MarshallMath | 29.04.2014 10:37 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.04.2014
Suchlauf-Zeit: 09:58:46
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.29.02
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Arne
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 274625
Verstrichene Zeit: 18 Min, 21 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Tiefer Rootkit-Suchlauf: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 19
PUP.Optional.WebCake.A, HKLM\SOFTWARE\CLASSES\APPID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}, In Quarantäne, [6799a65ae41c3bc59f1a63eec73b44bc],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}, In Quarantäne, [6799a65ae41c3bc59f1a63eec73b44bc],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [b64a7a86a55b946cbfd2a27b3cc614ec],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [b64a7a86a55b946cbfd2a27b3cc614ec],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [619fa8581de3b54bacb3fe1f7092748c],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [619fa8581de3b54bacb3fe1f7092748c],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BB975E58-E769-4E5A-BA12-B765BC559FF3}, In Quarantäne, [1be5a15fe51b1de3b70165ec34ce06fa],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [f60adc24a55bc53b10edaaa7877bf40c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [b34d26da27d9dc24c23cf859d929b24e],
PUP.Optional.TubeDimmer, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TubeDimmer, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\TubeDimmer, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\CLASSES\APPID\WebCakeIEClient.DLL, In Quarantäne, [c739d03056aa659beac9484faa59b64a],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [fd033ec2a957e11f8134711750b2fe02],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\WebCakeIEClient.DLL, In Quarantäne, [9f618f7142bebe42d5de5047897a50b0],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\fjoijdanhaiflhibkljeklcghcmmfffh, In Quarantäne, [ed13d52b936d37c9dfdb3265fb087c84],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, Löschen bei Neustart, [3ec26898718fbb45397d5f29768cff01],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [eb1511ef33cdcb355369b2d5bb4724dc],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [6c941ae69967b14f6680336a729114ec],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0M1S1H1K2U, Löschen bei Neustart, [6c941ae69967b14f6680336a729114ec]
Registrierungsdaten: 10
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=),Ersetzt,[db25b64a23dd7e82cf43f53dd82c827e]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5),Ersetzt,[b24ea25e44bc4cb420ee69c90301a060]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=),Ersetzt,[36cac43c12eeb9476ba9cd6511f30000]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=),Ersetzt,[f20e1fe150b016eaeb28939f34d0847c]
Hijack.SearchPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=),Ersetzt,[bf41c838b05030d033e267cbd82c4bb5]
Hijack.StartPage, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5),Löschen bei Neustart,[6a9630d0d32ddf21c04dcf639b69a858]
Hijack.SearchPage, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=),Löschen bei Neustart,[916f000003fd48b88887ae844bb954ac]
Hijack.SearchPage, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=),Löschen bei Neustart,[827e966a728e8e72a076082a61a33fc1]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI|(Default), hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=%s, Gut: (hxxp://www.google.com), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=%s),Löschen bei Neustart,[ee12e02008f8e81885b9003440c442be]
PUP.Optional.SearchCertifiedTB.A, HKU\S-1-5-21-3025636346-100433202-2293546944-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|(Default), hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=%s, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=%s),Löschen bei Neustart,[837d41bf728e13eda39cca6aba4a06fa]
Ordner: 19
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\Cache, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.OPtional.Dealply.A, C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly, In Quarantäne, [01ffaa5602fee21ef341a5f855ae46ba],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.DealPly.A, C:\Users\Arne\AppData\Roaming\Dealply, In Quarantäne, [c838649c7a860df37afee57f53af6a96],
PUP.Optional.DealPly.A, C:\Users\Arne\AppData\Roaming\Dealply\UpdateProc, In Quarantäne, [c838649c7a860df37afee57f53af6a96],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Common, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\content, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\defaults, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\defaults\preferences, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\locale, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\locale\en-US, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\META-INF, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\skin, In Quarantäne, [20e025db0ff131cf8065284235cde818],
Dateien: 90
PUP.Optional.DealPly.A, C:\Users\Arne\AppData\Roaming\Dealply\UpdateProc\UpdateTask.exe, In Quarantäne, [01ff07f9718fa75937ebe6385ba5ae52],
PUP.Optional.ZombieAlert.A, C:\Windows\SysWOW64\TubeDimmer.EA96BC9739D9.dll, Löschen bei Neustart, [b54b34ccf50be21e579d2cf93bc9936d],
PUP.Optional.WebSearch.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\searchplugins\Web Search.xml, In Quarantäne, [32ce718fd927649cb1cddca1b54d9b65],
