28/11/2013] [15:35 28/11/2013] 42BB9AF7E83B49FB186307A58A4414A7

Searching for "*Zip Opener Packages*"
No files found.

Searching for "*Plus-HD*"
No files found.

Searching for "*Crossrider*"
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\crossriderManifest.json.vir --a---- 400 bytes [13:44 09/09/2013] [13:44 09/09/2013] 47603EA8C51CCE36090B315E23DBDF13
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\13_CrossriderAppUtils.js.vir --a---- 5955 bytes [13:44 09/09/2013] [13:44 09/09/2013] A15314F10FA928B5C242EDDC4B91F503
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\14_CrossriderUtils.js.vir --a---- 12369 bytes [13:44 09/09/2013] [13:44 09/09/2013] 56E07DB48844B5EB4DD57F053D87A38D
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\extensionData\plugins\78_CrossriderInfo.js.vir --a---- 2220 bytes [13:44 09/09/2013] [13:44 09/09/2013] EC3226E86137F361EEEF8F1244A0225A
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Google\Chrome\User Data\Default\Extensions\jidjhchcblhlapbcpheibgdjkajekhbh\1.24.65_0\js\lib\crossriderAPI.js.vir --a---- 11366 bytes [13:44 09/09/2013] [13:44 09/09/2013] 7B3ADEF52BEDD686D98A3C0F45278020
C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\crossriderManifest.json --a---- 400 bytes [18:44 28/11/2013] [13:44 09/09/2013] 5060361FBB3EBFE66B81A76F847A819A
C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\13_CrossriderAppUtils.js --a---- 5955 bytes [18:44 28/11/2013] [13:44 09/09/2013] A15314F10FA928B5C242EDDC4B91F503
C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\14_CrossriderUtils.js --a---- 12369 bytes [18:44 28/11/2013] [13:44 09/09/2013] 56E07DB48844B5EB4DD57F053D87A38D
C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\extensionData\plugins\78_CrossriderInfo.js --a---- 2220 bytes [18:44 28/11/2013] [13:44 09/09/2013] EC3226E86137F361EEEF8F1244A0225A
C:\zoek_backup\C_Users_Sonne_AppData_Local_Google_Chrome_User Data_Default_Extensions_iefogiieekeeeeaiklglonbockmhmkgd\1.24.52_0\js\lib\crossriderAPI.js --a---- 11366 bytes [18:44 28/11/2013] [13:44 09/09/2013] 7B3ADEF52BEDD686D98A3C0F45278020

Searching for "*newnext.me*"
No files found.

Searching for "*NextLive*"
No files found.

========== folderfind ==========

Searching for "*Searchprotect*"
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect d------ [18:05 28/11/2013]
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect d------ [18:05 28/11/2013]
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Searchprotect d------ [18:05 28/11/2013]
C:\AdwCleaner\Quarantine\C\Users\Sonne\AppData\Local\Searchprotect\SearchProtect d------ [18:05 28/11/2013]

Searching for "*Dealply*"
No folders found.

Searching for "*Qtrax*"
C:\Users\Sonne\AppData\Local\Microsoft\Silverlight\OutOfBrowser\3905286838.portal.qtrax.com d------ [08:07 27/06/2013]

Searching for "*conduit*"
No folders found.

Searching for "*Zip Opener Packages*"
No folders found.

Searching for "*Plus-HD*"
No folders found.

Searching for "*Crossrider*"
No folders found.

Searching for "*newnext.me*"
C:\zoek_backup\C_Users_Sonne_AppData_Roaming_newnext.me d-a---- [18:43 28/11/2013]

Searching for "*NextLive*"
No folders found.

========== regfind ==========

Searching for "Searchprotect"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"="C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll"

Searching for "Dealply"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"Name"="dealply_m"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[102] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

/**
* Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing
* information, see hxxp://www.dealply.com/
*
* THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE
* LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
* OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND,
* EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
* WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C81A6CC7-9F65-4B36-9A95-33D5EBF5372E}]
"Path"="\DealPly"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F18FBE52-13C8-49FF-B7FC-18FCA0169CDD}]
"Path"="\DealPlyUpdate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPly]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DealPlyUpdate]
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"Name"="dealply_m"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[102] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

/**
* Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing
* information, see hxxp://www.dealply.com/
*
* THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE
* LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
* OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND,
* EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
* WARRANTIES OF MERCHANTABILIT
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js"

Searching for "Qtrax"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65A6A838-CF81-4A49-AED4-D6FD263E0342}]
"Path"="\QtraxPlayer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\QtraxPlayer]

Searching for "conduit"
No data found.

