Leisachen | 18.04.2014 09:37 | Ich komme leider mit dem revo uninstaller nicht zurecht. Finde den zu löschenden "Ordner" nicht. Wo genau finde ich diesen in dem Programm? Code:
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Liza on 18.04.2014 at 10:04:58,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.04.2014 at 10:22:55,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.04.2014
Suchlauf-Zeit: 09:44:33
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.17.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Liza
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 277926
Verstrichene Zeit: 9 Std, 56 Min, 42 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, 3432, Löschen bei Neustart, [d12fb54bc937fb054c6a30f2ec15956b]
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe, 3624, Löschen bei Neustart, [67999a669070de223c7840e22dd4a060]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 52
PUP.Optional.Conduit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [d828b34d0cf4a8584ac31aff1fe27789],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CLTMNGSVC.EXE, In Quarantäne, [d828b34d0cf4a8584ac31aff1fe27789],
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CLTMNGSVC.EXE, In Quarantäne, [d828b34d0cf4a8584ac31aff1fe27789],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344344440}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355345540}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366346640}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550355345540}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660366346640}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440344344440}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.BHO.1, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.BHO, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.BHO, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.BHO.1, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{11111111-1111-1111-1111-110311341140}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220322342240}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.Sandbox.1, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0033440.Sandbox, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.Sandbox, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0033440.Sandbox.1, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220322342240}, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110311341140}\INPROCSERVER32, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\APPID\{6A7CD9EC-D8BD-4340-BCD0-77C09A282921}, In Quarantäne, [926e28d8a35d748c27ed5bba7290d42c],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{6A7CD9EC-D8BD-4340-BCD0-77C09A282921}, In Quarantäne, [926e28d8a35d748c27ed5bba7290d42c],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\CLASSES\Linkey.Linkey, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Linkey.Linkey, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [cb3557a927d933cd38e41df851b113ed],
PUP.Optional.Linkey.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Linkey, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\LINKEY, In Quarantäne, [19e7ca360ff1629eaf090868748ecd33],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [34ccf30d897715eb817a9ae411f1df21],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\Plus-HD-2.6, In Quarantäne, [b749798703fd31cfefe194ec61a10000],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\LINKEY, In Quarantäne, [1de347b9cf31d8282c8c4a2614ee26da],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK\General, In Quarantäne, [16eae917aa56b44c39febeb2e41e7b85],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK, In Quarantäne, [1be5857b649c39c763d5383853afbe42],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [ff01946c867a46ba1fafe2c68a79867a],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.6, In Quarantäne, [dc24a858b34d03fd0fb10f61c141f709],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [996760a0b64a4db3e31f78068082c33d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [7a86cd337b8538c805340094c73cf20e],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, In Quarantäne, [718f9b653cc4f808d3eedb95ed1519e7],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [bc4442beb44c966ad653e686de242ad6],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Plus-HD-2.6, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Settings Manager, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\F06DEFF2-5B9C-490D-910F-35D3A9119622, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
Registrierungswerte: 4
PUP.Optional.Linkey.A, HKLM\SOFTWARE\LINKEY|ie_jsurl, hxxp://app.linkeyproject.com/popup/IE/background.js, In Quarantäne, [19e7ca360ff1629eaf090868748ecd33]
PUP.Optional.Linkey.A, HKLM\SOFTWARE\WOW6432NODE\LINKEY|ie_jsurl, hxxp://app.linkeyproject.com/popup/IE/background.js, In Quarantäne, [1de347b9cf31d8282c8c4a2614ee26da]