PUP.Optional.SearchCertifiedTB.A, C:\Program Files (x86)\Mozilla Firefox\searchplugins\Web Search.xml, In Quarantäne, [1ae60bf5c53baa560bc4a5de649ebc44],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\app.dat, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\data.dat, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\TubeDimmer.exe, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\TubeDimmer.exe.config, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\TubeDimmer.ico, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\TubeDimmerService.exe, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\TubeDimmerService.exe.config, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.TubeDimmer, C:\ProgramData\TubeDimmer\Uninstall.exe, In Quarantäne, [12eedd238e7207f95eb5206a5ca6b44c],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\Setup.ico, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\Setup.dat, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\Setup.exe, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\_Setup.dll, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.Optional.WebCake.A, C:\ProgramData\Tarma Installer\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\_Setupx.dll, In Quarantäne, [7e8225db0ff14bb5793fbadd0ff4ad53],
PUP.OPtional.Dealply.A, C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\Uninstall DealPly.lnk, In Quarantäne, [01ffaa5602fee21ef341a5f855ae46ba],
PUP.OPtional.Dealply.A, C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly Help.url, In Quarantäne, [01ffaa5602fee21ef341a5f855ae46ba],
PUP.OPtional.Dealply.A, C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly.url, In Quarantäne, [01ffaa5602fee21ef341a5f855ae46ba],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\pinnedSearch_FindWide.htm, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\INSTALL.TNT, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\ffassist.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\GLOBALUNINSTALL.TNT, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\hmac.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\ie8starter.exe, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\iehpr.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\iestage2.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\IEToolbar.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\IEToolbar64.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\LastSession.log, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\log.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\npTNT2.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\npTNT2Ghost.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\OldStyleSB.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\PARTNER.TNT, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\passport.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\passport64.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\pinnedSearch.htm, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\progress.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\regsvr.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\RemoteSkin.wms, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\sqlite.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\tnt2chrome.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\TNT2User.exe, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\TNT2UserPS.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\TNT2UserPS64.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\TntMagicDel.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\UnInjLib.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\UnInjLib64.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\UNINSTALL.TNT, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\UninstallDlg.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\untar.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\UPDATE.TNT, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\xpi.tar, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.FindWide, C:\Users\Arne\AppData\Local\TNT2\2.0.0.1534\zipunzip.1.dll, In Quarantäne, [9070629ec937a55b013ad6d9ec17a060],
PUP.Optional.DealPly.A, C:\Users\Arne\AppData\Roaming\Dealply\UpdateProc\config.dat, In Quarantäne, [c838649c7a860df37afee57f53af6a96],
PUP.Optional.DealPly.A, C:\Users\Arne\AppData\Roaming\Dealply\UpdateProc\TTL.DAT, In Quarantäne, [c838649c7a860df37afee57f53af6a96],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Common\pinnedSearch.htm, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447\inst.ini, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447\PARTNER.1.TNT, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447\partner.dat, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447\passport.dll, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447\passport64.dll, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.TidyNetwork.A, C:\Users\Arne\AppData\Local\TNT2\Profiles\10447\runt.ini, In Quarantäne, [c23e5fa155ab35cb634f72f4a75b956b],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\build.sh, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\chrome.manifest, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\config_build.sh, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\icon.png, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\install.rdf, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\readme.txt, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\content\about.xul, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\content\firefoxOverlay.xul, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\content\options.xul, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\content\overlay.js, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\defaults\preferences\webcake.js, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\locale\en-US\about.dtd, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\locale\en-US\prefwindow.dtd, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\locale\en-US\webcake.dtd, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\locale\en-US\webcake.properties, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\META-INF\manifest.mf, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\META-INF\zigbert.rsa, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\META-INF\zigbert.sf, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\skin\overlay.css, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.WebCake.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\extensions\plugin@getwebcake.com\skin\toolbar-button.png, In Quarantäne, [20e025db0ff131cf8065284235cde818],