Searching for "Zip Opener Packages"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"DisplayIcon"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"UninstallString"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe /Uninstall /NM="Zip Opener Packages" /AN="" /MBN="Zip Opener Packages 83""
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"DisplayName"="Zip Opener Packages 83"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"UninstallerPath"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"UninstallerPathParent"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"DisplayIcon"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"UninstallString"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages\uninstaller.exe /Uninstall /NM="Zip Opener Packages" /AN="" /MBN="Zip Opener Packages 83""
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"DisplayName"="Zip Opener Packages 83"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"UninstallerPath"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages 83]
"UninstallerPathParent"="C:\Users\Sonne\AppData\Roaming\Zip Opener Packages"

Searching for "Plus-HD"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5]
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Manifest]
"Name"="Plus-HD-2.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{12648780-d578-4ecf-bf84-0e18639d0860}]
"AppName"="Plus-HD-1.6-helper.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{12648780-d578-4ecf-bf84-0e18639d0860}]
"AppPath"="C:\Program Files (x86)\Plus-HD-1.6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{134a4566-20ef-4e7b-b221-e1afb3c7cc07}]
"AppName"="Plus-HD-2.5-buttonutil64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{134a4566-20ef-4e7b-b221-e1afb3c7cc07}]
"AppPath"="C:\Program Files (x86)\Plus-HD-2.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{580a372d-7927-49e8-9829-35a62f0ae487}]
"AppName"="Plus-HD-2.5-codedownloader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{580a372d-7927-49e8-9829-35a62f0ae487}]
"AppPath"="C:\Program Files (x86)\Plus-HD-2.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{990fbfea-1b6f-47e2-ab7a-a2946326c732}]
"AppName"="Plus-HD-2.5-helper.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{990fbfea-1b6f-47e2-ab7a-a2946326c732}]
"AppPath"="C:\Program Files (x86)\Plus-HD-2.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ae2a420b-066c-4a22-a55d-d458972576eb}]
"AppName"="Plus-HD-2.5-bg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ae2a420b-066c-4a22-a55d-d458972576eb}]
"AppPath"="C:\Program Files (x86)\Plus-HD-2.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b3ad746b-cb54-49dd-a194-6eb097fe6c5e}]
"AppName"="Plus-HD-1.6-buttonutil64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b3ad746b-cb54-49dd-a194-6eb097fe6c5e}]
"AppPath"="C:\Program Files (x86)\Plus-HD-1.6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d0f19be0-b4d5-4e81-adea-c00f24c90fa8}]
"AppName"="Plus-HD-1.6-buttonutil.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d0f19be0-b4d5-4e81-adea-c00f24c90fa8}]
"AppPath"="C:\Program Files (x86)\Plus-HD-1.6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d42fb26d-4c7d-494d-afa4-bb9b90ead653}]
"AppName"="Plus-HD-2.5-buttonutil.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d42fb26d-4c7d-494d-afa4-bb9b90ead653}]
"AppPath"="C:\Program Files (x86)\Plus-HD-2.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{df8d8370-e00b-4243-839a-728e803720f6}]
"AppName"="Plus-HD-1.6-bg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{df8d8370-e00b-4243-839a-728e803720f6}]
"AppPath"="C:\Program Files (x86)\Plus-HD-1.6"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2665d07-8d6d-412d-a4aa-e7c20ab481e4}]
"AppName"="Plus-HD-1.6-codedownloader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2665d07-8d6d-412d-a4aa-e7c20ab481e4}]
"AppPath"="C:\Program Files (x86)\Plus-HD-1.6"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5]
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Manifest]
"Name"="Plus-HD-2.5"

Searching for "Crossrider"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Code]
"AppJavaScript"="

/************************************************************************************
This is your Page Code. The appAPI.ready() code block will be executed on every page load.
For more information please visit our docs site: hxxp://docs.crossrider.com
*************************************************************************************/


appAPI.ready(function($) {

//alert(appAPI.isMatchPages("*youtube*"));
//alert(appAPI.isMatchPages("*watch*"));
//alert(appAPI.isMatchPages("*hd=1*"))

if (appAPI.isMatchPages("*youtube*") && appAPI.isMatchPages("*watch*") && !appAPI.isMatchPages("*hd=1*")) {
//alert(window.location);
window.location = window.location + "&hd=1"
//alert(window.location);
}

});
"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Code]
"BgJavaScript"="

/************************************************************************************
This is your background code.
For more information please visit our wiki site:
hxxp://docs.crossrider.com/#!/guide/background_scope
*************************************************************************************/

appAPI.ready(function($) {

// Place your code here (ideal for handling browser button, global timers, etc.)

});

"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Installer]
"CodeDownloadDomain"="hxxp://app-static.crossrider.com"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Installer]
"Domain"="hxxp://app-static.crossrider.com"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1]
"JavaScript"="appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},css:"/plugins/stylesheets/sidebar.css",themes:"/plugins/images/sidebar"}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},statsBase:{production:"hxxp://nstats.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},geolocation:"hxxp://www.geoplugin.net/json.gp?jsoncallback=fn",meta:"/notifier/"+appAPI._cr_config.appID()+"/meta.json",messages:"/notifier/"+appAPI._cr_config.appID()+"/{id}.json",logger:"/notifications.gif",loggerAPI:"/api_notifications.gif"},notifications:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},cs
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/base.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\101]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/cortica_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[102] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