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK|browser, ie ff cr, In Quarantäne, [1be5857b649c39c763d5383853afbe42]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1271339329-609278821-480542443-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [7a86cd337b8538c805340094c73cf20e]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 33
PUP.Optional.SystemK.A, C:\ProgramData\systemk, In Quarantäne, [4cb4c13fc13f5aa6ffd779f58979e818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\ChromeExtension, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\IEExtension, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\Logs, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\Logs, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.OpenCandy, C:\Users\Liza\AppData\Roaming\OpenCandy, In Quarantäne, [6a96ab55eb154bb50afcf866738ff50b],
PUP.Optional.OpenCandy, C:\Users\Liza\AppData\Roaming\OpenCandy\33C3B8041DEA419F9FAE8AE8B1B5E8BE, In Quarantäne, [6a96ab55eb154bb50afcf866738ff50b],
PUP.Optional.Iminent.A, C:\Users\Liza\AppData\Local\Temp\Iminent, In Quarantäne, [36ca3ac62dd37c84a37cd08ece349c64],
PUP.Optional.Iminent.A, C:\Users\Liza\AppData\Local\Temp\Iminent\Log, In Quarantäne, [36ca3ac62dd37c84a37cd08ece349c64],
PUP.Optional.Multiplug, C:\Program Files (x86)\YoutubeAdblocker, In Quarantäne, [a35d38c8a858a35db284c997ca38c33d],
PUP.Optional.YoutubeAdblocker.A, C:\ProgramData\YoutubeAdblocker, In Quarantäne, [dc246e929769da26fa565d052bd753ad],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
Dateien: 146
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe, In Quarantäne, [d12fb54bc937fb054c6a30f2ec15956b],
PUP.Optional.OptimizerPro, C:\Program Files (x86)\Optimizer Pro\OptProReminder.exe, Löschen bei Neustart, [67999a669070de223c7840e22dd4a060],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, In Quarantäne, [d828b34d0cf4a8584ac31aff1fe27789],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-bho64.dll, In Quarantäne, [d12fec14e719c8380f193ed80cf540c0],
Trojan.SProtector, C:\Program Files (x86)\WS.Booster, In Quarantäne, [d927b24e946c13edcc98bb9a38c957a9],
PUP.Optional.Conduit.A, C:\Users\Liza\AppData\Local\Temp\SPSetup.exe, In Quarantäne, [d82815eb4db387797c9168b10ef3e020],
PUP.Optional.Conduit, C:\Users\Liza\AppData\Local\Temp\verifier.exe, In Quarantäne, [fd03a55bf60a9868ea6de9d58f745aa6],
PUP.Optional.SearchProtect.A, C:\Users\Liza\AppData\Local\Temp\nscE43E.exe, In Quarantäne, [c63af60a08f8cf315dc13be9c53c51af],
PUP.Optional.SearchProtect.A, C:\Users\Liza\AppData\Local\Temp\nsn5F05.exe, In Quarantäne, [19e74bb5fe028080879741e37b86ec14],
PUP.Optional.SearchProtect.A, C:\Users\Liza\AppData\Local\Temp\nsnEE3E.exe, In Quarantäne, [d42c39c79b6516eafa241a0a728f926e],
PUP.Optional.SearchProtect.A, C:\Users\Liza\AppData\Local\Temp\nsx6694.exe, In Quarantäne, [d42cea1698688b75b36bf034689919e7],
PUP.Optional.Conduit, C:\Users\Liza\AppData\Local\Temp\embededstub.exe, In Quarantäne, [d927da26d62a1ee289ce3d81d62dda26],
PUP.Optional.Linkey.A, C:\Users\Liza\AppData\Local\Temp\nsoC2B9.tmp\nsoCE90.tmp\mediabar.exe, In Quarantäne, [d82833cd6f91f70953fd1f46a25f8a76],
PUP.Optional.Linkey.A, C:\Users\Liza\AppData\Local\Temp\nsoC2B9.tmp\nsoCE90.tmp\SettingsManagerMediaBar.exe, In Quarantäne, [53ad7789f808738d73dd4124f011d927],
PUP.Optional.Conduit.A, C:\Users\Liza\AppData\Local\Temp\nssE1E9\SpSetup.exe, In Quarantäne, [5aa6c0408d73d62a19f4d64378891ce4],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nso2980.exe, In Quarantäne, [798739c7e91788783ce2bc6810f1e31d],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsuF661.exe, In Quarantäne, [2ed247b9ed13bf4121fdb56fe61b1ce4],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Travis_Garland_-_Motel_Pool_AUDIO.mp3 (1).exe, In Quarantäne, [dc24887845bb0df3b4939cc1ee13d030],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Travis_Garland_-_Motel_Pool_AUDIO.mp3.exe, In Quarantäne, [47b92ed2837d3ac64ff8be9fe21fba46],
PUP.Optional.OpenCandy, C:\Users\Liza\Downloads\PhotoScape_V3.6.5.exe, In Quarantäne, [0000a15f1fe10bf564905af0fd07e917],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Lil_wayne_ft_2_Chainz-RICH_AS_FUCK-lyrics.mp3.exe, In Quarantäne, [1ae6ef11d22e54ac36fdca8ade2353ad],
PUP.Optional.Softonic.A, C:\Users\Liza\Downloads\SoftonicDownloader_fuer_photo-booth-fur-windows-7.exe, In Quarantäne, [1ae636ca7b859f613c94d04a4fb24eb2],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Tyga_-_Faded_feat_Lil_Wayne.mp3.exe, In Quarantäne, [fe02bd43ed139c640b283420679aa15f],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Tyga_-_Make_it_Nasty_NEW_HD.mp3.exe, In Quarantäne, [c23ec33d8b75669ac46f9bb9748dff01],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Tyga_ft_2_Chainz_-_Do_My_Dance_LYRICS.mp3.exe, In Quarantäne, [8e729868f30d4bb57db6e56f5ca5ed13],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Drake_-_Own_It_Nothing_Was_The_Same.mp3 (1).exe, In Quarantäne, [2fd1b9473bc5de22c28563faaa57936d],
PUP.Optional.Installex, C:\Users\Liza\Downloads\Drake_-_Own_It_Nothing_Was_The_Same.mp3.exe, In Quarantäne, [30d02dd346ba7e82f94e1746fa07e41c],