PUP.Optional.Babylon.A, C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://search.babylon.com/?affID=110823&tt=300912_TORP_4012_6&babsrc=HP_ss&mntrId=ee022286000000000000e4d53d42a5e7",), Ersetzt,[9e62ee128d7349b7f285cd92848005fb]
PUP.Optional.CrossRider.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "140b60b2e1bd6d063993e25aa98c3419");), Ersetzt,[17e9a0602ed2eb154b9da3bb2ada8e72]
PUP.Optional.CertifiedTB.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://search.certified-toolbar.com?si=43169&st=home&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5");), Ersetzt,[50b0a8588c7432ce7a9271ee16eea060]
PUP.Optional.CertifiedTB.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://search.certified-toolbar.com?si=43169&st=newtab&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5");), Ersetzt,[ea162dd398689868093c48173bc935cb]
PUP.Optional.CertifiedTB.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.certified-toolbar.com?si=43169&st=chrome&tid=3580&ver=3.5&ts=1369177136274&tguid=43169-3580-1369177136274-BCC9678E3DBE08AA96F7CD6EDEC727F5&q=");), Ersetzt,[2dd3758b42be946cf1553a25f311eb15]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.205 - Bericht erstellt am 29/04/2014 um 10:10:00
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Arne - ARNE-LT
# Gestartet von : C:\Users\Arne\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Browser Updater
Ordner Gelöscht : C:\Program Files (x86)\Iminent
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\PinPhotoZoom
Ordner Gelöscht : C:\Program Files (x86)\Protected Search
Ordner Gelöscht : C:\Program Files (x86)\SearchProtect
Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater
Ordner Gelöscht : C:\Users\Arne\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Arne\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Software Updater
Ordner Gelöscht : C:\Users\Arne\AppData\Local\TubeDimmer
Ordner Gelöscht : C:\Users\Arne\AppData\LocalLow\SimplyTech
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\BupSystem
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\PinPhotoZoom
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\Software Updater
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\SweetPacksToolbarData
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\sparpilot@sparpilot.com
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbdamgnimlipjnpgiakiojcbbmcmiibn
Datei Gelöscht : C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater
Datei Gelöscht : C:\Windows\System32\Tasks\Dealply
Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate
Datei Gelöscht : C:\Windows\System32\Tasks\Freemium1ClickMaint
Datei Gelöscht : C:\Windows\System32\Tasks\Lyrics-Monkey Update
Datei Gelöscht : C:\Windows\System32\Tasks\ProtectedSearch
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater Ui
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mbdamgnimlipjnpgiakiojcbbmcmiibn
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ofnnlhbgdcabppjmlijllkhekcglbjlg
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{011166B1-9A69-4174-93D5-F7D3324553FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3A520357-BA99-4C9B-BEDF-12E3E46DDF14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8DA8B89E-0C65-403B-8231-AB22ECFA0687}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A928E66C-F501-4E66-9953-855C712F93B2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B0E28FA0-DF07-44B6-95CE-48BE26DB9266}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E6B4EE8F-C38E-4994-BE28-229A3F92262C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FCA8936E-403A-4487-A966-70F80F1D5A6A}
Schlüssel Gelöscht : HKCU\Software\pc optimizer pro
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Lyrics_Monkey
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\simplytech
Schlüssel Gelöscht : HKLM\Software\covus freemium gmbh
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5dfd64a7-81dd-45a9-9874-1fe13b7f4d56}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FLV Player
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [(Default)]
-\\ Mozilla Firefox v25.0 (de)
[ Datei : C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultengine", "Web Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc");
Zeile gelöscht : user_pref("extentions.webcake.installId", "759c8903-db9d-4ee7-8082-229dd85e3ba5");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.Services.BHPCode", "01");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.Services.DefaultEvent", "000");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.Services.DefaultWebSite", "000");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.Services.IminentClientCode", "11");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.minibar.Services.SmartFavCode", "02");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.Services.BHPCode", "01");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultEvent", "000");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultWebSite", "000");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.Services.IminentClientCode", "11");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.Services.SmartFavCode", "02");