/**
* Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing
* information, see hxxp://www.dealply.com/
*
* THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE
* LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
* OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND,
* EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
* WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\103]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_5_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[104] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

var permanentData = {gui:[],actions:[]};
var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1 e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9 f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4cf351d0b2","1f89d526fc52417e16d99b9f069f1 8f
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/jollywallet_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\105]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/corticas_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\107]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupish_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\108]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/icm_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\116]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/ads_only_5_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\117]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupons_intext_ads_5_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[119] = function() {


(function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m=r,q);$(e).trigger(c)}else{if(q!==m){location.href=location.href.replace(/#.*/,"")+q}}p=setTimeout(n
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/similar_web_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[120] = function() {

function injectScript(geo) {
appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=luck&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID());
}

var geo = appAPI.db.get("geo");
if (!geo) {
appAPI.request.get("hxxp://ipgeoapi.com/", function(res) {
if (res) {
var res = appAPI.JSON.parse(res);
if (res && res.country_name) {
geo = res.country_name;
appAPI.db.set("geo", geo, appAPI.time.daysFromNow(7));

injectScript(geo);
}
}
});
} else {
injectScript(geo);
}

};"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/luck_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[123] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.intext){
return;
}
}

// boris don't want it on youtube for shop helper
if (appAPI.appID == 33256 && location.href.indexOf("youtube.com") !== -1) {
return;
}


if (!(/^https\:\/\//.test(document.location.href))) {
appAPI.dom.addRemoteJS("hxxp://intext.nav-links.com/js/intext.js?afid=crossrider&subid=" + appAPI.internal.monetization.getSubId() + "&maxlinks=3&linkcolor=009900");
}

};"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_adv_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\124]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_no_search_no_coupons_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\125]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi2_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\126]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_ws_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\127]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_p_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\128]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_pricora_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\129]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/widdit_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13]
"Name"="CrossriderAppUtils"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderAppUtils.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\132]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_coupons_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\133]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_intext_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\134]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_serp_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\135]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi3_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[138] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

function injectScript(geo) {
appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=getdeal&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID());
}