PUP.Optional.DomaIQ, C:\Users\Liza\Downloads\Setup.exe, In Quarantäne, [50b031cf21dffd03c1bd8799d8299b65],
PUP.Optional.Softonic.A, C:\Users\Liza\Downloads\SoftonicDownloader_fuer_die-sims-2-open-for-business (1).exe, In Quarantäne, [ee122fd159a7d12f488842d87f829c64],
PUP.Optional.Softonic.A, C:\Users\Liza\Downloads\SoftonicDownloader_fuer_die-sims-2-open-for-business (2).exe, In Quarantäne, [748c38c8ee12cc34923e91894fb29868],
PUP.Optional.Softonic.A, C:\Users\Liza\Downloads\SoftonicDownloader_fuer_die-sims-2-open-for-business.exe, In Quarantäne, [659bdf21639db7491fb11901fa07ed13],
PUP.Optional.Softonic.A, C:\Users\Liza\Downloads\SoftonicDownloader_fuer_mycam.exe, In Quarantäne, [ee12966aa25e04fc7957fe1c5fa2b64a],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-2.6-chromeinstaller.job, In Quarantäne, [2cd46e9226da8b75a13fdd8f0df5619f],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-2.6-codedownloader.job, In Quarantäne, [6f918a76ea1610f0b22e2a426c9648b8],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-2.6-enabler.job, In Quarantäne, [22de2ad645bb0ef2c11ff27abe44936d],
PUP.Optional.PlusHD.A, C:\Windows\Tasks\Plus-HD-2.6-updater.job, In Quarantäne, [54ac926e50b05da322be5715fa087d83],
PUP.Optional.Linkey.A, C:\Users\Liza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Linkey.lnk, In Quarantäne, [e917e61a7c84bd430ec6026c659d1ce4],
PUP.Optional.SystemK.A, C:\ProgramData\systemk\general.cfg, In Quarantäne, [4cb4c13fc13f5aa6ffd779f58979e818],
PUP.Optional.SystemK.A, C:\ProgramData\systemk\coordinator.cfg, In Quarantäne, [4cb4c13fc13f5aa6ffd779f58979e818],
PUP.Optional.SystemK.A, C:\ProgramData\systemk\S-1-5-21-1271339329-609278821-480542443-1000.cfg, In Quarantäne, [4cb4c13fc13f5aa6ffd779f58979e818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\log.log, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\Helper.dll, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\Uninstall.exe, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.Linkey.A, C:\Program Files (x86)\Linkey\ChromeExtension\ChromeExtension.crx, In Quarantäne, [11efca36a15f0000fcb980f014eee818],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [8b7557a91de35ca41e9e6215ad554bb5],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win32cert.dll, In Quarantäne, [718fef119070b34d0cc13e599c6757a9],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win64cert.dll, In Quarantäne, [3bc5d42cc83838c8eedfefa8e1224fb1],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win32prop.dll, In Quarantäne, [ad53da26ba461be5ba14e4b3e71cdd23],
PUP.Optional.Datamngr.A, C:\ProgramData\Wincert\win64prop.dll, In Quarantäne, [ca36d62afe0203fd616d682f1de6b24e],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [9a66ca3622de03fdb6b3cbd354af24dc],
PUP.Optional.OpenCandy, C:\Users\Liza\AppData\Roaming\OpenCandy\33C3B8041DEA419F9FAE8AE8B1B5E8BE\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [6a96ab55eb154bb50afcf866738ff50b],
PUP.Optional.Multiplug, C:\Program Files (x86)\YoutubeAdblocker\dv2ZpdR1q.dat, In Quarantäne, [a35d38c8a858a35db284c997ca38c33d],
PUP.Optional.Multiplug, C:\Program Files (x86)\YoutubeAdblocker\dv2ZpdR1q.tlb, In Quarantäne, [a35d38c8a858a35db284c997ca38c33d],
PUP.Optional.YoutubeAdblocker.A, C:\ProgramData\YoutubeAdblocker\1yUVY_G6QO.dat, In Quarantäne, [dc246e929769da26fa565d052bd753ad],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-buttonutil64.exe, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\33440.crx, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\background.html, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Installer.log, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-buttonutil.dll, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-buttonutil64.dll, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6-helper.exe, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Plus-HD-2.6.ico, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\Uninstall.exe, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\Plus-HD-2.6\utils.exe, In Quarantäne, [19e711efa45c41bf0426e67fb64cde22],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\del_DM_DLL_nso2715.dll, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\del_DM_EXE_nso2715.exe, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\del_mg_nso2715.dll, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\favicon.ico, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\Helper.dll, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkChrome.dll, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemkmgrc1.cfg, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\systemku.exe, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\tbicon.exe, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\Uninstall.exe, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\systemkmgrc1.cfg, In Quarantäne, [16ea3ac628d84db3044c5f060af802fe],
PUP.Optional.DefaultSearch.A, C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.default-search.net?sid=476&aid=122&itype=n&ver=11471&tm=298&src=hmp" ],), Ersetzt,[7a86946c1be5cb3508242c2636ce22de]