Zeile gelöscht : user_pref("iminent.webbooster.scripts.sslminibar.displayFavLinks", "1");
Zeile gelöscht : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "1351272131905");
Zeile gelöscht : user_pref("sweetim.toolbar.Visibility.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Zeile gelöscht : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.cda.returnValue", "hide");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-handler.js");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff_1_6.html");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-handler.js");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handler.js");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Zeile gelöscht : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Zeile gelöscht : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.google.com/.*|.*.google.co.in/.*|.*.google.com.br/.*|.*.google.es/.*|.*.youtube.com/.*|.*.yahoo.com/.*|.[...]
Zeile gelöscht : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Zeile gelöscht : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Zeile gelöscht : user_pref("sweetim.toolbar.mode.debug", "false");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.enable", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.callback", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..*|.*.yahoo..*|.*.youtube.com.*|.*ask.com.*|.*.sweetim.com.*");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
Zeile gelöscht : user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid=chff1");
Zeile gelöscht : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"[...]
Zeile gelöscht : user_pref("sweetim.toolbar.search.history.capacity", "10");
Zeile gelöscht : user_pref("sweetim.toolbar.simapp_id", "{39AAF1C5-1B93-11E2-BEC2-60EB6983C6D5}");
Zeile gelöscht : user_pref("sweetim.toolbar.version", "1.6.0.3");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Web Search");
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Startup_urls] : hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2912d6c9-cc4c-4f0c-9ff4-0903618a3c5a&searchtype=hp&fr=linkury-tb&installDate=11/05/2013&type=hp1000
Gelöscht [Homepage] : hxxp://search.babylon.com/?affID=110823&tt=300912_TORP_4012_6&babsrc=HP_ss&mntrId=ee022286000000000000e4d53d42a5e7
Gelöscht [Extension] : abepbblpkilpjohncjbccmdjhdhbnhdj
Gelöscht [Extension] : mbdamgnimlipjnpgiakiojcbbmcmiibn
*************************
AdwCleaner[R0].txt - [26395 octets] - [29/04/2014 10:07:26]
AdwCleaner[S0].txt - [24070 octets] - [29/04/2014 10:10:00]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [24131 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Arne on 29.04.2014 at 10:15:38,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3025636346-100433202-2293546944-1000\Software\sweetim
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\pc optimizer pro"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Arne\AppData\Roaming\mozilla\firefox\profiles\rhvx4y9h.default\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}
Emptied folder: C:\Users\Arne\AppData\Roaming\mozilla\firefox\profiles\rhvx4y9h.default\minidumps [97 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.04.2014 at 10:21:44,78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-04-2014
Ran by Arne (administrator) on ARNE-LT on 29-04-2014 11:31:00
Running from C:\Users\Arne\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Spotify Ltd) C:\Users\Arne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Audible, Inc.) C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
(Dropbox, Inc.) C:\Users\Arne\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Geek Software GmbH) D:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [615584 2011-01-20] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-01-20] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2280232 2010-07-29] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2010-10-29] (Acer Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1025616 2012-09-03] (Dritek System Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-13] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737360 2014-04-29] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [PDFPrint] => D:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-02-19] (Geek Software GmbH)
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1163264 2012-09-25] ()
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3025636346-100433202-2293546944-1000\...\Run: [Spotify Web Helper] => C:\Users\Arne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-03-05] (Spotify Ltd)
HKU\S-1-5-21-3025636346-100433202-2293546944-1000\...\Run: [Wunderlist] => C:\Users\Arne\AppData\Local\Apps\2.0\X6KLWTQC.92T\71K9O604.LH1\wund..tion_45ec1bcecca77a53_0002.0000_8bd0285384bbd56f\Wunderlist.exe [6880768 2013-02-05] (6 Wunderkinder GmbH)
HKU\S-1-5-21-3025636346-100433202-2293546944-1000\...\Run: [DAEMON Tools Lite] => D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-3025636346-100433202-2293546944-1000\...\Run: [Driver Operating Service] => C:\Users\Arne\AppData\Local\Apps\2.0\X6KLWTQC.92T\71K9O604.LH1\dros..tion_0000000000000000_0001.0000_b7335b782fe9a0ac\Driver Operating Service.appref-ms
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Audible Download Manager.lnk
ShortcutTarget: Audible Download Manager.lnk -> C:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe (Audible, Inc.)