var geo = appAPI.db.get("geo");
if (!geo) {
appAPI.request.get("hxxp://ipgeoapi.com/", function(res) {
if (res) {
var res = appAPI.JSON.parse(res);
if (res && res.country_name) {
geo = res.country_nam
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/getdeal_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14]
"Name"="CrossriderUtils"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderUtils.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\17]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/jQuery.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\2]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_1.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21]
"JavaScript"="var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h("body").bindExtensionEvent("debug_request_data",function(j,i){i f(i.appId==f.appId){e();}});h("body").bindExtensionEvent("debug_request_reload_background",function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBa ckground){appAPI.internal.reloadBackground();}});h("body").bindExtensionEvent("debug_request_reload_plugins",function(j,i){if(i.appId==f.appId){appAPI .resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h("body").bindExtensionEvent("debug_mode_activate",function(j,i){if(i.appId ==f.appId){b(i);}});h("body").bindExtensionEvent("debug_mode_deactivate",function(j,i){if(i.appId==f.appId){d();}});h("body").bindExtensionEvent("debu g_request_database",function(j,i){if(i.appId==f.appId){c(i);}});h("b
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/debug.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22]
"JavaScript"="(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.init ializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === "undefined") { jQuery = $jquery_171; }('+appAPI.resources.parseIncludeJS(c.toString())+")($jquery_171)")();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appA PI.time.daysFromNow(90),nextCheck:360,DBNamespace:"Resources_",isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.b rowser.msie&&z.browser.version*1==7},w=new z.Deferred(),h=J("meta")||{},D=J("remote_resources")||{remoteId:0},e=J("queue")||{},g=initialVersion=J("lastVersion")||0;return z.Class.extend({i
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/resources.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28]
"JavaScript"="var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}});e("body").bindExtensionEvent("__CR_REQUEST_READY",a);},isReady:func tion(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e("body").fireExtensionEvent("__CR_RESPONSE_READY",{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/initializer.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\3]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_2.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\35]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEAjax.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId="BG";appAPI.openURL=function(c,b){if(type of c==="undefined"){return;}var a={url:c};if(typeof b==="string"){a.where=b;}appAPI.internal.message.send({eventName:"openURL",eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!=="string"){console.error("appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: "+(typeof a));return;}appAPI.internal.message.send({eventName:"runHelper",eventContent:a});};window.alert=function(a){appAPIinternal.alert(a);};window.open=func tion(b,a,d,c){appAPI.internal.message.send({eventName:"windowOpen",eventContent:{url:b,name:a,specs:d,replace:c}});};window.console.log=appAPI.interna l.console.log;console.log=window.console.log;window.console.info=
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBackground.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.consol e.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.inte rnal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.intern al.callbacks.setEventHandler("openURL",function(c){if(appAPI.isActiveTab()){var b=c.url;var a=c.where;appAPI.openURL(b,a);}});appAPI.internal.callbacks.setEventHandler("runHelper",function(b){if(appAPI.isActiveTab()){var a=b;appAPIinternal.run(a);}});(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onBeforeNavigate");if(typeof c!=="string"){re
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBrowserEvents.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d==="undefined"){return;}var a=e.eventName;if(typeof a==="undefined"){return;}if(typeof appAPI.internal.callbacks[a]==="undefined"){return;}if(typeof appAPI.internal.callbacks[a].handler!=="undefined"){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners==="undefined"){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]==="undefined"){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalDa
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IECallbacks.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\39]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEDatabase.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\4]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/jquery-1_7_1_min.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\40]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEExtension.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform="IE";if(typeof appAPI.appInfo==="undefined"){appAPI.appInfo={};}var b=appAPI.internal.prefs.getChar("fullVersionForUrl","Installer");if(typeof b==="string"){appAPI.appInfo.platformVersion=b;}else{appAPI.appInfo.platformVersion=appAPI.internal.prefs.getChar("fullVersion","Installer");}appAPI.a ppInfo.userId=appAPI.internal.prefs.getChar("bic","Crossrider");appAPI.appInfo.id=appAPI.internal.prefs.getInt("activeAppId","");appAPI.appInfo.versio n=appAPI.internal.prefs.getInt("version","Manifest");appAPI.appInfo.description=appAPI.internal.prefs.getChar("description","Manifest");appAPI.appInfo .name=appAPI.internal.prefs.getChar("name","Manifest");appAPI.appInfo.publisherName=appAPI.inte
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInfo.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\42]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInternal.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\43]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMessaging.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\44]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMisc.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.tabId="onRequest";window.console.log=appAPI.internal.console.log;console .log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console. warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onRequest");if(typeof c!=="string"){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!=="object"){return 0;}var d=0;for(var b in c){d++;appAPI.internal.callbacks.addListener("onRequest",function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!=="string"){re
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEOnRequest.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\46]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IETimers.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47]
"JavaScript"="(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appIdfunction(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:"hxxp://resources.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},update:"/apps/{appId}/resources/meta/{lastVersion}"},env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:" Resources_",isDebugappAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get("debug_resources_path"))},w=o("meta")||{},g=o("remote_resources")||{r emoteId:0},t=o("queue")||{},B=o("lastVersion")||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}}); }},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!=="undefined"){D=jQuery.trim(D);}return b(D,"string"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/resources_background.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\64]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiMessage.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\72]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiValidation.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78]
"Name"="CrossriderInfo"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderInfo.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87]
"JavaScript"="var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform=="FF"){$jquery.fn.__prepend=$jquery.fn.prepend;$jquery.fn.prepend=function(a){if($jquery(a).is("script")){window. document.body.appendChild(a);}else{$jquery(this).__prepend(a);}};}var isChrome=appAPI.platform==="CH";function wit_getXMLHttpRequest(){return function(){this.open=function(b,a,c){this.type=b;this.url=a;this.isAsync=c;};this.send=function(){var a=this,b;if(this.isAsync){b=this.type=="GET"?appAPI.request.get:appAPI.request.post;b(this.url,function(c){a.readyState=4;a.status=200;a.responseText= c;if(a.onreadystatechange){a.onreadystatechange();}});}else{b=this.type=="GET"?appAPI.request.sync.get:appAPI.request.sync.post;a.readyState=4;a.statu s=200;a.responseText=b(this.url);}};this.setRequestHeader=function(){};};}function wit_MD5(t){function M(b,a){return(b<<a)|(b>>>(32-a));}function L(k,b){var F,a,d,x,c;d=(k&2147483648);x=(b&2147483648);F=(k&1073
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/ginyas_wrapper.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91]
"JavaScript"="(function(h){var o=(function(){var Q=0;var Y="";function P(ab){return Z(N(R(ab)));}function O(ab){return B(N(R(ab)));}function I(ab,ac){return E(N(R(ab)),ac);}function W(ab,ac){return Z(G(R(ab),R(ac)));}function L(ab,ac){return B(G(R(ab),R(ac)));}function H(ab,ad,ac){return E(G(R(ab),R(ad)),ac);}function aa(){return P("abc").toLowerCase()=="900150983cd24fb0d6963f7d28e17f72";}function N(ab){return U(F(M(ab),ab.length*8));}function G(ad,ag){var af=M(ad);if(af.length>16){af=F(af,ad.length*8);}var ab=Array(16),ae=Array(16);for(var ac=0;ac<16;ac++){ab[ac]=af[ac]^909522486;ae[ac]=af[ac]^1549556828;}var ah=F(ab.concat(M(ag)),512+ag.length*8);return U(F(ae.concat(ah),512+128));}function Z(ad){if(typeof Q==="undefined"){Q=0;}var af=Q?"0123456789ABCDEF":"0123456789abcdef";var ac="";var ab;for(var ae=0;ae<ad.length;ae++){ab=ad.charCodeAt(ae);ac+=af.charAt((ab>>>4)&15)+af.charAt(ab&15);}return ac;}function B(ad){if(typeof Y==="undefine
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/monetizationLoader.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92]
"JavaScript"="if(typeof appAPI.internal.monetization==="undefined"){appAPI.internal.monetization={};}if(typeof appAPI.internal.monetization.plugins==="undefined"){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[92]=function(){if(typeof appAPI.internal.monetization.verticals!=="undefined"){if(!appAPI.internal.monetization.verticals.shopping){return;}}if(!(/^https\:\/\//.test(document.location.href))){appAPI.dom.addRemoteJS("hxxp://www.superfish.com/ws/sf_main.jsp?dlsource=crossrider&userId=abc&CTID="+appAPI.internal.monetization.getSubId());}};"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\93]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94]
"JavaScript"="appAPI.isBackground=false;appAPI.tabId="POPUP";appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: "+(typeof a));return;}if(a.length!==4){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA)");return;}appAPI.internal.message.send({eventName:"onSetBadgeColorFromPopup",eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a) {var b={};if(typeof c!=="string"){console.error("appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: "+(typeof c));return;}b.text=c;if(typeof a==="undefined"||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: "+(typeof a));return;}else{if(a.lengt
[HKEY_CURRENT_USER\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEPopup.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Code]
"AppJavaScript"="