PUP.Optional.DefaultSearch.A, C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.default-search.net?sid=476&aid=122&itype=n&ver=11471&tm=298&src=hmp",), Ersetzt,[f60a649c44bcec141a13aea48282a060]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 10:00:04
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Liza - LIZA-PC
# Gestartet von : C:\Users\Liza\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\ProgramData\Browser Manager
Ordner Gelöscht : C:\ProgramData\BrowserProtect
Ordner Gelöscht : C:\ProgramData\webSaVE
Ordner Gelöscht : C:\ProgramData\wincert
Ordner Gelöscht : C:\ProgramData\JOaniiCCoupOnn
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
Ordner Gelöscht : C:\Program Files (x86)\Driver Pro
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\Settings Manager
Ordner Gelöscht : C:\Program Files (x86)\webSaVE
Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\Liza\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Liza\AppData\Local\torch
Ordner Gelöscht : C:\Users\Liza\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Liza\AppData\Roaming\Driver Pro
Ordner Gelöscht : C:\Users\Liza\AppData\Roaming\Optimizer Pro
Ordner Gelöscht : C:\Users\Liza\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Liza\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Liza\Documents\Optimizer Pro
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Driver Pro]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKCU\Software\Driver Pro
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Google Chrome v33.0.1750.146
[ Datei : C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [8195 octets] - [18/04/2014 09:58:15]
AdwCleaner[S0].txt - [7514 octets] - [18/04/2014 10:00:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7574 octets] ##########
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-04-2014 02
Ran by Liza (administrator) on LIZA-PC on 18-04-2014 10:31:23
Running from C:\Users\Liza\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Liza\Desktop\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-04] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2885904 2012-04-06] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [636032 2012-02-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BtTray] => C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [371976 2012-09-19] (IVT Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4971024 2014-03-19] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2013-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKU\S-1-5-21-1271339329-609278821-480542443-1000\...\MountPoints2: {290250ad-29af-11e3-b589-806e6f6e6963} - D:\Autorun.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\rjatydimofu.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.default-search.net?sid=476&aid=122&itype=n&ver=11471&tm=298&src=hmp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x82D1002DBEBDCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=298&src=ds&p={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=298&src=ds&p={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=11471&tm=298&src=ds&p={searchTerms}
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\SysWOW64\skype4com.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-10-27]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-10-27]
Chrome:
=======
CHR Extension: (Adblock Plus) - C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-25]
CHR Extension: (webSaave) - C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecjpggdbgdlkljldbdekeanngpmdhclp [2014-03-11]
CHR Extension: (websAve) - C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gefkcklehiibplbjbigldggffoefhkhg [2014-02-23]
CHR Extension: (AdBlock) - C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-02-25]
CHR Extension: (websave) - C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhdlbfeojolndnlbeeflcaffljigmcdk [2014-03-11]
CHR Extension: (Google Wallet) - C:\Users\Liza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-12]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-02-14] (Advanced Micro Devices, Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3782672 2014-02-23] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1612552 2012-09-26] (IVT Corporation)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [146184 2012-09-19] (IVT Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2102072 2013-12-18] (AVG)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [42808 2013-12-18] (AVG)
S3 w7Svc; C:\Program Files (x86)\webcam 7\wService.exe [5258560 2013-11-11] (Moonware Studios)
==================== Drivers (Whitelisted) ====================
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2012-01-03] (Advanced Micro Devices)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
S3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
S3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48608 2012-10-02] (Ralink Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-28] (Realtek Semiconductor Corp.)