Startup: C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Arne\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x48ACA9D9C724CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.10
FireFox:
========
FF ProfilePath: C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Protegere - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\security@protegere.org [2014-04-28]
FF Extension: YouTube Unblocker - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\youtubeunblocker@unblocker.yt [2013-12-02]
FF Extension: ReminderFox - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} [2013-12-02]
FF Extension: Evernote Web Clipper - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2014-04-28]
FF Extension: InvisibleHand - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi [2012-10-08]
FF Extension: Ciuvo - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\extension@ciuvo.com.xpi [2012-10-08]
FF Extension: leethax.net extension - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\leethax@leethax.net.xpi [2013-01-28]
FF Extension: Clearly - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\readable@evernote.com.xpi [2012-10-26]
FF Extension: NoScript - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-10-24]
FF Extension: Soundcloud SUPER +2: Downloader and Recommender - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\{988da70d-b78d-44a1-a9c7-ed11832a9e2e}.xpi [2012-12-19]
FF Extension: FootieFox - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\{9fb7d178-155a-4318-9173-1a8eaaea7fe4}.xpi [2012-10-08]
FF Extension: Adblock Plus - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\rhvx4y9h.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-08]
FF HKLM-x32\...\Firefox\Extensions: [{28B041F9-242D-4DE0-9A19-A82C542ACFB0}] - C:\Windows\Installer\{8BDECB8E-FA78-41E5-937D-05B6C9651112}\{28B041F9-242D-4DE0-9A19-A82C542ACFB0}.xpi
FF Extension: No Name - C:\Windows\Installer\{8BDECB8E-FA78-41E5-937D-05B6C9651112}\{28B041F9-242D-4DE0-9A19-A82C542ACFB0}.xpi [2014-04-28]
FF HKCU\...\Firefox\Extensions: [{b5ad6039-a173-4149-9dcf-d04371526253}] - C:\Program Files (x86)\Lyrics_Monkey\131.xpi
Chrome:
=======
CHR HomePage: hxxp://search.babylon.com/?affID=110823&tt=300912_TORP_4012_6&babsrc=HP_ss&mntrId=ee022286000000000000e4d53d42a5e7
CHR StartupUrls: "hxxp://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN", "https://www.bitcoin.de/de", "hxxp://www.gmx.net/", "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2912d6c9-cc4c-4f0c-9ff4-0903618a3c5a&searchtype=hp&fr=linkury-tb&installDate=11/05/2013&type=hp1000"
CHR DefaultSearchKeyword: ecosia.org
CHR DefaultSearchProvider: Ecosia
CHR DefaultSearchURL: hxxp://ecosia.org/search?q={searchTerms}&addon=opensearch
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2014-04-28]
CHR Extension: (Google Docs) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-05]
CHR Extension: (Google Drive) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-05]
CHR Extension: (Schalten Sie das Licht) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2014-04-28]
CHR Extension: (YouTube) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-05]
CHR Extension: (Adblock Plus) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-06-05]
CHR Extension: (Ecosia - Die Suchmaschine, die Bäume pflanzt) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\clellnciejhoedgepbdilbkdkaoecgpc [2014-04-28]
CHR Extension: (Hide My Ass! Web Proxy) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmgnmcnlncejehjlnhaglpnoolgbflbd [2014-04-28]
CHR Extension: (Google-Suche) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-05]
CHR Extension: (FeedSquares - Supercharge your Google Reader) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddkahgkblobiogkkeedfnjkldecloidi [2014-04-28]
CHR Extension: (Clock für Google Chrome ™) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg [2014-04-28]
CHR Extension: (AdBlock) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-28]