/************************************************************************************
This is your Page Code. The appAPI.ready() code block will be executed on every page load.
For more information please visit our docs site: hxxp://docs.crossrider.com
*************************************************************************************/


appAPI.ready(function($) {

//alert(appAPI.isMatchPages("*youtube*"));
//alert(appAPI.isMatchPages("*watch*"));
//alert(appAPI.isMatchPages("*hd=1*"))

if (appAPI.isMatchPages("*youtube*") && appAPI.isMatchPages("*watch*") && !appAPI.isMatchPages("*hd=1*")) {
//alert(window.location);
window.location = window.location + "&hd=1"
//alert(window.location);
}

});
"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Code]
"BgJavaScript"="

/************************************************************************************
This is your background code.
For more information please visit our wiki site:
hxxp://docs.crossrider.com/#!/guide/background_scope
*************************************************************************************/

appAPI.ready(function($) {

// Place your code here (ideal for handling browser button, global timers, etc.)

});

"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Installer]
"CodeDownloadDomain"="hxxp://app-static.crossrider.com"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Installer]
"Domain"="hxxp://app-static.crossrider.com"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1]
"JavaScript"="appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},css:"/plugins/stylesheets/sidebar.css",themes:"/plugins/images/sidebar"}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging:"hxxp://staging-app.crossrider.com"},statsBase:{production:"hxxp://nstats.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},geolocation:"hxxp://www.geoplugin.net/json.gp?jsoncallback=fn",meta:"/notifier/"+appAPI._cr_config.appID()+"/meta.json",messages:"/notifier/"+appAPI._cr_config.appID()+"/{id}.json",logger:"/notifications.gif",loggerAPI:"/api_notifications.gif"},notifications:{base:{production:"https://w9u6a2p6.ssl.hwcdn.net",staging
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\1]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/base.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\101]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/cortica_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[102] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

/**
* Copyright (C) 2012 DealPly Technologies Ltd. All rights reserved. For licensing
* information, see hxxp://www.dealply.com/
*
* THERE IS NO WARRANTY FOR THE SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE
* LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR
* OTHER PARTIES PROVIDE THE SOFTWARE "AS IS" WITHOUT WARRANTY OF ANY KIND,
* EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
* WARRANTIES OF MERCHANTABILIT
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\102]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/dealply_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\103]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_5_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[104] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

var permanentData = {gui:[],actions:[]};
var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1 e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9 f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4cf3
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\104]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/jollywallet_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\105]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/corticas_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\107]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupish_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\108]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/icm_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\116]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/ads_only_5_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\117]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/coupons_intext_ads_5_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[119] = function() {


(function($,e,b){var c="hashchange",h=document,f,g=$.event.special,i=h.documentMode,d="on"+c in e&&(i===b||i>7);function a(j){j=j||location.href;return"#"+j.replace(/^[^#]*#?(.*)$/,"$1")}$.fn[c]=function(j){return j?this.bind(c,j):this.trigger(c)};$.fn[c].delay=50;g[c]=$.extend(g[c],{setup:function(){if(d){return false}$(f.start)},teardown:function(){if(d){return false}$(f.stop)}});f=(function(){var j={},p,m=a(),k=function(q){return q},l=k,o=k;j.start=function(){p||n()};j.stop=function(){p&&clearTimeout(p);p=b};function n(){var r=a(),q=o(m);if(r!==m){l(m=r,q);$(e).trigger(c)}else{if(q!==m){location.href=location.
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\119]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/similar_web_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[120] = function() {

function injectScript(geo) {
appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=luck&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID());
}

var geo = appAPI.db.get("geo");
if (!geo) {
appAPI.request.get("hxxp://ipgeoapi.com/", function(res) {
if (res) {
var res = appAPI.JSON.parse(res);
if (res && res.country_name) {
geo = res.country_name;
appAPI.db.set("geo", geo, appAPI.time.daysFromNow(7));

injectScript(geo);
}
}
});
} el
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\120]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/luck_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[123] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.intext){
return;
}
}