R3 rtbth; C:\Windows\System32\DRIVERS\rtbth.sys [692832 2012-10-02] (Ralink Technology, Corp.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 10:31 - 2014-04-18 10:31 - 00017976 _____ () C:\Users\Liza\Desktop\FRST.txt
2014-04-18 10:22 - 2014-04-18 10:22 - 00000624 _____ () C:\Users\Liza\Desktop\JRT.txt
2014-04-18 10:04 - 2014-04-18 10:04 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 10:03 - 2014-04-18 10:03 - 00007670 _____ () C:\Users\Liza\Desktop\AdwCleaner[S0].txt
2014-04-18 09:58 - 2014-04-18 10:00 - 00000000 ____D () C:\AdwCleaner
2014-04-18 09:57 - 2014-04-18 09:57 - 00035919 _____ () C:\Users\Liza\Desktop\mbam.txt
2014-04-18 09:55 - 2014-04-18 09:55 - 00035923 _____ () C:\maleware.txt
2014-04-17 23:58 - 2014-04-17 23:57 - 01426178 _____ () C:\Users\Liza\Desktop\adwcleaner.exe
2014-04-17 23:56 - 2014-04-17 23:57 - 01426178 _____ () C:\Users\Liza\Downloads\adwcleaner.exe
2014-04-17 23:56 - 2014-04-17 23:56 - 01016261 _____ (Thisisu) C:\Users\Liza\Desktop\JRT.exe
2014-04-17 23:55 - 2014-04-17 23:56 - 01016261 _____ (Thisisu) C:\Users\Liza\Downloads\JRT.exe
2014-04-17 23:46 - 2014-04-18 09:53 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-17 23:45 - 2014-04-17 23:45 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-17 23:45 - 2014-04-17 23:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-17 23:45 - 2014-04-17 23:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-17 23:45 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-17 23:45 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-17 23:45 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-17 23:38 - 2014-04-17 23:38 - 00001264 _____ () C:\Users\Liza\Desktop\Revo Uninstaller.lnk
2014-04-17 23:38 - 2014-04-17 23:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-17 23:37 - 2014-04-17 23:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Liza\Downloads\revosetup95.exe
2014-04-17 23:37 - 2014-04-17 23:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Liza\Desktop\revosetup95.exe
2014-04-17 23:36 - 2014-04-17 23:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Downloads\mbam-setup-2.0.1.1004 (2).exe
2014-04-17 23:35 - 2014-04-17 23:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-04-17 18:29 - 2014-04-17 18:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-17 18:26 - 2014-04-17 18:27 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-16 21:35 - 2014-04-18 10:31 - 00000000 ____D () C:\FRST
2014-04-16 21:34 - 2014-04-16 21:34 - 02158592 _____ (Farbar) C:\Users\Liza\Downloads\FRST64 (1).exe
2014-04-16 21:34 - 2014-04-16 21:34 - 02158592 _____ (Farbar) C:\Users\Liza\Desktop\FRST64 (1).exe
2014-04-16 21:33 - 2014-04-16 21:33 - 02158592 _____ (Farbar) C:\Users\Liza\Downloads\FRST64.exe
2014-04-16 20:03 - 2014-04-16 20:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2014-04-16 20:03 - 2014-04-16 20:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2014-04-09 13:15 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-09 13:15 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-09 13:15 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-09 13:15 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-09 13:15 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 13:15 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 13:15 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 13:15 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 13:14 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 13:14 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 13:14 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 13:14 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 13:14 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 13:14 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 13:14 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 13:14 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 13:14 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 13:14 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 13:14 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 13:14 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-07 16:15 - 2014-04-07 16:15 - 00397312 _____ () C:\Users\Liza\Downloads\image (8).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00380928 _____ () C:\Users\Liza\Downloads\image (11).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00327680 _____ () C:\Users\Liza\Downloads\image (9).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00327680 _____ () C:\Users\Liza\Downloads\image (12).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00327680 _____ () C:\Users\Liza\Downloads\image (10).jpeg