CHR Extension: (RSS Live Links) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcamnijgggppihioleoenjmlnakejdph [2014-04-28]
CHR Extension: (Evernote Snipping Tool ) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmhpjbejpnnaffkpmebeagdiidibjfa [2013-11-12]
CHR Extension: (Clearly) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\iooicodkiihhpojmmeghjclgihfjdjhj [2013-06-05]
CHR Extension: (Evernote Web) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2013-06-05]
CHR Extension: (Google Wallet) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-28]
CHR Extension: (Download Protect) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\noknoogiiibmpoenlhpcllbmbncldhfa [2014-04-28]
CHR Extension: (Google Mail) - C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-05]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-04-29] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-04-29] (Avira Operations GmbH & Co. KG)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-04-29] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
R3 hpnuhst; C:\Windows\System32\DRIVERS\hpnuhst.sys [16384 2007-03-27] (Hewlett-Packard Development Company)
R3 HPNUHUB; C:\Windows\System32\DRIVERS\hpnuhub.sys [40448 2007-10-30] (Hewlett-Packard Development Company)
R3 L1C; C:\Windows\System32\DRIVERS\L1C60x64.sys [75888 2012-09-03] (Atheros Communications, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-12-17] (Duplex Secure Ltd.)
U3 ar62kwb2; C:\Windows\System32\Drivers\ar62kwb2.sys [0 ] (Advanced Micro Devices)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 SANDRA; \??\D:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.RTM\WNt500x64\Sandra.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-29 10:47 - 2014-04-29 10:48 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-04-29 10:21 - 2014-04-29 10:21 - 00001716 _____ () C:\Users\Arne\Desktop\JRT.txt
2014-04-29 10:15 - 2014-04-29 10:15 - 00000000 ____D () C:\Windows\ERUNT
2014-04-29 10:13 - 2014-04-29 10:13 - 00024412 _____ () C:\Users\Arne\Desktop\AdwCleaner[S0].txt
2014-04-29 10:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-04-29 10:06 - 2014-04-29 10:10 - 00000000 ____D () C:\AdwCleaner
2014-04-29 10:06 - 2014-04-29 10:06 - 00027383 _____ () C:\Users\Arne\Desktop\mbam.txt
2014-04-29 10:01 - 2014-04-29 10:11 - 00031432 _____ () C:\Windows\PFRO.log
2014-04-29 10:01 - 2014-04-29 10:11 - 00000112 _____ () C:\Windows\setupact.log
2014-04-29 10:01 - 2014-04-29 10:01 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-29 09:38 - 2014-04-29 10:03 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-29 09:38 - 2014-04-29 09:38 - 00001105 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-29 09:38 - 2014-04-29 09:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-29 09:38 - 2014-04-29 09:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-29 09:38 - 2014-04-29 09:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-29 09:38 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-29 09:38 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-29 09:38 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-29 09:37 - 2014-04-29 09:38 - 01016261 _____ (Thisisu) C:\Users\Arne\Desktop\JRT.exe
2014-04-29 09:36 - 2014-04-29 09:37 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Arne\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-29 09:30 - 2014-04-29 09:31 - 01310621 _____ () C:\Users\Arne\Desktop\adwcleaner.exe
2014-04-28 11:45 - 2014-04-28 11:45 - 00027112 _____ () C:\ComboFix.txt
2014-04-28 11:35 - 2014-04-28 11:45 - 00000000 ____D () C:\Qoobox
2014-04-28 11:35 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-28 11:35 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-28 11:35 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-28 11:35 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-28 11:35 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-28 11:35 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-28 11:35 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-28 11:35 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-28 11:34 - 2014-04-28 11:43 - 00000000 ____D () C:\Windows\erdnt