// boris don't want it on youtube for shop helper
if (appAPI.appID == 33256 && location.href.indexOf("youtube.com") !== -1) {
return;
}


if (!(/^https\:\/\//.test(document.location.href))) {
appAPI.dom.addRemoteJS("hxxp://intext.nav-links.com/js/intext.js?afid=crossrider&subid=" + appAPI.internal.monetization.getSubId() + "&maxlinks=3&linkcolor=009900");
}

};"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\123]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/intext_adv_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\124]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_no_search_no_coupons_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\125]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi2_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\126]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_ws_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\127]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/revizer_p_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\128]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/superfish_pricora_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\129]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/widdit_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13]
"Name"="CrossriderAppUtils"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\13]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderAppUtils.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\132]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_coupons_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\133]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_intext_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\134]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi_serp_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\135]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/arcadi3_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}

appAPI.internal.monetization.plugins[138] = function() {

if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}

function injectScript(geo) {
appAPI.dom.addRemoteJS('https://j6i7c9j2.ssl.hwcdn.net/index/index/loader.js?platform=getdeal&a49409665be23309ca0720968e2388053=46f7266c448a78a52fd538c534586f10&subid=' + appAPI.internal.monetization.getSubId() + '&geo=' + geo + '&userid=' + appAPI.getCrossriderID());
}