2014-04-07 16:14 - 2014-04-07 16:14 - 00356352 _____ () C:\Users\Liza\Downloads\image.jpeg
2014-04-07 16:14 - 2014-04-07 16:14 - 00311296 _____ () C:\Users\Liza\Downloads\image (7).jpeg
2014-04-06 12:19 - 2014-04-06 12:19 - 00142075 _____ () C:\Users\Liza\Downloads\Jaumo.htm
2014-04-06 12:19 - 2014-04-06 12:19 - 00000000 ____D () C:\Users\Liza\Downloads\Jaumo_files
2014-04-01 20:30 - 2013-12-18 10:38 - 00042808 _____ (AVG) C:\Windows\system32\uxtuneup.dll
2014-04-01 20:30 - 2013-12-18 10:38 - 00035640 _____ (AVG) C:\Windows\SysWOW64\uxtuneup.dll
2014-04-01 20:30 - 2013-12-18 10:38 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll
2014-04-01 20:30 - 2013-12-18 10:38 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll
2014-03-30 23:01 - 2014-04-16 21:52 - 00000000 ____D () C:\ProgramData\Assistant
2014-03-26 15:08 - 2014-03-26 15:09 - 00000000 ____D () C:\Users\Liza\AppData\Roaming\DVDVideoSoft
2014-03-26 15:08 - 2014-03-26 15:09 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-26 15:06 - 2014-03-26 15:07 - 34946552 _____ (DVDVideoSoft Ltd. ) C:\Users\Liza\Downloads\FreeVideoDub_2.0.21.822.exe
2014-03-26 15:02 - 2009-09-04 18:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-03-26 15:02 - 2009-09-04 18:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2014-03-26 15:01 - 2014-03-26 15:01 - 00003152 _____ () C:\Windows\System32\Tasks\{F3CDC153-31B0-4CE8-9060-F92D3DBEAB76}
2014-03-26 15:00 - 2014-03-26 15:00 - 00000195 _____ () C:\Windows\DirectX.log
2014-03-26 15:00 - 2006-11-29 14:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-03-26 15:00 - 2006-11-29 14:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2014-03-26 14:54 - 2014-03-26 14:54 - 00000000 ____D () C:\Users\Liza\AppData\Local\Windows Live
2014-03-26 14:52 - 2014-03-26 14:53 - 142602520 _____ (Microsoft Corporation) C:\Users\Liza\Downloads\wlsetup-all_16.4.3508.0205.exe
2014-03-26 13:35 - 2014-04-06 15:48 - 00009728 _____ () C:\Users\Liza\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-26 13:22 - 2014-03-26 13:28 - 00000000 ____D () C:\Users\Liza\AppData\Roaming\vlc
2014-03-26 13:22 - 2014-03-26 13:22 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-03-26 13:19 - 2014-03-26 13:19 - 00613200 _____ (Chip Digital GmbH) C:\Users\Liza\Downloads\VLC media player 32 Bit - CHIP-Downloader.exe
==================== One Month Modified Files and Folders =======
2014-04-18 10:31 - 2014-04-18 10:31 - 00017976 _____ () C:\Users\Liza\Desktop\FRST.txt
2014-04-18 10:31 - 2014-04-16 21:35 - 00000000 ____D () C:\FRST
2014-04-18 10:22 - 2014-04-18 10:22 - 00000624 _____ () C:\Users\Liza\Desktop\JRT.txt
2014-04-18 10:13 - 2013-10-12 10:36 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-18 10:10 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 10:10 - 2009-07-14 06:45 - 00021840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 10:06 - 2013-09-30 08:27 - 02037508 _____ () C:\Windows\WindowsUpdate.log
2014-04-18 10:04 - 2014-04-18 10:04 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 10:03 - 2014-04-18 10:03 - 00007670 _____ () C:\Users\Liza\Desktop\AdwCleaner[S0].txt
2014-04-18 10:02 - 2014-03-11 12:22 - 00000430 ____H () C:\Windows\Tasks\WS.Booster-S-667284051.job
2014-04-18 10:02 - 2014-02-23 16:36 - 00000446 ____H () C:\Windows\Tasks\WS.Booster-S-5195167130.job
2014-04-18 10:02 - 2013-10-12 10:36 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-18 10:02 - 2012-09-26 09:53 - 00000967 _____ () C:\Windows\SysWOW64\bscs.ini