2014-04-28 11:24 - 2014-04-28 11:24 - 00001267 _____ () C:\Users\Arne\Desktop\Revo Uninstaller.lnk
2014-04-28 11:24 - 2014-04-28 11:24 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-28 11:23 - 2014-04-28 11:24 - 05196309 ____R (Swearware) C:\Users\Arne\Desktop\ComboFix.exe
2014-04-28 10:30 - 2014-04-28 10:30 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Arne\Desktop\revosetup95.exe
2014-04-28 09:38 - 2014-04-28 09:39 - 00036560 _____ () C:\Users\Arne\Desktop\Addition.txt
2014-04-28 09:37 - 2014-04-29 11:31 - 00023794 _____ () C:\Users\Arne\Desktop\FRST.txt
2014-04-28 09:37 - 2014-04-29 11:31 - 00000000 ____D () C:\FRST
2014-04-28 08:46 - 2014-04-28 08:46 - 02061824 _____ (Farbar) C:\Users\Arne\Desktop\FRST64.exe
2014-04-09 09:21 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-09 09:09 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 09:09 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 09:09 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 09:09 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 09:09 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 09:09 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 09:09 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 09:09 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 09:09 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 09:09 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 09:09 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 09:07 - 2014-04-28 08:06 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-04 17:36 - 2014-04-04 17:36 - 00002521 _____ () C:\Users\Public\Desktop\Freetec TubeBox.lnk
2014-04-04 17:36 - 2014-04-04 17:36 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\dlg
2014-04-04 17:36 - 2014-04-04 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freetec
2014-04-04 17:33 - 2014-04-04 17:33 - 00118784 _____ () C:\Windows\system32\winipsfc.exe
2014-04-04 17:32 - 2014-04-04 17:32 - 00000000 ____D () C:\Program Files (x86)\SparPilotAddon
2014-04-04 17:24 - 2014-04-04 17:27 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Security System 2
==================== One Month Modified Files and Folders =======
2014-04-29 11:31 - 2014-04-28 09:37 - 00023794 _____ () C:\Users\Arne\Desktop\FRST.txt
2014-04-29 11:31 - 2014-04-28 09:37 - 00000000 ____D () C:\FRST
2014-04-29 10:57 - 2013-04-02 14:35 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-29 10:57 - 2013-04-02 14:35 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-29 10:48 - 2014-04-29 10:47 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-04-29 10:21 - 2014-04-29 10:21 - 00001716 _____ () C:\Users\Arne\Desktop\JRT.txt
2014-04-29 10:20 - 2009-07-14 06:45 - 00015120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-29 10:20 - 2009-07-14 06:45 - 00015120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-29 10:15 - 2014-04-29 10:15 - 00000000 ____D () C:\Windows\ERUNT
2014-04-29 10:14 - 2012-11-07 17:15 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Dropbox
2014-04-29 10:13 - 2014-04-29 10:13 - 00024412 _____ () C:\Users\Arne\Desktop\AdwCleaner[S0].txt
2014-04-29 10:11 - 2014-04-29 10:01 - 00031432 _____ () C:\Windows\PFRO.log
2014-04-29 10:11 - 2014-04-29 10:01 - 00000112 _____ () C:\Windows\setupact.log
2014-04-29 10:10 - 2014-04-29 10:06 - 00000000 ____D () C:\AdwCleaner
2014-04-29 10:10 - 2013-05-21 12:49 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch
2014-04-29 10:10 - 2013-05-21 12:49 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-04-29 10:10 - 2012-09-03 22:22 - 01692259 _____ () C:\Windows\WindowsUpdate.log
2014-04-29 10:06 - 2014-04-29 10:06 - 00027383 _____ () C:\Users\Arne\Desktop\mbam.txt
2014-04-29 10:03 - 2014-04-29 09:38 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-29 10:02 - 2013-02-05 18:50 - 00000000 ____D () C:\Users\Arne\AppData\Local\Deployment