var geo = appAPI.db.get("geo");
if (!geo) {
appAPI.request.get("hxxp://ipgeoapi.com/", function(res) {
if (res) {
var res = appAPI.JSON.parse(res);
if (res && res.c
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\138]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/monetization/geo/getdeal_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14]
"Name"="CrossriderUtils"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\14]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderUtils.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\17]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/jQuery.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\2]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_1.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21]
"JavaScript"="var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h("body").bindExtensionEvent("debug_request_data",function(j,i){i f(i.appId==f.appId){e();}});h("body").bindExtensionEvent("debug_request_reload_background",function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBa ckground){appAPI.internal.reloadBackground();}});h("body").bindExtensionEvent("debug_request_reload_plugins",function(j,i){if(i.appId==f.appId){appAPI .resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h("body").bindExtensionEvent("debug_mode_activate",function(j,i){if(i.appId ==f.appId){b(i);}});h("body").bindExtensionEvent("debug_mode_deactivate",function(j,i){if(i.appId==f.appId){d();}});h("body").bindExtensionEvent("debu g_request_database",function
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\21]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/debug.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22]
"JavaScript"="(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.init ializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === "undefined") { jQuery = $jquery_171; }('+appAPI.resources.parseIncludeJS(c.toString())+")($jquery_171)")();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appA PI.time.daysFromNow(90),nextCheck:360,DBNamespace:"Resources_",isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.b rowser.msie&&z.browser.version*1==7},w=new z.Deferred(),h=J("meta")||{},D=J("remote_resources")||{remoteId:0},e=J("queue")||{},g=initialVersion=J("l
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\22]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/resources.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28]
"JavaScript"="var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}});e("body").bindExtensionEvent("__CR_REQUEST_READY",a);},isReady:func tion(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e("body").fireExtensionEvent("__CR_RESPONSE_READY",{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\28]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/initializer.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\3]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie8_fix_2.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\35]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEAjax.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId="BG";appAPI.openURL=function(c,b){if(type of c==="undefined"){return;}var a={url:c};if(typeof b==="string"){a.where=b;}appAPI.internal.message.send({eventName:"openURL",eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!=="string"){console.error("appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: "+(typeof a));return;}appAPI.internal.message.send({eventName:"runHelper",eventContent:a});};window.alert=function(a){appAPIinternal.alert(a);};window.open=func tion(b,a,d,c){appAPI.internal.message.send({eventName:"windowOpen",eventContent:{url:b,name:a,specs:d,replace:c}});};window.console.log=appAPI.interna l.console.log;console.log
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\36]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBackground.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.consol e.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.inte rnal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.intern al.callbacks.setEventHandler("openURL",function(c){if(appAPI.isActiveTab()){var b=c.url;var a=c.where;appAPI.openURL(b,a);}});appAPI.internal.callbacks.setEventHandler("runHelper",function(b){if(appAPI.isActiveTab()){var a=b;appAPIinternal.run(a);}});(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onBef
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\37]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEBrowserEvents.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d==="undefined"){return;}var a=e.eventName;if(typeof a==="undefined"){return;}if(typeof appAPI.internal.callbacks[a]==="undefined"){return;}if(typeof appAPI.internal.callbacks[a].handler!=="undefined"){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners==="undefined"){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]==="undefined"){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.int
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\38]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IECallbacks.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\39]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEDatabase.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\4]
"Url"="hxxp://app-static.crossrider.com/plugins/javascripts/jquery-1_7_1_min.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\40]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEExtension.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform="IE";if(typeof appAPI.appInfo==="undefined"){appAPI.appInfo={};}var b=appAPI.internal.prefs.getChar("fullVersionForUrl","Installer");if(typeof b==="string"){appAPI.appInfo.platformVersion=b;}else{appAPI.appInfo.platformVersion=appAPI.internal.prefs.getChar("fullVersion","Installer");}appAPI.a ppInfo.userId=appAPI.internal.prefs.getChar("bic","Crossrider");appAPI.appInfo.id=appAPI.internal.prefs.getInt("activeAppId","");appAPI.appInfo.versio n=appAPI.internal.prefs.getInt("version","Manifest");appAPI.appInfo.description=appAPI.internal.prefs.getChar("description","Manifest");appAPI.appInfo .name=appAPI.internal.prefs.getChar("name","Manifest");
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\41]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInfo.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\42]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEInternal.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\43]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMessaging.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\44]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEMisc.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45]
"JavaScript"="if(typeof appAPI==="undefined"){appAPI={};}if(typeof appAPI.internal==="undefined"){appAPI.internal={};}if(typeof appAPI.internal.callbacks==="undefined"){appAPI.internal.callbacks={};}appAPI.tabId="onRequest";window.console.log=appAPI.internal.console.log;console .log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console. warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,"Crossrider\\onRequest");if(typeof c!=="string"){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!=="object"){return 0;}var d=0;for(var b in c){d++;appAPI.internal.callbacks.addListener("onRequest",function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditiona
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\45]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEOnRequest.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\46]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IETimers.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47]
"JavaScript"="(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appIdfunction(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:"hxxp://resources.crossrider.com",staging:"hxxp://staging-app.crossrider.com"},update:"/apps/{appId}/resources/meta/{lastVersion}"},env:appAPI.appInfo.environment==="staging"?"staging":"production",saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:" Resources_",isDebugappAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get("debug_resources_path"))},w=o("meta")||{},g=o("remote_resources")||{r emoteId:0},t=o("queue")||{},B=o("lastVersion")||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}}); }},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!=="undefined
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\47]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/resources_background.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\64]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiMessage.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\72]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/appApiValidation.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78]
"Name"="CrossriderInfo"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\78]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/CrossriderInfo.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87]
"JavaScript"="var CROSSRIDER_PLATFORM=true;var JQ=bbrsJQ=$jquery;if(appAPI.platform=="FF"){$jquery.fn.__prepend=$jquery.fn.prepend;$jquery.fn.prepend=function(a){if($jquery(a).is("script")){window. document.body.appendChild(a);}else{$jquery(this).__prepend(a);}};}var isChrome=appAPI.platform==="CH";function wit_getXMLHttpRequest(){return function(){this.open=function(b,a,c){this.type=b;this.url=a;this.isAsync=c;};this.send=function(){var a=this,b;if(this.isAsync){b=this.type=="GET"?appAPI.request.get:appAPI.request.post;b(this.url,function(c){a.readyState=4;a.status=200;a.responseText= c;if(a.onreadystatechange){a.onreadystatechange();}});}else{b=this.type=="GET"?appAPI.request.sync.get:appAPI.request.sync.post;a.readyState=4;a.statu s=200;a.responseText=b(this.url);}};this.setRequestHeader=function(){};};}function wit_MD5(t){function M(b,a){return(b<<a)|(b>>>(32-a));}function L(k,b){var F,a,d,x,c;d=(
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\87]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/ginyas_wrapper.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91]
"JavaScript"="(function(h){var o=(function(){var Q=0;var Y="";function P(ab){return Z(N(R(ab)));}function O(ab){return B(N(R(ab)));}function I(ab,ac){return E(N(R(ab)),ac);}function W(ab,ac){return Z(G(R(ab),R(ac)));}function L(ab,ac){return B(G(R(ab),R(ac)));}function H(ab,ad,ac){return E(G(R(ab),R(ad)),ac);}function aa(){return P("abc").toLowerCase()=="900150983cd24fb0d6963f7d28e17f72";}function N(ab){return U(F(M(ab),ab.length*8));}function G(ad,ag){var af=M(ad);if(af.length>16){af=F(af,ad.length*8);}var ab=Array(16),ae=Array(16);for(var ac=0;ac<16;ac++){ab[ac]=af[ac]^909522486;ae[ac]=af[ac]^1549556828;}var ah=F(ab.concat(M(ag)),512+ag.length*8);return U(F(ae.concat(ah),512+128));}function Z(ad){if(typeof Q==="undefined"){Q=0;}var af=Q?"0123456789ABCDEF":"0123456789abcdef";var ac="";var ab;for(var ae=0;ae<ad.length;ae++){ab=ad.charCodeAt(ae);ac+=af.charAt((ab>>>4)&15)+af.charAt(ab&15);}return ac
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\91]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/monetizationLoader.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92]
"JavaScript"="if(typeof appAPI.internal.monetization==="undefined"){appAPI.internal.monetization={};}if(typeof appAPI.internal.monetization.plugins==="undefined"){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[92]=function(){if(typeof appAPI.internal.monetization.verticals!=="undefined"){if(!appAPI.internal.monetization.verticals.shopping){return;}}if(!(/^https\:\/\//.test(document.location.href))){appAPI.dom.addRemoteJS("hxxp://www.superfish.com/ws/sf_main.jsp?dlsource=crossrider&userId=abc&CTID="+appAPI.internal.monetization.getSubId());}};"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\92]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\93]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94]
"JavaScript"="appAPI.isBackground=false;appAPI.tabId="POPUP";appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: "+(typeof a));return;}if(a.length!==4){console.error("appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA)");return;}appAPI.internal.message.send({eventName:"onSetBadgeColorFromPopup",eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a) {var b={};if(typeof c!=="string"){console.error("appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: "+(typeof c));return;}b.text=c;if(typeof a==="undefined"||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error("appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but go
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\AppDataLow\Software\Plus-HD-2.5\Plugins\94]
"Url"="hxxp://app-static.crossrider.com/plugins/mins/ie/IEPopup.js"