2014-04-18 10:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-18 10:02 - 2009-07-14 06:51 - 00055765 _____ () C:\Windows\setupact.log
2014-04-18 10:00 - 2014-04-18 09:58 - 00000000 ____D () C:\AdwCleaner
2014-04-18 09:57 - 2014-04-18 09:57 - 00035919 _____ () C:\Users\Liza\Desktop\mbam.txt
2014-04-18 09:55 - 2014-04-18 09:55 - 00035923 _____ () C:\maleware.txt
2014-04-18 09:53 - 2014-04-17 23:46 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-18 09:49 - 2010-11-21 05:47 - 00131320 _____ () C:\Windows\PFRO.log
2014-04-18 09:41 - 2013-10-12 10:36 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-18 09:04 - 2013-12-17 17:50 - 00000000 ____D () C:\ProgramData\MFAData
2014-04-18 09:03 - 2013-09-30 11:28 - 00000000 ____D () C:\Users\Liza\AppData\Local\Adobe
2014-04-17 23:57 - 2014-04-17 23:58 - 01426178 _____ () C:\Users\Liza\Desktop\adwcleaner.exe
2014-04-17 23:57 - 2014-04-17 23:56 - 01426178 _____ () C:\Users\Liza\Downloads\adwcleaner.exe
2014-04-17 23:56 - 2014-04-17 23:56 - 01016261 _____ (Thisisu) C:\Users\Liza\Desktop\JRT.exe
2014-04-17 23:56 - 2014-04-17 23:55 - 01016261 _____ (Thisisu) C:\Users\Liza\Downloads\JRT.exe
2014-04-17 23:45 - 2014-04-17 23:45 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-17 23:45 - 2014-04-17 23:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-17 23:45 - 2014-04-17 23:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-17 23:38 - 2014-04-17 23:38 - 00001264 _____ () C:\Users\Liza\Desktop\Revo Uninstaller.lnk
2014-04-17 23:38 - 2014-04-17 23:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-17 23:37 - 2014-04-17 23:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Liza\Downloads\revosetup95.exe
2014-04-17 23:37 - 2014-04-17 23:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Liza\Desktop\revosetup95.exe
2014-04-17 23:36 - 2014-04-17 23:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Downloads\mbam-setup-2.0.1.1004 (2).exe
2014-04-17 23:36 - 2014-04-17 23:35 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Downloads\mbam-setup-2.0.1.1004 (1).exe
2014-04-17 18:27 - 2014-04-17 18:29 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-17 18:27 - 2014-04-17 18:26 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Liza\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-16 21:53 - 2014-03-11 12:25 - 00000000 ____D () C:\ProgramData\webSaave
2014-04-16 21:53 - 2014-02-23 16:35 - 00000000 ____D () C:\ProgramData\WoeBsaavE
2014-04-16 21:53 - 2014-02-23 16:35 - 00000000 ____D () C:\ProgramData\websavee
2014-04-16 21:52 - 2014-03-30 23:01 - 00000000 ____D () C:\ProgramData\Assistant
2014-04-16 21:52 - 2014-03-06 17:35 - 00000000 ____D () C:\ProgramData\DowNSSaVe
2014-04-16 21:51 - 2014-02-23 16:35 - 00000000 ____D () C:\Program Files (x86)\WoeBsaavE
2014-04-16 21:51 - 2014-02-23 16:35 - 00000000 ____D () C:\Program Files (x86)\websavee
2014-04-16 21:34 - 2014-04-16 21:34 - 02158592 _____ (Farbar) C:\Users\Liza\Downloads\FRST64 (1).exe
2014-04-16 21:34 - 2014-04-16 21:34 - 02158592 _____ (Farbar) C:\Users\Liza\Desktop\FRST64 (1).exe
2014-04-16 21:33 - 2014-04-16 21:33 - 02158592 _____ (Farbar) C:\Users\Liza\Downloads\FRST64.exe
2014-04-16 21:30 - 2014-03-11 12:25 - 00000000 ____D () C:\Program Files (x86)\webSaave
2014-04-16 20:34 - 2013-12-17 17:57 - 00000981 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-04-16 20:07 - 2013-12-17 17:56 - 00000000 ____D () C:\ProgramData\AVG2014
2014-04-16 20:03 - 2014-04-16 20:03 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2014-04-16 20:03 - 2014-04-16 20:03 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2014-04-11 13:23 - 2013-09-30 13:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 13:16 - 2013-09-30 13:24 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-09 09:52 - 2014-01-26 16:14 - 00000000 ____D () C:\Users\Liza\Desktop\MUSIK
2014-04-07 16:15 - 2014-04-07 16:15 - 00397312 _____ () C:\Users\Liza\Downloads\image (8).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00380928 _____ () C:\Users\Liza\Downloads\image (11).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00327680 _____ () C:\Users\Liza\Downloads\image (9).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00327680 _____ () C:\Users\Liza\Downloads\image (12).jpeg