2014-04-29 10:02 - 2013-02-05 18:50 - 00000000 ____D () C:\Users\Arne\AppData\Local\Apps\2.0
2014-04-29 10:01 - 2014-04-29 10:01 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-29 10:01 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME
2014-04-29 09:38 - 2014-04-29 09:38 - 00001105 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-29 09:38 - 2014-04-29 09:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-29 09:38 - 2014-04-29 09:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-29 09:38 - 2014-04-29 09:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-29 09:38 - 2014-04-29 09:37 - 01016261 _____ (Thisisu) C:\Users\Arne\Desktop\JRT.exe
2014-04-29 09:37 - 2014-04-29 09:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Arne\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-29 09:31 - 2014-04-29 09:30 - 01310621 _____ () C:\Users\Arne\Desktop\adwcleaner.exe
2014-04-28 11:45 - 2014-04-28 11:45 - 00027112 _____ () C:\ComboFix.txt
2014-04-28 11:45 - 2014-04-28 11:35 - 00000000 ____D () C:\Qoobox
2014-04-28 11:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-04-28 11:43 - 2014-04-28 11:34 - 00000000 ____D () C:\Windows\erdnt
2014-04-28 11:43 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-28 11:24 - 2014-04-28 11:24 - 00001267 _____ () C:\Users\Arne\Desktop\Revo Uninstaller.lnk
2014-04-28 11:24 - 2014-04-28 11:24 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-28 11:24 - 2014-04-28 11:23 - 05196309 ____R (Swearware) C:\Users\Arne\Desktop\ComboFix.exe
2014-04-28 10:30 - 2014-04-28 10:30 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Arne\Desktop\revosetup95.exe
2014-04-28 09:39 - 2014-04-28 09:38 - 00036560 _____ () C:\Users\Arne\Desktop\Addition.txt
2014-04-28 08:46 - 2014-04-28 08:46 - 02061824 _____ (Farbar) C:\Users\Arne\Desktop\FRST64.exe
2014-04-28 08:39 - 2013-11-08 19:56 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-28 08:06 - 2014-04-09 09:07 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-28 08:00 - 2013-08-23 20:55 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-28 07:56 - 2012-09-04 00:20 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-10 19:00 - 2013-06-05 10:38 - 00002178 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-10 09:43 - 2009-07-14 19:58 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-04-10 09:43 - 2009-07-14 19:58 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-04-10 09:43 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-09 09:07 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-06 12:49 - 2009-07-14 06:45 - 00311320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-06 12:48 - 2012-09-04 09:16 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-06 12:48 - 2012-09-04 09:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-04-06 12:35 - 2012-09-04 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-04-04 17:36 - 2014-04-04 17:36 - 00002521 _____ () C:\Users\Public\Desktop\Freetec TubeBox.lnk
2014-04-04 17:36 - 2014-04-04 17:36 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\dlg
2014-04-04 17:36 - 2014-04-04 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freetec
2014-04-04 17:36 - 2012-10-10 17:02 - 00000000 ____D () C:\ProgramData\Package Cache
2014-04-04 17:33 - 2014-04-04 17:33 - 00118784 _____ () C:\Windows\system32\winipsfc.exe
2014-04-04 17:32 - 2014-04-04 17:32 - 00000000 ____D () C:\Program Files (x86)\SparPilotAddon
2014-04-04 17:27 - 2014-04-04 17:24 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Security System 2
2014-04-03 09:51 - 2014-04-29 09:38 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-29 09:38 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-29 09:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 09:35 - 2012-09-03 23:22 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Users\Arne\AppData\Local\Temp\avgnt.exe
C:\Users\Arne\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-07 11:42
==================== End Of Log ============================ --- --- ---
--- --- --- |