Searching for "newnext.me"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l"

Searching for "NextLive"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l"
[HKEY_USERS\S-1-5-21-2983943463-2176006230-4185877932-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="C:\Windows\SysWOW64\rundll32.exe "C:\Users\Sonne\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l"

-= EOF =-

Alt 30.11.2013, 13:05   #9
M-K-D-B
/// TB-Ausbilder
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



Servus,


wenn du FRST richtig ausgeführt hast, dann erstellt es 2 Logdateien, FRST.txt und Addition.txt.

Poste mir bitte noch die Addition.txt, dann kann es weitergehen.

Alt 04.12.2013, 20:09   #10
M-K-D-B
/// TB-Ausbilder
 
Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Standard

Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6



Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!

Antwort

Themen zu Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6
adware, adware?, akamaihd.net, aktiviert, angezeigt, anzeigen, applaus, korrekt, loswerden, nerviger, plushd, probleme, pup.optional.conduit.a, pup.optional.opencandy, pup.optional.searchprotect.a, trojan:js/medfos.b, verschwunden, überall, öffnen



Ähnliche Themen: Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6


  1. Ständig öffnen sich neue Internet-Fenster
    Plagegeister aller Art und deren Bekämpfung - 14.09.2015 (48)
  2. Windows 8 internet explorer.ständig werbefenster, Tabs,downloads,browsergames die sich automatisch öffnen oder angezeigt werden
    Plagegeister aller Art und deren Bekämpfung - 01.08.2014 (4)
  3. Bei Aufruf einer Seite oder Funktion öffnen sich ständig Fenster, die nicht gewünscht sind, auch während ich dies schreibe.
    Log-Analyse und Auswertung - 08.06.2014 (1)
  4. Es öffnen sich ständig neue Fenster und Tabs
    Plagegeister aller Art und deren Bekämpfung - 17.03.2014 (4)
  5. neue Seiten mit rvzr-a.akamaihd.net öffnen sich ständig
    Log-Analyse und Auswertung - 01.12.2013 (18)
  6. Windows 7 Miniaturanwendungen werden nicht korrekt angezeigt
    Mülltonne - 17.04.2013 (1)
  7. Einige Internetseiten lassen sich nicht öffnen und werden weiss angezeigt
    Plagegeister aller Art und deren Bekämpfung - 30.03.2013 (1)
  8. Alles Datein von USb-Speicherkarten werden als Verküpfung angezeigt und lassen sich nicht öffnen!
    Plagegeister aller Art und deren Bekämpfung - 24.10.2011 (25)
  9. Ordner auf externer Festplatte werden nur noch als Verknüpfungen angezeigt, die sich nicht öffnen
    Log-Analyse und Auswertung - 17.10.2011 (24)
  10. Setup.exe Datein lassen sich nicht ausführen , und Minianwendungen werden nicht Korrekt angezeigt ?
    Log-Analyse und Auswertung - 25.06.2011 (5)
  11. Es öffnen sich ständig Seiten
    Plagegeister aller Art und deren Bekämpfung - 30.10.2010 (3)
  12. Ständig öffnen sich unerwünscht neue Fenster/Internet-Seiten
    Log-Analyse und Auswertung - 05.12.2009 (5)
  13. Websites werden nicht angezeigt - ständig pop-ups
    Log-Analyse und Auswertung - 18.06.2008 (0)
  14. TR/Crypt.XPACK.GEN gefunden und nun öffnen sich Werbe-Fenster!
    Plagegeister aller Art und deren Bekämpfung - 28.05.2008 (4)
  15. Seiten werden nicht angezeigt
    Alles rund um Windows - 08.03.2007 (14)
  16. fenster öffnen sich ständig...
    Plagegeister aller Art und deren Bekämpfung - 01.12.2006 (1)
  17. Werbe-Fenster öffnen sich einfach so! ???
    Plagegeister aller Art und deren Bekämpfung - 29.03.2005 (14)

Zum Thema Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 - Huhu, seit ein paar Tagen habe ich ein paar Probleme mit Mozilla. Ständig öffnen sich Fenster (akamaihd.net) die aber dann auch nicht richtig angezeigt werden können. Wernebanner und gewisse Textanzeigen - Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6...
Archiv
Du betrachtest: Adware? ständig öffnen sich (Werbe)fenster akamaihd.net und Seiten werden nicht korrekt angezeigt PLUSHD6 auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.