2014-04-07 16:15 - 2014-04-07 16:15 - 00327680 _____ () C:\Users\Liza\Downloads\image (10).jpeg
2014-04-07 16:14 - 2014-04-07 16:14 - 00356352 _____ () C:\Users\Liza\Downloads\image.jpeg
2014-04-07 16:14 - 2014-04-07 16:14 - 00311296 _____ () C:\Users\Liza\Downloads\image (7).jpeg
2014-04-06 20:38 - 2014-02-23 16:34 - 00000000 ____D () C:\ProgramData\1747ce369cecf38d
2014-04-06 19:28 - 2011-04-12 09:43 - 00699342 _____ () C:\Windows\system32\perfh007.dat
2014-04-06 19:28 - 2011-04-12 09:43 - 00149450 _____ () C:\Windows\system32\perfc007.dat
2014-04-06 19:28 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-06 15:48 - 2014-03-26 13:35 - 00009728 _____ () C:\Users\Liza\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-06 12:19 - 2014-04-06 12:19 - 00142075 _____ () C:\Users\Liza\Downloads\Jaumo.htm
2014-04-06 12:19 - 2014-04-06 12:19 - 00000000 ____D () C:\Users\Liza\Downloads\Jaumo_files
2014-04-03 09:51 - 2014-04-17 23:45 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-17 23:45 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-17 23:45 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 15:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-03-31 03:16 - 2014-04-09 13:15 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 13:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 13:15 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 13:15 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-27 11:56 - 2013-10-01 13:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-27 11:55 - 2013-10-01 13:50 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-27 11:55 - 2013-10-01 13:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-26 15:09 - 2014-03-26 15:08 - 00000000 ____D () C:\Users\Liza\AppData\Roaming\DVDVideoSoft
2014-03-26 15:09 - 2014-03-26 15:08 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-03-26 15:07 - 2014-03-26 15:06 - 34946552 _____ (DVDVideoSoft Ltd. ) C:\Users\Liza\Downloads\FreeVideoDub_2.0.21.822.exe
2014-03-26 15:01 - 2014-03-26 15:01 - 00003152 _____ () C:\Windows\System32\Tasks\{F3CDC153-31B0-4CE8-9060-F92D3DBEAB76}
2014-03-26 15:00 - 2014-03-26 15:00 - 00000195 _____ () C:\Windows\DirectX.log
2014-03-26 14:54 - 2014-03-26 14:54 - 00000000 ____D () C:\Users\Liza\AppData\Local\Windows Live
2014-03-26 14:53 - 2014-03-26 14:52 - 142602520 _____ (Microsoft Corporation) C:\Users\Liza\Downloads\wlsetup-all_16.4.3508.0205.exe
2014-03-26 13:28 - 2014-03-26 13:22 - 00000000 ____D () C:\Users\Liza\AppData\Roaming\vlc
2014-03-26 13:22 - 2014-03-26 13:22 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-03-26 13:19 - 2014-03-26 13:19 - 00613200 _____ (Chip Digital GmbH) C:\Users\Liza\Downloads\VLC media player 32 Bit - CHIP-Downloader.exe
Some content of TEMP:
====================
C:\Users\Liza\AppData\Local\Temp\4zgkciub.dll
C:\Users\Liza\AppData\Local\Temp\AutoRun.exe
C:\Users\Liza\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Liza\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\Liza\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Liza\AppData\Local\Temp\Delta.exe
C:\Users\Liza\AppData\Local\Temp\DeltaTB.exe
C:\Users\Liza\AppData\Local\Temp\dlLogic.exe
C:\Users\Liza\AppData\Local\Temp\dltr.exe
C:\Users\Liza\AppData\Local\Temp\Driver_Pro.exe
C:\Users\Liza\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Liza\AppData\Local\Temp\drm_dyndata_7330016.dll
C:\Users\Liza\AppData\Local\Temp\First15.exe
C:\Users\Liza\AppData\Local\Temp\MybabylonTB.exe
C:\Users\Liza\AppData\Local\Temp\Quarantine.exe
C:\Users\Liza\AppData\Local\Temp\SettingsManagerSetup.exe
C:\Users\Liza\AppData\Local\Temp\Softonic_DE_1-5-9_DE-Production_10_CleanRelease.exe
C:\Users\Liza\AppData\Local\Temp\VP6Install.exe
C:\Users\Liza\AppData\Local\Temp\VP6VFW.dll
C:\Users\Liza\AppData\Local\Temp\WSSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 15:06
==================== End Of Log ============================ --- --- ---
--- --- --- |